Once Revoked Let's Encrypt Certificate Actively Signing Malware
The bug was opened with an allegation that an older Let’s Encrypt certificate (and an alternate version) is “actively signing malware.” The reporter provided VirusTotal relations and other references, and argued that the certificate should not be reintroduced to public trust. Mozilla CA Program staff asked for evidence of private key compromise or misuse, noting that public certificates can be copied and misused and that the primary concern is private key handling and use. After reviewing the references provided, Mozilla staff stated they still could not identify any CA-related vulnerability, exploit, or threat, and suggested the allegation was unsubstantiated. The bug was intended to be closed as Invalid, and the current resolution is INVALID. The thread also includes additional links and discussion from the reporter, but Mozilla staff continued to request a CA-related concern beyond public bundling with malware.
- A bug was filed alleging that a Let’s Encrypt certificate is being used to sign malware.
- Mozilla staff indicated an intent to close the bug as Invalid.
- The bug was resolved as INVALID.
- Community commenter — Filed the report claiming an old Let’s Encrypt CA/certificate is actively signing malware and provided VirusTotal and other references.
- Mozilla representative — Asked for evidence of private key compromise or misuse and said the allegation about malware signing was unsubstantiated based on public certificate bundling.
- Mozilla representative — Stated an intent to close the bug on Wed 27-Sep-2023 as Invalid.
- Community commenter — Responded with additional links and references, including a related older Bugzilla thread and other web pages.
- Mozilla representative — Said they still could not identify any CA-related vulnerability, exploit, or threat and asked what other concern existed.
- Community commenter — Added more references and argued that previously revoked certificates being distributed by malware is significant.
- Community commenter — Provided a Mozilla TLS Observatory certs/description link for the ISRG Root X1 certificate.