← Internet Security Research Group cases
Bugzilla #1753123 Revocation Issue Self Reported Incident

Let's Encrypt: Failure to provide OCSP Responses for some certificates

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-disclosed incident by Let’s Encrypt involving a failure to provide OCSP responses for a small number of certificates. During remediation of Bug 1751984, Let’s Encrypt discovered database entries that had precertificate data but no corresponding certificate status (OCSP response) data, and these certificates therefore never had OCSP data available. As a result, requests for their OCSP responses returned an “unauthorized” response, which Let’s Encrypt described as a violation of BR Section 4.10.2 requiring a service to automatically check the current status of all unexpired certificates issued by the CA. Let’s Encrypt investigated, identified 132 affected unexpired certificates, and determined the root cause. The CA then generated and began serving OCSP responses for the affected certificates, merged and deployed a fix to prevent certificates without corresponding OCSP status information from being stored, and confirmed that all unexpired certificates have available OCSP responses. The bug was resolved as FIXED, and Let’s Encrypt reported completion of committed remediation items after an audit of error assignments inside closures.

Model: gpt-5.4-nano Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:22 UTC Confidence: 0.90 4 comments
Chronology
  1. A Boulder change was deployed to production that later led to certificates being stored without corresponding OCSP status data.
  2. Let’s Encrypt discovered missing OCSP response storage for affected certificates and began generating and serving OCSP responses, along with deploying fixes.
Thread Activity
  1. Internet Security Research Group — Created the incident report explaining that affected certificates had no OCSP response data, causing OCSP requests to return “unauthorized,” and described remediation steps including generating/serving OCSP responses and deploying a fix.
  2. Internet Security Research Group — Provided a weekly update listing remediation items and statuses, including publishing OCSP responses for affected certificates and adding metrics for unauthorized response codes.
  3. Internet Security Research Group — Reported completion of the audit of error assignments inside closures and asked to close the issue if no further questions remained.
  4. Mozilla representative — Indicated intent to close the bug on 23-Feb-2022 unless concerns remained.
Participants
Internet Security Research Group Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 97% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 96% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 96% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 95% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 95% similar
Let's Encrypt: Early CRL Removal Incident
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 94% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1486650 RESOLVED Self Reported Incident Revocation Issue Opened 2018-08-27 · Closed 2023-02-22 · 90% similar
Let's Encrypt: OCSP "unauthorized" responses
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 90% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action