Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
Let’s Encrypt disclosed a compliance issue related to audit logging of OCSP updates for subscriber certificates. During a quarterly internal review of the CA/B Forum baseline requirements, the CA determined it may not be compliant with baseline requirements section 5.4.1.2.5, and further investigation confirmed it was not. The CA stated that it logs an audit log event when OCSP is signed upon initial certificate issuance, but that subsequent OCSP response updates during a certificate’s 90-day lifetime were not logged as required. The CA reported that issuance was not stopped for this incident and described the scope as certificates issued from Let’s Encrypt Intermediate Certificate Authorities, with exceptions for certificates revoked before the second OCSP signing update. As remediation, the CA said a Boulder CA software change was needed to implement the required logging and targeted completion was updated from 2020-01-31 to 2021-01-31. The CA later reported that updated CA software with pertinent logging changes was deployed through staging and production, and Mozilla indicated the bug could be closed once remediation work was confirmed complete; the bug is resolved as FIXED.
- Internal audit detected non-compliance with baseline requirements for audit log retention on OCSP updates to subscriber certificates.
- Incident report disclosure procedure was started.
- Updated CA software with OCSP logging changes was deployed to staging and production.
- Mozilla indicated the bug could be closed after confirming remediation work was complete.
- Internet Security Research Group — Submitted an incident report describing the OCSP audit logging gap, its scope, and remediation steps including a Boulder CA software change with a revised target date.
- Internet Security Research Group — Corrected the remediation target date from 2020-01-31 to 2021-01-31.
- Internet Security Research Group — Reported that updated CA software with logging changes was deployed to staging and production.
- Mozilla representative — Indicated the bug could be closed next week unless additional remediation work remained.