← Internet Security Research Group cases
Bugzilla #1735247 Ca Certificate Compliance Certificate Misissuance

Let's Encrypt: Mis-issued certificates related to SC48v2

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that Let’s Encrypt issued certificates that were not compliant with the Baseline Requirements revision SC48v2 after it became effective on 2021-10-01. The SC48v2 ballot required that the Fully-Qualified Domain Name (or wildcard FQDN portion) consist solely of Domain Labels that are P-Labels or Non-Reserved LDH Labels. Let’s Encrypt determined it missed a case where a Reserved LDH Label could be allowed when a hyphen is its second character, leading to issuance of domains like `a---foo.example.com`. After a mis-issuance report was received on 2021-10-11, Let’s Encrypt stopped issuance while reviewing the report and deployed a fix to restore issuance. An audit found 7 affected certificates, and the certificates were revoked within 24 hours of the problem report. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.90 4 comments
Chronology
  1. Baseline Requirements revision SC48v2 became effective, introducing a new FQDN/wildcard domain-label constraint.
  2. Let’s Encrypt received a report that it had potentially mis-issued certificates related to SC48v2.
  3. Let’s Encrypt deployed a fix and restored issuance services.
  4. An audit identified 7 affected certificates and they were revoked within 24 hours of the report.
Thread Activity
  1. Internet Security Research Group — Reported that Let’s Encrypt received and confirmed a mis-issuance report related to SC48v2, stopped issuance, and was writing a patch, restoring issuance, and reviewing certificates for revocation.
  2. Internet Security Research Group — Noted that a fix was released and issuance services were restored, and that a full incident report with mis-issued certificate information and revocation status would be posted within 24 hours.
  3. Internet Security Research Group — Provided an incident summary stating SC48v2’s effective-date requirement, the specific reserved-label edge case missed by code, that 7 certificates were affected, and that they were revoked within 24 hours; included links to crt.sh entries for the certificates.
  4. Mozilla representative — Stated they would close the bug next Wednesday (20-Oct-2021) unless there were follow-up questions or objections.
Participants
Internet Security Research Group Mozilla representative Community commenter
Similar Local Cases
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 91% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance
#1462735 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 90% similar
Let's Encrypt: Case-sensitive CAA tag processing
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 89% similar
Let's Encrypt: CAA Misissuances
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 88% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 88% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
#1789521 RESOLVED Certificate Misissuance Opened 2022-09-06 · Closed 2024-05-09 · 87% similar
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 87% similar
Let's Encrypt: Duplicate Serial Numbers
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 79% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action