← Internet Security Research Group cases
Bugzilla #1684112 Technical Compliance

Let's Encrypt: Failure to audit log subscriber certificate OCSP updates

RESOLVED FIXED Internet Security Research Group
AI Summary

Let's Encrypt identified a compliance issue regarding the logging of OCSP updates for subscriber certificates. While initial certificate issuance was logged correctly, subsequent updates were not, violating baseline requirements. The issue was discovered during an internal audit, and although it affected all certificates issued from their Intermediate Certificate Authorities, issuance was not halted. Remediation steps included software updates to ensure proper logging, with a target completion date set for January 31, 2021. The necessary changes have since been deployed.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 0.90
Chronology
  1. Internal audit detected non-compliance with OCSP update logging.
  2. Updated CA software with logging changes deployed.
  3. Bug closure planned as remediation was completed.
Participants
Andrew Gabbitas Kris Chris Ben Wilson
External References
Similar Local Cases
#1771722 RESOLVED Technical Compliance Opened 2022-05-30 · Closed 2023-02-22 · 49% similar
Firmaprofesional: 2022 - Title field
#1737057 RESOLVED Technical Compliance Opened 2021-10-21 · Closed 2023-02-22 · 49% similar
Entrust: CRLs and OCSP responses not issued as specified in the CPS
#1832338 RESOLVED Technical Compliance Opened 2023-05-10 · Closed 2023-06-08 · 48% similar
Firmaprofesional: 2023 - Ensure Timestamp service Logs Integrity
#1716902 RESOLVED Technical Compliance Opened 2021-06-17 · Closed 2023-02-22 · 48% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1771727 RESOLVED Technical Compliance Opened 2022-05-30 · Closed 2023-02-22 · 47% similar
Firmaprofesional: 2022 - Define Device Obsolescence Process
#1905072 RESOLVED Technical Compliance Opened 2024-06-27 · Closed 2024-08-22 · 47% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#1718680 RESOLVED Technical Compliance Opened 2021-06-29 · Closed 2023-02-22 · 47% similar
Asseco DS / Certum: Forward dating certificates (notBefore in the future)
#1651611 RESOLVED Technical Compliance Opened 2020-07-09 · Closed 2023-02-22 · 47% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action