← Internet Security Research Group cases
Bugzilla #1795483 Delayed Revocation

Let's Encrypt: Delayed revocation for removed gTLD

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let's Encrypt reported that it did not revoke three subscriber certificates within the 5-day revocation timeline required by BRs Section 4.9.1.1 after the relevant gTLD was removed from the root zone. The affected certificates contained names whose use became no longer permitted once their gTLD was removed. Let's Encrypt stated that it later revoked the three certificates and expected to post a complete incident report. In the incident report, Let's Encrypt described how it monitors ICANN’s gTLD list and how automation notified SRE of the `.cancerresearch` gTLD removal on October 6, 2022, but the certificates remained unrevoked past the 5-day window. The report also states that Let's Encrypt stopped issuance for names under the `.cancerresearch` gTLD and revoked the affected certificates. The remediation items were completed when Let's Encrypt updated its gTLD removal alert runbook on 2022-11-23 to include revoking any remaining valid certificates and highlighting required response time, and the bug was marked as FIXED/RESOLVED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.90 8 comments
Chronology
  1. ICANN removed the `.cancerresearch` gTLD from the root zone, and automation notified Let's Encrypt SRE.
  2. The 5-day revocation window for `.cancerresearch` certificates closed without revocation of three still-valid certificates.
  3. Let's Encrypt revoked the affected `.cancerresearch` certificates and confirmed no additional affected certificates under other recently removed gTLDs.
  4. Let's Encrypt updated its gTLD removal alert runbook to ensure timely revocation of remaining valid certificates.
Thread Activity
  1. Renken representative — Let's Encrypt said it identified a failure to revoke three certificates within the 5-day BRs Section 4.9.1.1 timeline after their gTLD was removed, and stated it had revoked them while expecting to post a complete incident report.
  2. Renken representative — Let's Encrypt provided an incident report describing monitoring of ICANN’s gTLD list, the `.cancerresearch` removal timeline, and that three certificates remained valid past the 5-day window before being revoked.
  3. Renken representative — The reporter stated they were continuing to work on remediation items and monitoring the bug for questions.
  4. Renken representative — The reporter repeated that remediation work was ongoing and asked for others’ thoughts on the intent/meaning of BRs Section 4.9.1.1.
  5. Renken representative — The reporter said remediation items were expected to be completed shortly.
  6. Renken representative — The reporter reiterated remediation was ongoing and set a target date of 2022-11-23.
  7. Renken representative — The reporter said remediation items were completed after updating the gTLD removal alert runbook on 2022-11-23 and asked that the bug be closed.
  8. Mozilla representative — Mozilla stated they would take a look at closing the bug on Wed 30-Nov-2022 unless there were issues or questions.
Participants
Renken representative Mozilla representative
Similar Local Cases
#1799755 RESOLVED Delayed Revocation Opened 2022-11-08 · Closed 2024-05-09 · 89% similar
Let's Encrypt: End Entity CRLs Not Reissued On Time
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1715672 RESOLVED Delayed Revocation Opened 2021-06-10 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 84% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1619179 RESOLVED Delayed Revocation Opened 2020-03-02 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Incomplete revocation for CAA rechecking bug
#1627614 RESOLVED Delayed Revocation Opened 2020-04-06 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1798812 RESOLVED Delayed Revocation Opened 2022-11-02 · Closed 2023-05-04 · 72% similar
CFCA: Delayed reporting of revocation of an intermediate CA certificate
#1886442 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2024-06-01 · 72% similar
Certigna: Revocation delay for TLS certificates with basic constraint not marked as critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action