← Internet Security Research Group cases
Bugzilla #1793114 Self Reported Incident

Let's Encrypt: Incomplete and Inconsistent CRLs

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let's Encrypt identified issues with its Certificate Revocation List (CRL) infrastructure, including a period where CRLs contained only 10% of unexpired and revoked certificates, violating BRs Section 4.10.1. The CA proactively disclosed this incident, detailing the timeline and actions taken to resolve the issues. The first issue was resolved, and a full incident report was provided. Additionally, Let's Encrypt reported inconsistent CRLs across partitions for about 28 days, which was not deemed a compliance violation by root programs. Remediation efforts included deploying fixes and monitoring systems to prevent future occurrences. The case has been marked as resolved.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.90 23 comments
Chronology
  1. Let's Encrypt disclosed issues with CRL completeness and consistency.
  2. Let's Encrypt provided a detailed incident report and remediation plan.
  3. External monitoring for CRLs was deployed.
Thread Activity
  1. Internet Security Research Group — Let’s Encrypt detected issues affecting CRLs, including incomplete entries.
  2. Internet Security Research Group — Incident report detailing the CRL issues was submitted.
  3. Internet Security Research Group — External monitoring system for CRLs was successfully deployed.
Participants
Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 97% similar
Let's Encrypt: Early CRL Removal Incident
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 96% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 96% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 96% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 96% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 93% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 92% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 89% similar
Let's Encrypt: CAA Rechecking bug

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action