← Internet Security Research Group cases
Bugzilla #1753123
Certificate Problem Report
Let's Encrypt: Failure to provide OCSP Responses for some certificates
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt identified a failure to provide OCSP responses for a small number of certificates due to a bug in their system. This issue was discovered while revoking certificates, leading to the realization that 132 certificates issued between December 2, 2021, and January 29, 2022, lacked corresponding OCSP data. The CA has since populated the missing OCSP responses and implemented fixes to prevent future occurrences. The incident has been resolved with all affected certificates now having available OCSP responses.
Chronology
- Bug introduced to Boulder
- Bug deployed to Production (Incident Begins)
- Discovery of missing OCSP responses
- OCSP responses generated for affected certificates
- Audit of error checks completed
- Case closure proposed
Participants
Aaron Gable
Brett Wilson
External References
Similar Local Cases
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: Delay updating OCSP responses
CFCA: Certificate with wrong crlDistributionPoints
Certainly: Serving Expired OCSP Responses
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: TLS Using ALPN TLS Version and OID