← Internet Security Research Group cases
Bugzilla #1729567
Certificate Problem Report
Let's Encrypt: Delay updating OCSP responses
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt experienced a delay in updating OCSP responses, which fell behind the required schedule due to a misconfigured alert system. The issue was detected on September 5, 2021, and responses were served that did not comply with both the Microsoft Trusted Root Program and Baseline Requirements. The problem was resolved by September 8, 2021, after identifying the root cause and implementing technical mitigations. A full incident report was provided, detailing the timeline and corrective actions taken.
Chronology
- Internal monitoring detected OCSP response update delay.
- Incident response began after awareness of the issue.
- OCSP responses returned to compliance.
- Review of existing alerts completed and changes deployed.
- Bug closed as fixed.
Participants
Aaron Gable
Brett Wilson
Ryan Sleevi
External References
Similar Local Cases
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: TLS Using ALPN TLS Version and OID
Let's Encrypt: 302 total OCSP responses available beyond acceptable timelines
Izenpe: Failure to provide a preliminary report within 24 hours.
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates