← Internet Security Research Group cases
Bugzilla #1838667 Certificate Misissuance

Let's Encrypt: Duplicate Serial Numbers

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt reported that it issued certificates with duplicate serial numbers. The issue was triggered by a subscriber certificate profile configuration change that removed the ISRG CPS OID and related CPS URL from the Certificate Policies extension; during the deployment window, a single ACME order finalization flow could produce a precertificate and final certificate with the same serial number but mismatched Certificate Policies extensions. Let’s Encrypt halted issuance while investigating, confirmed the issue was transient and limited to the deploy period, and then resumed issuance. It identified a preliminary set of 645 affected serial numbers and stated it would revoke the affected certificates within 5 days and post a full incident report by 2023-06-20. The incident report attachment describes the BRs requirement violated (precertificate extensions must be byte-for-byte identical to the certificate extensions, with specified exceptions) and notes that 645 affected serials were revoked by 2023-06-19. Let’s Encrypt later reported that an explicit correspondence check change had been deployed to Production to remediate the incident and asked that the bug be closed if no further questions remained.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.86 9 comments
Chronology
  1. Let’s Encrypt deployed a certificate profile configuration change that temporarily allowed precertificate and final certificate mismatches, resulting in duplicate serial numbers.
  2. Let’s Encrypt halted issuance to investigate the duplicate-serial-number incident and later resumed issuance after confirming it was transient.
  3. Let’s Encrypt revoked all affected certificates (645 serials) as part of incident remediation.
  4. Let’s Encrypt deployed a remediation (explicit correspondence check) to Production and requested closure.
Thread Activity
  1. Mm representative — Reported that Let's Encrypt issued certificates with duplicate serial numbers and provided two certspotter URLs for the two certificates.
  2. Internet Security Research Group — Explained that during a subscriber certificate profile deployment, a single ACME finalization flow could produce a precertificate and final certificate with the same serial number but different Certificate Policies extension contents; stated issuance was halted, issue confirmed transient, 645 affected serials identified, revocation planned within 5 days, and a full incident report to be posted by 2023-06-20.
  3. Sectigo — Shared a gist of Sectigo Go code for constructing final TBSCertificate from the corresponding precertificate and asked if the approach had been considered.
  4. Internet Security Research Group — Acknowledged considering the approach and said the incident would be reflected in a root cause analysis write-up.
  5. Internet Security Research Group — Provided attachments related to precertificate and certificate URLs for affected serials.
  6. Internet Security Research Group — Reported that an explicit correspondence check change was deployed to Production and asked that the bug be closed if no further questions remained.
  7. Mozilla representative — Indicated the bug would be closed next week unless issues still needed discussion.
Participants
Mm representative Internet Security Research Group Sectigo Mozilla representative
Similar Local Cases
#1789521 RESOLVED Certificate Misissuance Opened 2022-09-06 · Closed 2024-05-09 · 95% similar
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 94% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 89% similar
Let's Encrypt: CAA Misissuances
#1735247 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 84% similar
Entrust: EV TLS Certificate cPSuri missing
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 84% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1462735 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 81% similar
Let's Encrypt: Case-sensitive CAA tag processing
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 79% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action