← Internet Security Research Group cases
Bugzilla #1921573 Self Reported Incident Policy Document Issue

Let's Encrypt: No Meaningful Subject Distinguished Name

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On September 27, 2024, Let's Encrypt discovered a conflict in their Certificate Policy/Certificate Practice Statement (CP/CPS) regarding the Subject Distinguished Name in their certificates. This conflict arose from changes allowing certificates to be issued without a Common Name, which contradicted existing policy. Following the discovery, issuance was halted, and an updated CP/CPS was published. Let's Encrypt identified 133,613 unexpired certificates affected by this issue and revoked them on October 1, 2024. A full incident report was provided, detailing the timeline and actions taken to resolve the issue, including a review and update of their CP/CPS.

Model: gpt-4o-mini Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 12 comments
Chronology
  1. Let's Encrypt discovers a conflict in their CP/CPS regarding Subject Distinguished Name.
  2. Let's Encrypt revokes 133,613 affected certificates.
  3. Let's Encrypt publishes updated CP/CPS.
Thread Activity
  1. Internet Security Research Group — Let's Encrypt discovered a conflict in our CP/CPS regarding the Subject field.
  2. Internet Security Research Group — We identified 133,613 unexpired affected certificates and revoked them.
  3. Internet Security Research Group — Incident report detailing the conflict and actions taken was provided.
  4. Internet Security Research Group — We published v5.5 of our CP/CPS, completing our remediation.
  5. Mozilla representative — Indicated intent to close the bug unless further issues arise.
Participants
Internet Security Research Group Google representative Mozilla representative
Similar Local Cases
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 100% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 92% similar
Let's Encrypt: CAA Rechecking bug
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 92% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 88% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 87% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 87% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 87% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 87% similar
Let's Encrypt: Early CRL Removal Incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action