← Certainly LLC cases
Bugzilla #1954889 Self Reported Incident Revocation Issue

Certainly: Early CRL Entry Removal

RESOLVED INVALID Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certainly reported a potential compliance issue involving CRL generation. The initial incident report stated that on 2025-02-13 Certainly deployed a Boulder version with a logic bug that could remove entries for some revoked certificates from the CRL before the certificates had expired, which would violate Baseline Requirements section 4.10.1 and RFC 5280 section 3.3. Certainly said it became aware of the issue at 16:23 UTC on 2025-03-18 after a member of the Let’s Encrypt team directed it to a Boulder pull request containing the fix, and that a fix was deployed. In the full incident report, Certainly described an impact assessment (including a total of 77,467 certificates and zero “remaining valid” certificates) and stated that issuance was not stopped because the incident did not affect issuance. After further review, Certainly revised its evaluation and concluded it was not actually impacted because its configuration did not enable the feature flags needed to trigger the buggy code path, and it confirmed it had not issued incomplete CRLs. Based on this revised evaluation, Certainly requested the bug be closed as invalid, and the bug status is RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:18 UTC Confidence: 0.86 4 comments
Chronology
  1. Certainly deployed a Boulder release that included a CRL generation logic bug.
  2. Let’s Encrypt notified Certainly about the upstream Boulder fix, prompting Certainly’s investigation.
  3. Certainly deployed the upstream fix to address the CRL generation bug.
  4. A preliminary incident report was published in the bug.
  5. Certainly revised its evaluation after further review and requested closure as invalid.
Thread Activity
  1. Fastly representative — Wayne Thayer posted a preliminary incident report describing the suspected CRL entry removal issue and stated a fix had been deployed with a full report to follow.
  2. Fastly representative — David Jeffery posted the full incident report with a detailed timeline, impact assessment, and root cause analysis, and noted they would continue monitoring.
  3. Fastly representative — David Jeffery revised the incident evaluation, stated Certainly was not actually impacted due to configuration/feature flags, confirmed CRLs were complete, and requested the bug be closed as invalid.
Participants
Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1900129 RESOLVED Revocation Issue Opened 2024-05-31 · Closed 2024-06-28 · 95% similar
Certainly: Serving invalid or incomplete CRLs
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 79% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method
#1752452 RESOLVED Self Reported Incident Opened 2022-01-28 · Closed 2023-02-22 · 79% similar
Certainly: TLS Using ALPN TLS Version and OID
#1968836 RESOLVED Incident Self Reported Incident Opened 2025-05-28 · Closed 2025-08-26 · 79% similar
Certainly: Sample Websites Unavailable
#2052399 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-07-03 Still Open · 78% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2052085 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Audit Finding Opened 2026-07-02 Still Open · 78% similar
Certainly: Missing audit log entries for certificates issued during capacity testing
#1526099 RESOLVED Self Reported Incident Revocation Issue Audit Finding Opened 2019-02-07 · Closed 2023-02-22 · 78% similar
IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 78% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action