Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
This case involves Let's Encrypt's failure to revoke certain certificates that were not compliant with the Baseline Requirements due to a certificate lifetime incident. Let's Encrypt became aware of the issue during the analysis of Bug 1715455 and decided not to revoke the affected certificates, citing exceptional circumstances. The CA has committed to ensuring that the issue will be included in their next audit statement and is working on implementing the ACME Renewal Info (ARI) extension to improve future certificate management. The incident has been resolved, with all affected certificates expected to expire by September 7, 2021.
- Incident response for Bug 1715455 begins
- All affected certificates expected to expire
- Internet Security Research Group — We became aware that we would not be revoking these certificates during our analysis of Bug 1715455.
- Mm representative — Responses similar to 'we do not deem this non-compliant certificate to be a security risk' are not acceptable.
- Community commenter — This doesn't appear to provide the required detail.
- Internet Security Research Group — We're planning to update by Tuesday 2021-06-15 6pm PDT with more information and plans.
- Internet Security Research Group — We intend to deploy a demonstration version of ACME Renewal Info (ARI) by 2021-11-12.
- Internet Security Research Group — The draft ACME Renewal Information (ARI) spec has received good discussion.
- Internet Security Research Group — We consider remediation done on this incident and propose closing if there are no followup questions.