Let's Encrypt: Failure to provide OCSP Responses for some certificates
This case is a self-disclosed incident by Let’s Encrypt involving a failure to provide OCSP responses for a small number of certificates. During remediation of Bug 1751984, Let’s Encrypt discovered database entries that had precertificate data but no corresponding certificate status (OCSP response) data, and these certificates therefore never had OCSP data available. As a result, requests for their OCSP responses returned an “unauthorized” response, which Let’s Encrypt described as a violation of BR Section 4.10.2 requiring a service to automatically check the current status of all unexpired certificates issued by the CA. Let’s Encrypt investigated, identified 132 affected unexpired certificates, and determined the root cause. The CA then generated and began serving OCSP responses for the affected certificates, merged and deployed a fix to prevent certificates without corresponding OCSP status information from being stored, and confirmed that all unexpired certificates have available OCSP responses. The bug was resolved as FIXED, and Let’s Encrypt reported completion of committed remediation items after an audit of error assignments inside closures.
- A Boulder change was deployed to production that later led to certificates being stored without corresponding OCSP status data.
- Let’s Encrypt discovered missing OCSP response storage for affected certificates and began generating and serving OCSP responses, along with deploying fixes.
- Internet Security Research Group — Created the incident report explaining that affected certificates had no OCSP response data, causing OCSP requests to return “unauthorized,” and described remediation steps including generating/serving OCSP responses and deploying a fix.
- Internet Security Research Group — Provided a weekly update listing remediation items and statuses, including publishing OCSP responses for affected certificates and adding metrics for unauthorized response codes.
- Internet Security Research Group — Reported completion of the audit of error assignments inside closures and asked to close the issue if no further questions remained.
- Mozilla representative — Indicated intent to close the bug on 23-Feb-2022 unless concerns remained.