← Internet Security Research Group cases
Bugzilla #1886876
Certificate Problem Report
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
RESOLVED
FIXED
Internet Security Research Group
AI Summary
During a quarterly review, Let's Encrypt identified a discrepancy between their documented revocation policy for key compromises and their actual software behavior. The incident revealed that 18,333 revocation requests were processed incorrectly, leading to keys not being blocked as required. Although issuance of certificates was not halted, the team has since updated their CP/CPS to align with their operational practices and has completed necessary remediation actions, including blocking the affected keys and revoking certificates that should have been revoked.
Chronology
- Discrepancy discovered during CP/CPS review
- CP/CPS updated to reflect actual behavior
- All affected keys blocked
- Automation for CP/CPS review established
Participants
J.C. Jones [:jcj]
Aaron Gable
Mathew Hodson
Chris Wilson
External References
Similar Local Cases
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: End Entity CRLs Not Reissued On Time
Let's Encrypt: TLS Using ALPN TLS Version and OID
Certainly: Serving invalid or incomplete CRLs