← Internet Security Research Group cases
Bugzilla #1838667
Certificate Problem Report
Let's Encrypt: Duplicate Serial Numbers
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt encountered an issue where certificates were issued with duplicate serial numbers due to a configuration change that removed certain extensions from the Certificate Policies. This incident was identified on June 15, 2023, when a user reported the problem. The organization halted issuance, confirmed the issue was transient, and resumed operations after identifying 645 affected serial numbers. A full incident report was promised by June 20, 2023, and all affected certificates were revoked within five days.
Chronology
- Incident reported and issuance halted
- Full incident report promised
- All affected certificates revoked
- Remediation items completed
Participants
Andrew Ayer
Jacob Hoffman-Andrews
Aaron Gable
Rob Stradling
Brett Wilson
External References
Similar Local Cases
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Delay updating OCSP responses
Let's Encrypt: Incomplete and Inconsistent CRLs
CFCA: Certificate with wrong crlDistributionPoints
Let's Encrypt: CAA Rechecking bug
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates