← Internet Security Research Group cases
Bugzilla #1742704 Incident Self Reported Incident

Let's Encrypt: Potential Denial of Service against websites with broad private key reuse

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt reported that it discovered a bug in its ACME implementation that affected certificate revocation. The issue was triggered when a subscriber revoked a certificate using the revocation reason "keyCompromise"; due to the bug, the revoker only proved control of the FQDNs rather than the certificate private key, which then caused cascading revocation of other certificates based on the SPKI hash. In the reported incident, the SPKI hash matched approximately 130,000 certificates, and the automated revocation stressed Let’s Encrypt’s systems and led to alerts investigated by SRE. Let’s Encrypt deployed a patch within eight hours of discovering the bug and also began work on a hotfix, including identifying CPS Section 4.9.12 and deciding not to stop the revoke endpoint because doing so would be a policy violation more severe than the potential denial of service. The bug was filed as a responsible disclosure, and the case is marked RESOLVED with resolution FIXED. A later comment indicated the bug could be made publicly viewable, and Mozilla stated it would close the bug unless additional comments were provided.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.90 3 comments
Chronology
  1. A subscriber revoked a certificate with reason "keyCompromise", triggering cascading automated revocation of ~130,000 certificates due to an ACME revocation bug.
  2. Let’s Encrypt identified the issue, confirmed behavior in staging, and began work on a hotfix.
  3. Let’s Encrypt merged a hotfix after deciding not to stop the revoke endpoint to avoid a policy violation.
Thread Activity
  1. Community commenter — J.C. Jones [:jcj] reported the ACME revocation bug, described how "keyCompromise" revocations cascaded based on SPKI hash, provided an incident timeline, and linked to a hotfix/patch commit.
  2. Kflag representative — j**********s@kflag.net said the information could be made publicly viewable now.
  3. Community commenter — Ben Wilson said he would close the bug the next day unless there were additional comments or questions.
Participants
Insufficient representative Kflag representative Mozilla representative
Similar Local Cases
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 96% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 95% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 95% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 91% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1576789 RESOLVED Self Reported Incident Validation Issue Opened 2019-08-27 · Closed 2024-05-09 · 89% similar
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 89% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 88% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 88% similar
Let's Encrypt: Early CRL Removal Incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action