Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
This case describes an incident where Let's Encrypt discovered that two certificates were issued whose SPKI matched elliptic curve Debian weak keys associated with the Debian Weak Key vulnerability (CVE-2008-0166). The CA became aware of the underlying issue after a security researcher (Hanno Böck) started a thread in MozDev Security Policy and provided additional information and a repository of private keys generated with a vulnerable OpenSSL version. In response, Let's Encrypt blocked the affected keys and triggered automatic revocation for the two affected certificates, then completed a dry run across 598,824 keys and confirmed no additional affected certificates were found. The CA also deployed a patch to production to support blocking EC keys by using a database table rather than a flat file format. Let's Encrypt stated it stopped issuing certificates with Debian weak ECDSA keys and that all affected keys on the ECP256 and ECP384 curves have been blocked. The bug was resolved as FIXED, with the CA indicating there were no additional remediation items and requesting closure after monitoring.
- Two certificates were issued that matched the SPKI of elliptic curve Debian weak keys (ECP256/ECP384).
- A security researcher notified Mozilla’s MozDev Security Policy about the Debian Weak Key vulnerability’s applicability to EC keys and provided supporting materials.
- Two affected certificates were found and their private keys were manually blocked, triggering automatic revocation.
- Blocking of 598,824 weak keys on the ECP256 and ECP384 curves was completed with no additional certificates found.
- Internet Security Research Group — Opened an incident report describing discovery of two affected certificates, the CA’s blocking and revocation actions, and stating issuance with Debian weak ECDSA keys had stopped.
- Internet Security Research Group — Updated that there were no additional remediation items and that the CA would continue monitoring without further updates unless questions arose.
- Internet Security Research Group — Requested that the ticket be closed because there appeared to be no further questions.
- Mozilla representative — Indicated the ticket would be closed on or about Wed. 26-Oct-2022.