Let’s Encrypt disclosed an off-by-one-second certificate lifetime issue and updated its CP/CPS processes
Let’s Encrypt disclosed that its certificates were being issued with a validity period of 90 days plus 1 second because of how Boulder calculated notBefore and notAfter. The issue was first reported to Let’s Encrypt by email from Jesper Kristensen on 2021-06-08, and ISRG declared an internal incident the next day. Let’s Encrypt said it deployed a staging fix and then a production config change on 2021-06-09, after which new certificates used a lifetime of 7,775,999 seconds. The company also stated that it did not stop issuance, and that it would not revoke the affected certificates; it opened Bug 1715672 to track that non-revocation. In follow-up comments, Let’s Encrypt explained its review process, said it had not formalized review of all Mozilla CA incidents, and committed to a new triage rotation for MDSP, Bugzilla, and CABF ballot review. It later reported completing an internal CP/CPS consistency review, publishing updated CP and CPS versions, and finishing a retrospective review of historic CA compliance incidents.
- Let’s Encrypt became aware of an off-by-one-second certificate lifetime issue from an external email report.
- ISRG declared an internal incident and deployed a production fix so new certificates used the corrected lifetime.
- Let’s Encrypt filed Bug 1715672 to track its decision not to revoke affected certificates.
- Let’s Encrypt said its MDSP/Bugzilla review rotation was in place.
- Let’s Encrypt published updated CP and CPS versions after its internal consistency review.
- Let’s Encrypt reported completion of its retrospective review of historic CA compliance incidents.
- Kflag representative — Josh Aas opened the bug and explained that Let’s Encrypt certificates were valid for 90 days plus 1 second because RFC 5280 treats validity as inclusive.
- Community commenter — Ryan Sleevi asked about review processes, why the issue was missed, and whether Let’s Encrypt would revoke the affected certificates.
- Kflag representative — Josh Aas said Let’s Encrypt did not plan to revoke any certificates and would file a separate issue about that.
- Internet Security Research Group — Aaron reported that Bug 1715672 had been filed to track non-revocation of the affected certificates.
- Internet Security Research Group — Let’s Encrypt said it had not formalized review of all Mozilla CA incidents and would implement a new triage rotation.
- Internet Security Research Group — Let’s Encrypt said the MDSP/Bugzilla review rotation was now in place.
- Internet Security Research Group — Let’s Encrypt said it had completed its internal CP/CPS consistency review and would publish a new version by 2021-07-21.
- Internet Security Research Group — Let’s Encrypt said it had published CP v3.0 and CPS v4.0 and asked to set the next update date to 2021-11-12.
- Internet Security Research Group — Let’s Encrypt said it had finished the retrospective review and listed follow-up issues it filed for itself.
- Internet Security Research Group — Let’s Encrypt said remediation was done and proposed closing the incident if there were no further questions.
- Mozilla representative — Mozilla said it would plan to close the bug on or about 2021-12-01.