← Internet Security Research Group cases
Bugzilla #1886876
Self Reported Incident
Policy Document Issue
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
RESOLVED
FIXED
Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
During a quarterly review of its Certificate Policy/Certification Practice Statement (CP/CPS), Let's Encrypt discovered a discrepancy regarding the handling of revocation requests with the reason 'keyCompromise'. The CA's software did not block keys as committed in its CP/CPS for certain revocation requests, which was identified as a compliance failure. Let's Encrypt has since updated its CP/CPS to accurately reflect its practices, revoked the necessary certificates, and blocked the affected keys. The CA has completed all remediation actions and does not intend to provide further updates.
Chronology
- Let's Encrypt's Policy Management Authority discovered a compliance failure during a CP/CPS review.
- All keys that should have been blocked were successfully blocked.
- Automation for CP/CPS review when new feature flags are introduced was established.
Thread Activity
- Insufficient representative — Preliminary Incident Report issued detailing the discovery of the discrepancy.
- Internet Security Research Group — Incident Report provided, outlining the impact and corrective actions taken.
- Internet Security Research Group — Update on the completion of all remediation items related to the incident.
- Mozilla representative — Indicated intention to close the bug if no further questions arise.
Participants
Insufficient representative
Internet Security Research Group
Community commenter
Netmeister representative
Mozilla representative
External References
Similar Local Cases
Let's Encrypt: No Meaningful Subject Distinguished Name
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
Let's Encrypt: TLS Using ALPN TLS Version and OID
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
Let's Encrypt: Early CRL Removal Incident