← Certainly LLC cases
Bugzilla #1752452
Certificate Problem Report
Certainly: TLS Using ALPN TLS Version and OID
RESOLVED
FIXED
Certainly LLC
AI Summary
Certainly LLC faced a vulnerability related to the TLS-ALPN-01 validation method after being notified by Let’s Encrypt about a related issue. They promptly disabled the affected validations and revoked all certificates that relied on this method. The incident was declared on January 25, 2022, and a total of 337,621 certificates were identified as potentially problematic. A comprehensive incident report was prepared, detailing the timeline of actions taken and the steps to prevent future occurrences.
Chronology
- Incident declared after assessing vulnerability
- All affected certificates revoked
- Incident remediation plan finalized
- Remediation of the incident completed
Participants
Wayne Thayer
Charles Wang
External References
Similar Local Cases
Certainly: Early CRL Entry Removal
Certainly: Serving Expired OCSP Responses
Certainly: Serving invalid or incomplete CRLs
Certainly: Serving Bad OCSP Responses
SECOM: failure to revoke underscores
SECOM: certificate for .test TLD
Let's Encrypt: TLS Using ALPN TLS Version and OID
DigiCert: Verizon: "Default City" in Subject:localityName