← Internet Security Research Group cases
Bugzilla #1715672
Certificate Problem Report
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt faced a situation where they decided not to revoke certain certificates due to exceptional circumstances surrounding their validity period. The CA became aware of the issue during an analysis of a related bug and determined that revoking the certificates would not benefit the Web PKI. Instead, they committed to improving their processes to prevent similar incidents in the future, including the development of an ACME Renewal Info extension. The incident has been resolved, and all affected certificates are set to expire by September 2021.
Chronology
- Incident response begins
- Decision made not to revoke certificates
- Drafting of incident report begins
- All affected certificates set to expire
Participants
Aaron Gable
Ryan Sleevi
Jacob Hoffman-Andrews
Jesse Wilson
External References
Similar Local Cases
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
Let's Encrypt: Incomplete revocation for CAA rechecking bug
Let's Encrypt: TLS Using ALPN TLS Version and OID
Let's Encrypt: Delay updating OCSP responses
Let's Encrypt: OCSP responses with no revocationReason
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: 302 total OCSP responses available beyond acceptable timelines