← Internet Security Research Group cases
Bugzilla #1666047 Delayed Revocation

Let's Encrypt: 302 total OCSP responses served beyond acceptable timelines

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that, for a set of certificate serial numbers, Let's Encrypt served OCSP responses older than acceptable timelines. The issue was discovered during an on-call shift rotation when SREs triaged a non-paging alert about elevated error-level logs and began investigating on 2020-09-08. From 2020-09-07 to 2020-09-08, OCSP responses older than 3.5 days were served for 268 certificate serial numbers, and from 2020-09-12 to 2020-09-13 this occurred for an additional 34 serial numbers; none were served beyond their validity period (nextUpdate), and the maximum OCSP age reached was 5 days. Let's Encrypt executed remediation queries (first on 2020-09-08 17:47 UTC for 268 entries, and again on 2020-09-13 17:22 UTC for the remaining problematic entries) and verified that all potentially affected Certificate Status entries had been remediated. A fix for the root cause was deployed on 2020-09-10 17:37 UTC and concluded at 17:59 UTC, with remediation completed as of 2020-09-13 17:22:17. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated an intent to close it as completed on or about 2020-10-09 if no further questions were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.50 6 comments
Chronology
  1. Let's Encrypt began investigating after an on-call alert about elevated error-level logs led to discovery of OCSP responses served beyond acceptable timelines.
  2. Let's Encrypt deployed a production fix for the root cause of the OCSP timing issue.
  3. Let's Encrypt executed a final remediation query and verified all potentially affected certificate status entries were updated.
Thread Activity
  1. Internet Security Research Group — Created the incident report describing OCSP responses served older than acceptable timelines for 302 certificate serial numbers and the remediation actions taken.
  2. Community commenter — Asked about whether the proto2-to-proto3 migration introduced latent bugs and what additional OCSP remediations might be useful.
  3. Internet Security Research Group — Explained three changes that could have prevented/caught the issue, identified the immediate fix deployed on 2020-09-10, noted other in-flight fixes, and described next steps after proto3 migration.
  4. Mozilla representative — Stated an intent to close the bug as completed on or about 2020-10-09 if there were no additional questions.
Participants
Internet Security Research Group Community commenter Mozilla representative
Similar Local Cases
#1715672 RESOLVED Delayed Revocation Opened 2021-06-10 · Closed 2023-02-22 · 67% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1729567 RESOLVED Delayed Revocation Opened 2021-09-07 · Closed 2023-02-22 · 60% similar
Let's Encrypt: Delay updating OCSP responses
#1799755 RESOLVED Delayed Revocation Opened 2022-11-08 · Closed 2024-05-09 · 54% similar
Let's Encrypt: End Entity CRLs Not Reissued On Time
#1795483 RESOLVED Delayed Revocation Opened 2022-10-14 · Closed 2023-02-22 · 52% similar
Let's Encrypt: Delayed revocation for removed gTLD
#1619179 RESOLVED Delayed Revocation Opened 2020-03-02 · Closed 2023-02-22 · 51% similar
Let's Encrypt: Incomplete revocation for CAA rechecking bug
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 51% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1627614 RESOLVED Delayed Revocation Opened 2020-04-06 · Closed 2023-02-22 · 51% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 51% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action