← Internet Security Research Group cases
Bugzilla #1715455 Self Reported Incident

Let’s Encrypt disclosed an off-by-one-second certificate lifetime issue and updated its CP/CPS processes

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt disclosed that its certificates were being issued with a validity period of 90 days plus 1 second because of how Boulder calculated notBefore and notAfter. The issue was first reported to Let’s Encrypt by email from Jesper Kristensen on 2021-06-08, and ISRG declared an internal incident the next day. Let’s Encrypt said it deployed a staging fix and then a production config change on 2021-06-09, after which new certificates used a lifetime of 7,775,999 seconds. The company also stated that it did not stop issuance, and that it would not revoke the affected certificates; it opened Bug 1715672 to track that non-revocation. In follow-up comments, Let’s Encrypt explained its review process, said it had not formalized review of all Mozilla CA incidents, and committed to a new triage rotation for MDSP, Bugzilla, and CABF ballot review. It later reported completing an internal CP/CPS consistency review, publishing updated CP and CPS versions, and finishing a retrospective review of historic CA compliance incidents.

Model: gpt-5.4-mini Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.97 40 comments
Chronology
  1. Let’s Encrypt became aware of an off-by-one-second certificate lifetime issue from an external email report.
  2. ISRG declared an internal incident and deployed a production fix so new certificates used the corrected lifetime.
  3. Let’s Encrypt filed Bug 1715672 to track its decision not to revoke affected certificates.
  4. Let’s Encrypt said its MDSP/Bugzilla review rotation was in place.
  5. Let’s Encrypt published updated CP and CPS versions after its internal consistency review.
  6. Let’s Encrypt reported completion of its retrospective review of historic CA compliance incidents.
Thread Activity
  1. Kflag representative — Josh Aas opened the bug and explained that Let’s Encrypt certificates were valid for 90 days plus 1 second because RFC 5280 treats validity as inclusive.
  2. Community commenter — Ryan Sleevi asked about review processes, why the issue was missed, and whether Let’s Encrypt would revoke the affected certificates.
  3. Kflag representative — Josh Aas said Let’s Encrypt did not plan to revoke any certificates and would file a separate issue about that.
  4. Internet Security Research Group — Aaron reported that Bug 1715672 had been filed to track non-revocation of the affected certificates.
  5. Internet Security Research Group — Let’s Encrypt said it had not formalized review of all Mozilla CA incidents and would implement a new triage rotation.
  6. Internet Security Research Group — Let’s Encrypt said the MDSP/Bugzilla review rotation was now in place.
  7. Internet Security Research Group — Let’s Encrypt said it had completed its internal CP/CPS consistency review and would publish a new version by 2021-07-21.
  8. Internet Security Research Group — Let’s Encrypt said it had published CP v3.0 and CPS v4.0 and asked to set the next update date to 2021-11-12.
  9. Internet Security Research Group — Let’s Encrypt said it had finished the retrospective review and listed follow-up issues it filed for itself.
  10. Internet Security Research Group — Let’s Encrypt said remediation was done and proposed closing the incident if there were no further questions.
  11. Mozilla representative — Mozilla said it would plan to close the bug on or about 2021-12-01.
Participants
Kflag representative Community commenter Lebihan representative Aaronfriel representative Jesperkristensen representative Internet Security Research Group Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 100% similar
Let's Encrypt: CAA Rechecking bug
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 100% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 97% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 97% similar
Let's Encrypt: Early CRL Removal Incident
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 96% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 96% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 95% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 95% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action