← Internet Security Research Group cases
Bugzilla #1789521
Certificate Problem Report
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt identified and resolved an issue involving the issuance of certificates associated with Elliptic Curve Debian Weak Keys. The problem was first highlighted by a security researcher who pointed out that certain versions of OpenSSL, previously thought to be safe, actually supported EC keys. Following this discovery, Let's Encrypt took immediate action to revoke the affected certificates and block the weak keys. The CA has since ceased issuing certificates with these weak keys and has implemented measures to prevent future occurrences.
Chronology
- Security researcher Hanno Böck raised concerns about Debian Weak Key vulnerability.
- Two affected certificates were identified and revoked.
- Let's Encrypt confirmed no further remediation items were needed.
- Request to close the ticket was made.
Participants
agabbitas@letsencrypt.org
aaron@letsencrypt.org
bwilson@mozilla.com
External References
Similar Local Cases
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
Let's Encrypt: Early CRL Removal Incident
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
Once Revoked Let's Encrypt Certificate Actively Signing Malware
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829