← Internet Security Research Group cases
Bugzilla #1684112 Ca Certificate Compliance

Let's Encrypt: Failure to audit log subscriber certificate OCSP updates

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt disclosed a compliance issue related to audit logging of OCSP updates for subscriber certificates. During a quarterly internal review of the CA/B Forum baseline requirements, the CA determined it may not be compliant with baseline requirements section 5.4.1.2.5, and further investigation confirmed it was not. The CA stated that it logs an audit log event when OCSP is signed upon initial certificate issuance, but that subsequent OCSP response updates during a certificate’s 90-day lifetime were not logged as required. The CA reported that issuance was not stopped for this incident and described the scope as certificates issued from Let’s Encrypt Intermediate Certificate Authorities, with exceptions for certificates revoked before the second OCSP signing update. As remediation, the CA said a Boulder CA software change was needed to implement the required logging and targeted completion was updated from 2020-01-31 to 2021-01-31. The CA later reported that updated CA software with pertinent logging changes was deployed through staging and production, and Mozilla indicated the bug could be closed once remediation work was confirmed complete; the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.90 5 comments
Chronology
  1. Internal audit detected non-compliance with baseline requirements for audit log retention on OCSP updates to subscriber certificates.
  2. Incident report disclosure procedure was started.
  3. Updated CA software with OCSP logging changes was deployed to staging and production.
  4. Mozilla indicated the bug could be closed after confirming remediation work was complete.
Thread Activity
  1. Internet Security Research Group — Submitted an incident report describing the OCSP audit logging gap, its scope, and remediation steps including a Boulder CA software change with a revised target date.
  2. Internet Security Research Group — Corrected the remediation target date from 2020-01-31 to 2021-01-31.
  3. Internet Security Research Group — Reported that updated CA software with logging changes was deployed to staging and production.
  4. Mozilla representative — Indicated the bug could be closed next week unless additional remediation work remained.
Participants
Internet Security Research Group Mozilla representative
Similar Local Cases
#1648840 RESOLVED Ca Certificate Compliance Opened 2020-06-26 · Closed 2023-02-22 · 90% similar
Let's Encrypt: OCSP responses with no revocationReason
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 80% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#2044788 ASSIGNED Ca Certificate Compliance Self Reported Incident Incident Revocation Issue Opened 2026-06-03 Still Open · 79% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 79% similar
Let's Encrypt: Improper encoding of wildcard certificates
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 70% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1710444 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-05-10 · Closed 2023-02-22 · 70% similar
DigiCert: Invalid stateOrProvinceName
#1875205 RESOLVED Ca Certificate Compliance Opened 2024-01-18 · Closed 2024-01-26 · 70% similar
Digicert: SMIME certs missing State in Org ID
#1848306 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2023-08-11 · Closed 2023-11-02 · 70% similar
TWCA: CA certificate without EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action