Let's Encrypt: No Meaningful Subject Distinguished Name
On September 27, 2024, Let's Encrypt discovered a conflict in their Certificate Policy/Certificate Practice Statement (CP/CPS) regarding the Subject Distinguished Name in their certificates. This conflict arose from changes allowing certificates to be issued without a Common Name, which contradicted existing policy. Following the discovery, issuance was halted, and an updated CP/CPS was published. Let's Encrypt identified 133,613 unexpired certificates affected by this issue and revoked them on October 1, 2024. A full incident report was provided, detailing the timeline and actions taken to resolve the issue, including a review and update of their CP/CPS.
- Let's Encrypt discovers a conflict in their CP/CPS regarding Subject Distinguished Name.
- Let's Encrypt revokes 133,613 affected certificates.
- Let's Encrypt publishes updated CP/CPS.
- Internet Security Research Group — Let's Encrypt discovered a conflict in our CP/CPS regarding the Subject field.
- Internet Security Research Group — We identified 133,613 unexpired affected certificates and revoked them.
- Internet Security Research Group — Incident report detailing the conflict and actions taken was provided.
- Internet Security Research Group — We published v5.5 of our CP/CPS, completing our remediation.
- Mozilla representative — Indicated intent to close the bug unless further issues arise.