← Internet Security Research Group cases
Bugzilla #1751984 Certificate Problem Report

Let's Encrypt: TLS Using ALPN TLS Version and OID

RESOLVED FIXED Internet Security Research Group
AI Summary

On January 25, 2022, Let's Encrypt was notified of two compliance issues in their TLS-ALPN-01 challenge implementation, which allowed clients to negotiate TLS versions lower than 1.2 and accepted an outdated OID. Both issues were confirmed and led to the temporary disabling of the TLS-ALPN-01 challenge type. Let's Encrypt initiated revocation of approximately 2 million affected certificates, with a commitment to complete this by January 30, 2022. The issues were addressed with code fixes, and a comprehensive review of the validation method was undertaken to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:16 UTC Confidence: 1.00
Chronology
  1. Received bug report regarding TLS-ALPN-01 compliance issues.
  2. Disabled TLS-ALPN-01 challenge type and began revocation process.
  3. Completed revocation of all affected certificates.
  4. Completed review of TLS Using ALPN validation method.
Participants
Aaron Gable Ryan Sleevi Charles Wang Jr Moir Rob Matthias
Similar Local Cases
#1744827 RESOLVED Certificate Problem Report Opened 2021-12-07 · Closed 2024-03-08 · 64% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses
#1715672 RESOLVED Certificate Problem Report Opened 2021-06-10 · Closed 2023-02-22 · 64% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1729567 RESOLVED Certificate Problem Report Opened 2021-09-07 · Closed 2023-02-22 · 62% similar
Let's Encrypt: Delay updating OCSP responses
#1650845 RESOLVED Certificate Problem Report Opened 2020-07-06 · Closed 2024-06-30 · 60% similar
Sectigo: CPR response issues
#1753123 RESOLVED Certificate Problem Report Opened 2022-02-01 · Closed 2023-01-04 · 59% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1625322 RESOLVED Certificate Problem Report Opened 2020-03-26 · Closed 2023-02-22 · 58% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1793114 RESOLVED Certificate Problem Report Opened 2022-09-30 · Closed 2023-02-22 · 57% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1886876 RESOLVED Certificate Problem Report Opened 2024-03-21 · Closed 2024-04-17 · 56% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action