← Internet Security Research Group cases
Bugzilla #1838667 Certificate Problem Report

Let's Encrypt: Duplicate Serial Numbers

RESOLVED FIXED Internet Security Research Group
AI Summary

Let's Encrypt encountered an issue where certificates were issued with duplicate serial numbers due to a configuration change that removed certain extensions from the Certificate Policies. This incident was identified on June 15, 2023, when a user reported the problem. The organization halted issuance, confirmed the issue was transient, and resumed operations after identifying 645 affected serial numbers. A full incident report was promised by June 20, 2023, and all affected certificates were revoked within five days.

Model: gpt-4o-mini Generated: 2026-06-13 21:18 UTC Confidence: 0.90
Chronology
  1. Incident reported and issuance halted
  2. Full incident report promised
  3. All affected certificates revoked
  4. Remediation items completed
Participants
Andrew Ayer Jacob Hoffman-Andrews Aaron Gable Rob Stradling Brett Wilson
Similar Local Cases
#1715672 RESOLVED Certificate Problem Report Opened 2021-06-10 · Closed 2023-02-22 · 66% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1753123 RESOLVED Certificate Problem Report Opened 2022-02-01 · Closed 2023-01-04 · 66% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1729567 RESOLVED Certificate Problem Report Opened 2021-09-07 · Closed 2023-02-22 · 65% similar
Let's Encrypt: Delay updating OCSP responses
#1793114 RESOLVED Certificate Problem Report Opened 2022-09-30 · Closed 2023-02-22 · 65% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1809382 RESOLVED Certificate Problem Report Opened 2023-01-10 · Closed 2023-09-29 · 64% similar
CFCA: Certificate with wrong crlDistributionPoints
#1619047 RESOLVED Certificate Problem Report Opened 2020-02-29 · Closed 2023-02-22 · 61% similar
Let's Encrypt: CAA Rechecking bug
#1886876 RESOLVED Certificate Problem Report Opened 2024-03-21 · Closed 2024-04-17 · 58% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1577652 RESOLVED Certificate Problem Report Opened 2019-08-29 · Closed 2022-11-14 · 58% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action