← Internet Security Research Group cases
Bugzilla #1799755 Delayed Revocation

Let's Encrypt: End Entity CRLs Not Reissued On Time

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that Let’s Encrypt failed to update and reissue end-entity CRLs for its R3 and E1 intermediates for approximately 11 days, from 2022-10-27 15:55:40 UTC to 2022-11-08 06:11 UTC. For the last four days of this period, Let’s Encrypt stated it was in violation of BR 4.9.7, which requires CRL reissuance at least once every seven days when a CA publishes a CRL. Let’s Encrypt resumed publishing up-to-date CRLs at 2022-11-08 06:11 UTC after incident response actions. The thread states that revoked certificates during the affected period were not reflected in a CRL until the update occurred, affecting 96,354 revoked certificates, while up-to-date revocation status was available via OCSP. Let’s Encrypt also referenced remediation work, including completion of a remediation item (“Deploy External CRL Monitor”) and completion of the last three remediation items by 2022-12-07. Mozilla indicated it planned to close the bug on or about 2022-12-09, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.86 8 comments
Chronology
  1. Let’s Encrypt published the last CRL update for its R3 and E1 intermediates before the delayed reissuance period began.
  2. Let’s Encrypt resumed publishing up-to-date CRLs after completing incident response.
  3. Let’s Encrypt reported completion of the last three remediation items and that no further updates were planned.
Thread Activity
  1. Community commenter — Let’s Encrypt reported that it had failed to update published CRLs for about 11 days and said it resumed publishing up-to-date CRLs at 06:11 UTC on 2022-11-08, thanking Sam Harrington and Ryan Dickson for reporting.
  2. Community commenter — Let’s Encrypt created an attachment listing affected certificate URLs.
  3. Community commenter — Let’s Encrypt said the incident report was prepared but still undergoing internal review and would be posted within 24 hours.
  4. Community commenter — Let’s Encrypt posted the incident report describing the period of delayed CRL updates, the BR 4.9.7 violation for the last four days, and the remediation timeline.
  5. Community commenter — Let’s Encrypt stated the remediation item “Deploy External CRL Monitor” was completed and marked it as done.
  6. Internet Security Research Group — Let’s Encrypt said it was continuing to work on remediation items and expected to finish the last three by 2022-12-16.
  7. Community commenter — Let’s Encrypt reported that the last three remediation items were completed and that the incident remediation was finished, with no further updates planned.
  8. Mozilla representative — Mozilla stated it planned to close the bug on or about 9-Dec-2022.
Participants
Insufficient representative Internet Security Research Group Community commenter Mozilla representative
Similar Local Cases
#1795483 RESOLVED Delayed Revocation Opened 2022-10-14 · Closed 2023-02-22 · 89% similar
Let's Encrypt: Delayed revocation for removed gTLD
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 86% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1715672 RESOLVED Delayed Revocation Opened 2021-06-10 · Closed 2023-02-22 · 86% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1627614 RESOLVED Delayed Revocation Opened 2020-04-06 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1619179 RESOLVED Delayed Revocation Opened 2020-03-02 · Closed 2023-02-22 · 79% similar
Let's Encrypt: Incomplete revocation for CAA rechecking bug
#1818073 RESOLVED Delayed Revocation Opened 2023-02-21 · Closed 2023-06-28 · 71% similar
Sectigo: Late revocation for incomplete Subject organizationName
#1797165 RESOLVED Delayed Revocation Opened 2022-10-24 · Closed 2023-02-22 · 71% similar
DigiCert: Delayed Revocation of ~5.5 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action