Let's Encrypt: Mis-issued certificates related to SC48v2
This case reports that Let’s Encrypt issued certificates that were not compliant with the Baseline Requirements revision SC48v2 after it became effective on 2021-10-01. The SC48v2 ballot required that the Fully-Qualified Domain Name (or wildcard FQDN portion) consist solely of Domain Labels that are P-Labels or Non-Reserved LDH Labels. Let’s Encrypt determined it missed a case where a Reserved LDH Label could be allowed when a hyphen is its second character, leading to issuance of domains like `a---foo.example.com`. After a mis-issuance report was received on 2021-10-11, Let’s Encrypt stopped issuance while reviewing the report and deployed a fix to restore issuance. An audit found 7 affected certificates, and the certificates were revoked within 24 hours of the problem report. The bug was resolved as FIXED.
- Baseline Requirements revision SC48v2 became effective, introducing a new FQDN/wildcard domain-label constraint.
- Let’s Encrypt received a report that it had potentially mis-issued certificates related to SC48v2.
- Let’s Encrypt deployed a fix and restored issuance services.
- An audit identified 7 affected certificates and they were revoked within 24 hours of the report.
- Internet Security Research Group — Reported that Let’s Encrypt received and confirmed a mis-issuance report related to SC48v2, stopped issuance, and was writing a patch, restoring issuance, and reviewing certificates for revocation.
- Internet Security Research Group — Noted that a fix was released and issuance services were restored, and that a full incident report with mis-issued certificate information and revocation status would be posted within 24 hours.
- Internet Security Research Group — Provided an incident summary stating SC48v2’s effective-date requirement, the specific reserved-label edge case missed by code, that 7 certificates were affected, and that they were revoked within 24 hours; included links to crt.sh entries for the certificates.
- Mozilla representative — Stated they would close the bug next Wednesday (20-Oct-2021) unless there were follow-up questions or objections.