← Internet Security Research Group cases
Bugzilla #1954861 Self Reported Incident Certificate Misissuance

Let's Encrypt: Early CRL Removal Incident

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt reported a self-discovered incident where two revoked DV certificates were removed from CRLs before the certificates had expired. The incident violated RFC 5280 Section 3.3, which states that a CRL entry must not be removed until it appears on a regularly scheduled CRL issued beyond the revoked certificate’s validity period. Let’s Encrypt said the issue was detected via internal email alerts from its crl-monitor on 2025-03-18, and it developed, tested, and deployed a fix that restored the missing CRL entries. The CA also reported that it corrected the CRL partitioning logic, improved unit and integration tests to cover CRL entry removal edge cases, and reconfigured crl-monitor alerting to use its normal alerting mechanisms. In the report closure, Let’s Encrypt stated that all disclosed action items were completed and requested closure. Mozilla indicated it would close the bug on or about the following Thursday or Friday unless there were issues to discuss.

Model: gpt-5.4-nano Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 10 comments
Chronology
  1. Let’s Encrypt’s CRL monitoring detected that revoked certificate entries were removed from CRL partitions before the certificates expired.
  2. Let’s Encrypt deployed a fix that restored the missing CRL entries to the affected CRL partitions.
  3. Let’s Encrypt reported completion of remaining action items including new integration tests and updated CRL monitoring alerting.
Thread Activity
  1. Internet Security Research Group — Submitted a preliminary incident report describing two revoked certificates removed from CRLs early, citing RFC 5280 Section 3.3 and stating a fix was developed, tested, and deployed with entries restored.
  2. Internet Security Research Group — Posted a full incident report with timeline, impact (2 revoked certificates; 0 remaining valid), and remediation details including the fix and monitoring/test improvements.
  3. Google representative — Provided feedback praising the report and noted an expectation for the CCADB unique ID format, linking to CCADB incident reporting guidelines.
  4. Internet Security Research Group — Corrected the CA Owner CCADB unique ID to A000320 and stated the incident response template was updated to pre-populate it.
  5. Internet Security Research Group — Reported that outstanding action items were completed, including new integration tests for CRL behavior around expiration and reconfigured crl-monitor alerting.
  6. Mozilla representative — Indicated the bug would be closed on or about Thursday or Friday later that week unless issues or questions remained.
Participants
Internet Security Research Group Google representative Mozilla representative
Similar Local Cases
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 100% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 97% similar
Let's Encrypt: CAA Rechecking bug
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 97% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 97% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 95% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 94% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 92% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 89% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action