← Internet Security Research Group cases
Bugzilla #1954861
Certificate Problem Report
Let's Encrypt: Early CRL Removal Incident
RESOLVED
FIXED
Internet Security Research Group
AI Summary
The incident involved the early removal of two revoked certificates from Let's Encrypt's Certificate Revocation Lists (CRLs) before their expiration, violating RFC 5280, Section 3.3. This issue was identified through an internal alert and was resolved by restoring the missing entries. The root cause was a bug in the CRL partitioning logic, compounded by insufficient testing and misconfigured alerting. Let's Encrypt has since implemented corrective measures, including improved testing and monitoring protocols.
Chronology
- Incident begins with detection of missing CRL entries.
- Fix developed and deployed.
- All action items completed and incident report closure requested.
Participants
Ameer Ghani
chrome-root-program@google.com
bwilson@mozilla.com
External References
Similar Local Cases
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
Once Revoked Let's Encrypt Certificate Actively Signing Malware
Apple: Public Key Reuse
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829