← Internet Security Research Group cases
Bugzilla #1715672 Delayed Revocation

Let's Encrypt: Failure to revoke for Certificate Lifetime Incident

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Let's Encrypt's failure to revoke certain certificates that were not compliant with the Baseline Requirements due to a certificate lifetime incident. Let's Encrypt became aware of the issue during the analysis of Bug 1715455 and decided not to revoke the affected certificates, citing exceptional circumstances. The CA has committed to ensuring that the issue will be included in their next audit statement and is working on implementing the ACME Renewal Info (ARI) extension to improve future certificate management. The incident has been resolved, with all affected certificates expected to expire by September 7, 2021.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.85 18 comments
Chronology
  1. Incident response for Bug 1715455 begins
  2. All affected certificates expected to expire
Thread Activity
  1. Internet Security Research Group — We became aware that we would not be revoking these certificates during our analysis of Bug 1715455.
  2. Mm representative — Responses similar to 'we do not deem this non-compliant certificate to be a security risk' are not acceptable.
  3. Community commenter — This doesn't appear to provide the required detail.
  4. Internet Security Research Group — We're planning to update by Tuesday 2021-06-15 6pm PDT with more information and plans.
  5. Internet Security Research Group — We intend to deploy a demonstration version of ACME Renewal Info (ARI) by 2021-11-12.
  6. Internet Security Research Group — The draft ACME Renewal Information (ARI) spec has received good discussion.
  7. Internet Security Research Group — We consider remediation done on this incident and propose closing if there are no followup questions.
Participants
Internet Security Research Group Mm representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1619179 RESOLVED Delayed Revocation Opened 2020-03-02 · Closed 2023-02-22 · 96% similar
Let's Encrypt: Incomplete revocation for CAA rechecking bug
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 95% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1795483 RESOLVED Delayed Revocation Opened 2022-10-14 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Delayed revocation for removed gTLD
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 86% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1799755 RESOLVED Delayed Revocation Opened 2022-11-08 · Closed 2024-05-09 · 86% similar
Let's Encrypt: End Entity CRLs Not Reissued On Time
#1627614 RESOLVED Delayed Revocation Opened 2020-04-06 · Closed 2023-02-22 · 85% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1628292 RESOLVED Delayed Revocation Self Reported Incident Opened 2020-04-08 · Closed 2023-02-22 · 79% similar
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days
#1665763 RESOLVED Delayed Revocation Opened 2020-09-17 · Closed 2023-02-22 · 78% similar
Sectigo: Failure to revoke within 5 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action