← Internet Security Research Group cases
Bugzilla #1795483
Certificate Problem Report
Let's Encrypt: Delayed revocation for removed gTLD
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt identified a failure to revoke three certificates within the required five-day period after the removal of the `.cancerresearch` gTLD from the ICANN registry. This oversight was discovered during an investigation into another gTLD, leading to the revocation of the affected certificates. The incident was documented, and remediation steps were taken to prevent future occurrences, including updates to internal processes and alert systems. The issue has been resolved, and Let's Encrypt has committed to monitoring for any further questions or comments.
Chronology
- The `.cancerresearch` gTLD is removed from the root zone.
- The 5-day window for revoking `.cancerresearch` certificates closes.
- Incident report summary posted.
- Remediation items completed.
Participants
James Renken
B. Wilson
External References
Similar Local Cases
Let's Encrypt: No Meaningful Subject Distinguished Name
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Early CRL Removal Incident
Let's Encrypt: 302 total OCSP responses available beyond acceptable timelines
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities