Let's Encrypt: End Entity CRLs Not Reissued On Time
This case reports that Let’s Encrypt failed to update and reissue end-entity CRLs for its R3 and E1 intermediates for approximately 11 days, from 2022-10-27 15:55:40 UTC to 2022-11-08 06:11 UTC. For the last four days of this period, Let’s Encrypt stated it was in violation of BR 4.9.7, which requires CRL reissuance at least once every seven days when a CA publishes a CRL. Let’s Encrypt resumed publishing up-to-date CRLs at 2022-11-08 06:11 UTC after incident response actions. The thread states that revoked certificates during the affected period were not reflected in a CRL until the update occurred, affecting 96,354 revoked certificates, while up-to-date revocation status was available via OCSP. Let’s Encrypt also referenced remediation work, including completion of a remediation item (“Deploy External CRL Monitor”) and completion of the last three remediation items by 2022-12-07. Mozilla indicated it planned to close the bug on or about 2022-12-09, and the bug is marked RESOLVED with resolution FIXED.
- Let’s Encrypt published the last CRL update for its R3 and E1 intermediates before the delayed reissuance period began.
- Let’s Encrypt resumed publishing up-to-date CRLs after completing incident response.
- Let’s Encrypt reported completion of the last three remediation items and that no further updates were planned.
- Community commenter — Let’s Encrypt reported that it had failed to update published CRLs for about 11 days and said it resumed publishing up-to-date CRLs at 06:11 UTC on 2022-11-08, thanking Sam Harrington and Ryan Dickson for reporting.
- Community commenter — Let’s Encrypt created an attachment listing affected certificate URLs.
- Community commenter — Let’s Encrypt said the incident report was prepared but still undergoing internal review and would be posted within 24 hours.
- Community commenter — Let’s Encrypt posted the incident report describing the period of delayed CRL updates, the BR 4.9.7 violation for the last four days, and the remediation timeline.
- Community commenter — Let’s Encrypt stated the remediation item “Deploy External CRL Monitor” was completed and marked it as done.
- Internet Security Research Group — Let’s Encrypt said it was continuing to work on remediation items and expected to finish the last three by 2022-12-16.
- Community commenter — Let’s Encrypt reported that the last three remediation items were completed and that the incident remediation was finished, with no further updates planned.
- Mozilla representative — Mozilla stated it planned to close the bug on or about 9-Dec-2022.