← Internet Security Research Group cases
Bugzilla #1735247 Certificate Misissuance

Let's Encrypt: Mis-issued certificates related to SC48v2

RESOLVED FIXED Internet Security Research Group
AI Summary

Let's Encrypt identified a mis-issuance of certificates due to a software bug that allowed certain domain labels that violated the new Baseline Requirements effective October 1, 2021. Upon receiving a report on October 11, 2021, they halted issuance, confirmed the issue, and deployed a fix within hours. Affected certificates were revoked promptly, with a total of seven certificates identified as non-compliant. The incident was resolved with a full incident report to follow.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Confidence: 1.00
Chronology
  1. New Baseline Requirements (Ballot SC48v2) went into effect.
  2. Mis-issuance report received; issuance halted.
  3. Fix deployed and issuance restored.
  4. Audit revealed 7 affected certificates, which were revoked.
Participants
Jillian Karner Brett Wilson
Similar Local Cases
#1752670 RESOLVED Certificate Misissuance Opened 2022-01-29 · Closed 2024-05-09 · 60% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#2038351 ASSIGNED Certificate Misissuance Opened 2026-05-08 Still Open · 52% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 51% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1398427 RESOLVED Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 50% similar
Let's Encrypt: CAA Misissuances
#1836443 RESOLVED Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 48% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 48% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1922906 RESOLVED Certificate Misissuance Opened 2024-10-05 · Closed 2025-02-12 · 44% similar
FNMT: LDAP URI in CRL Distribution Points Extension
#1856591 RESOLVED Certificate Misissuance Opened 2023-10-03 · Closed 2024-01-26 · 43% similar
Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action