← Internet Security Research Group cases
Bugzilla #1751984
Incident
Self Reported Incident
Let's Encrypt: TLS Using ALPN TLS Version and OID
RESOLVED
FIXED
Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
On January 25, 2022, Let's Encrypt was informed of two compliance issues in their TLS-ALPN-01 validation method. The issues involved the minimum negotiated TLS version not being enforced and the acceptance of an outdated OID. Let's Encrypt confirmed both bugs and disabled the TLS-ALPN-01 challenge type for new validations. They initiated revocation of approximately 2 million affected certificates, with a completion deadline set for January 30, 2022. A comprehensive review of the TLS Using ALPN validation method was also started, with updates promised by February 18, 2022.
Chronology
- Let's Encrypt was informed of compliance issues in their TLS-ALPN-01 validation method.
- Revocation of all affected certificates was completed.
- Let's Encrypt promised updates on their comprehensive review of the TLS Using ALPN validation method.
Thread Activity
- Internet Security Research Group — This is a preliminary incident report regarding two irregularities in our TLS-ALPN-01 implementation.
- Community commenter — Questioned the revocation timeline and compliance with Baseline Requirements.
- Internet Security Research Group — Confirmed completion of revocation of all affected certificates.
- Mozilla representative — Indicated intention to close the bug unless further issues arise.
Participants
Internet Security Research Group
Community commenter
Nekollc representative
Thisisntrocket representative
Sectigo
Mozilla representative
External References
Similar Local Cases
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: CAA Rechecking bug
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: Early CRL Removal Incident