Let's Encrypt: Early CRL Removal Incident
Let’s Encrypt reported a self-discovered incident where two revoked DV certificates were removed from CRLs before the certificates had expired. The incident violated RFC 5280 Section 3.3, which states that a CRL entry must not be removed until it appears on a regularly scheduled CRL issued beyond the revoked certificate’s validity period. Let’s Encrypt said the issue was detected via internal email alerts from its crl-monitor on 2025-03-18, and it developed, tested, and deployed a fix that restored the missing CRL entries. The CA also reported that it corrected the CRL partitioning logic, improved unit and integration tests to cover CRL entry removal edge cases, and reconfigured crl-monitor alerting to use its normal alerting mechanisms. In the report closure, Let’s Encrypt stated that all disclosed action items were completed and requested closure. Mozilla indicated it would close the bug on or about the following Thursday or Friday unless there were issues to discuss.
- Let’s Encrypt’s CRL monitoring detected that revoked certificate entries were removed from CRL partitions before the certificates expired.
- Let’s Encrypt deployed a fix that restored the missing CRL entries to the affected CRL partitions.
- Let’s Encrypt reported completion of remaining action items including new integration tests and updated CRL monitoring alerting.
- Internet Security Research Group — Submitted a preliminary incident report describing two revoked certificates removed from CRLs early, citing RFC 5280 Section 3.3 and stating a fix was developed, tested, and deployed with entries restored.
- Internet Security Research Group — Posted a full incident report with timeline, impact (2 revoked certificates; 0 remaining valid), and remediation details including the fix and monitoring/test improvements.
- Google representative — Provided feedback praising the report and noted an expectation for the CCADB unique ID format, linking to CCADB incident reporting guidelines.
- Internet Security Research Group — Corrected the CA Owner CCADB unique ID to A000320 and stated the incident response template was updated to pre-populate it.
- Internet Security Research Group — Reported that outstanding action items were completed, including new integration tests for CRL behavior around expiration and reconfigured crl-monitor alerting.
- Mozilla representative — Indicated the bug would be closed on or about Thursday or Friday later that week unless issues or questions remained.