← Internet Security Research Group cases
Bugzilla #1751984 Incident Self Reported Incident

Let's Encrypt: TLS Using ALPN TLS Version and OID

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On January 25, 2022, Let's Encrypt was informed of two compliance issues in their TLS-ALPN-01 validation method. The issues involved the minimum negotiated TLS version not being enforced and the acceptance of an outdated OID. Let's Encrypt confirmed both bugs and disabled the TLS-ALPN-01 challenge type for new validations. They initiated revocation of approximately 2 million affected certificates, with a completion deadline set for January 30, 2022. A comprehensive review of the TLS Using ALPN validation method was also started, with updates promised by February 18, 2022.

Model: gpt-4o-mini Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.90 26 comments
Chronology
  1. Let's Encrypt was informed of compliance issues in their TLS-ALPN-01 validation method.
  2. Revocation of all affected certificates was completed.
  3. Let's Encrypt promised updates on their comprehensive review of the TLS Using ALPN validation method.
Thread Activity
  1. Internet Security Research Group — This is a preliminary incident report regarding two irregularities in our TLS-ALPN-01 implementation.
  2. Community commenter — Questioned the revocation timeline and compliance with Baseline Requirements.
  3. Internet Security Research Group — Confirmed completion of revocation of all affected certificates.
  4. Mozilla representative — Indicated intention to close the bug unless further issues arise.
Participants
Internet Security Research Group Community commenter Nekollc representative Thisisntrocket representative Sectigo Mozilla representative
Similar Local Cases
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 100% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 95% similar
Let's Encrypt: CAA Rechecking bug
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 95% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 95% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 95% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 94% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 93% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 92% similar
Let's Encrypt: Early CRL Removal Incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action