← Internet Security Research Group cases
Bugzilla #1886876 Self Reported Incident Policy Document Issue

Let's Encrypt: keyCompromise key blocking deviation from CP/CPS

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

During a quarterly review of its Certificate Policy/Certification Practice Statement (CP/CPS), Let's Encrypt discovered a discrepancy regarding the handling of revocation requests with the reason 'keyCompromise'. The CA's software did not block keys as committed in its CP/CPS for certain revocation requests, which was identified as a compliance failure. Let's Encrypt has since updated its CP/CPS to accurately reflect its practices, revoked the necessary certificates, and blocked the affected keys. The CA has completed all remediation actions and does not intend to provide further updates.

Model: gpt-4o-mini Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 14 comments
Chronology
  1. Let's Encrypt's Policy Management Authority discovered a compliance failure during a CP/CPS review.
  2. All keys that should have been blocked were successfully blocked.
  3. Automation for CP/CPS review when new feature flags are introduced was established.
Thread Activity
  1. Insufficient representative — Preliminary Incident Report issued detailing the discovery of the discrepancy.
  2. Internet Security Research Group — Incident Report provided, outlining the impact and corrective actions taken.
  3. Internet Security Research Group — Update on the completion of all remediation items related to the incident.
  4. Mozilla representative — Indicated intention to close the bug if no further questions arise.
Participants
Insufficient representative Internet Security Research Group Community commenter Netmeister representative Mozilla representative
External References
Similar Local Cases
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 100% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 96% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 96% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 95% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 95% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 95% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 95% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 94% similar
Let's Encrypt: Early CRL Removal Incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action