← Certainly LLC cases
Bugzilla #1752452
Self Reported Incident
Certainly: TLS Using ALPN TLS Version and OID
RESOLVED
FIXED
Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Certainly LLC discovered a vulnerability related to the TLS-ALPN-01 validation method after being notified of a related issue by Let’s Encrypt. Following this, Certainly disabled the affected validation method and revoked all certificates that relied on it. The incident was declared on January 25, 2022, and all affected certificates were revoked by January 26, 2022. A full incident report was prepared and shared, detailing the timeline of actions taken and the nature of the certificates involved. The CA has since completed remediation efforts and is monitoring the situation.
Chronology
- Certainly declares an incident after assessing vulnerability to TLS-ALPN-01 method.
- All affected certificates are revoked.
- Certainly completes remediation of the incident.
Thread Activity
- Fastly representative — Certainly was notified of a vulnerability and took immediate action to revoke affected certificates.
- Nekollc representative — Questions raised regarding the timing of certificate revocations.
- Mozilla representative — Indicated intention to close the case unless further concerns arise.
Participants
Community commenter
External References
Similar Local Cases
Certainly: Early CRL Entry Removal
Certainly: Sample Websites Unavailable
Sectigo: "Some-State" in stateOrProvinceName
Certainly: Expired certificates on "Valid" and "Revoked" test websites
Certainly: Missing audit log entries for certificates issued during capacity testing
Trustis: Non-Br-Compliant OCSP Responder
SwissSign: Undisclosed Intermediate Certificates
Kamu SM: "Some-State" in stateOrProvinceName