← Internet Security Research Group cases
Bugzilla #1921573
Certificate Problem Report
Let's Encrypt: No Meaningful Subject Distinguished Name
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt identified a conflict in their Certificate Policy/Certificate Practice Statement (CP/CPS) regarding the Subject Distinguished Name in their certificates. This conflict arose from a policy change allowing certificates without a Common Name, which contradicted existing statements requiring a meaningful Subject field. Following the discovery, issuance was halted, and an updated CP/CPS was published. A total of 133,613 unexpired certificates were revoked due to this issue, and a full incident report was provided detailing the timeline and impact of the incident.
Chronology
- Conflict discovered in CP/CPS
- Revocation of affected certificates completed
- Full incident report published
- New CP/CPS version published
Participants
Preston Locke
Lena
C. Clements
B. Wilson
External References
Similar Local Cases
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
Let's Encrypt: Delayed revocation for removed gTLD
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: Non-BR-Compliant Certificate Issuance
Let's Encrypt: Improper encoding of wildcard certificates