Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt identified issues with its Certificate Revocation List (CRL) infrastructure, including a period where CRLs contained only 10% of unexpired and revoked certificates, violating BRs Section 4.10.1. The CA proactively disclosed this incident, detailing the timeline and actions taken to resolve the issues. The first issue was resolved, and a full incident report was provided. Additionally, Let's Encrypt reported inconsistent CRLs across partitions for about 28 days, which was not deemed a compliance violation by root programs. Remediation efforts included deploying fixes and monitoring systems to prevent future occurrences. The case has been marked as resolved.
- Let's Encrypt disclosed issues with CRL completeness and consistency.
- Let's Encrypt provided a detailed incident report and remediation plan.
- External monitoring for CRLs was deployed.
- Internet Security Research Group — Let’s Encrypt detected issues affecting CRLs, including incomplete entries.
- Internet Security Research Group — Incident report detailing the CRL issues was submitted.
- Internet Security Research Group — External monitoring system for CRLs was successfully deployed.