← Certainly LLC cases
Bugzilla #1954889 Certificate Problem Report

Certainly: Early CRL Entry Removal

RESOLVED INVALID Certainly LLC
AI Summary

On February 13, 2025, Certainly LLC deployed a version of Boulder that contained a logic bug, leading to the premature removal of some revoked certificates from the Certificate Revocation List (CRL). This incident was identified on March 18, 2025, after a notification from the Let's Encrypt team. Although the bug could have affected a significant number of certificates, further investigation revealed that Certainly's specific configuration prevented any actual compliance issues. The company has since implemented a fix and is enhancing its monitoring systems to prevent similar occurrences in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:29 UTC Confidence: 0.90
Chronology
  1. Upstream commit containing bug in CRL generation code
  2. Deployed Boulder release containing the bug
  3. Received notification from Let's Encrypt
  4. Preliminary incident report published
  5. Revised evaluation of the incident published
Participants
Wayne Thayer djeffery@fastly.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1752452 RESOLVED Certificate Problem Report Opened 2022-01-28 · Closed 2023-02-22 · 60% similar
Certainly: TLS Using ALPN TLS Version and OID
#1771238 RESOLVED Certificate Problem Report Opened 2022-05-25 · Closed 2023-02-22 · 60% similar
Certainly: Serving Expired OCSP Responses
#1900129 RESOLVED Certificate Problem Report Opened 2024-05-31 · Closed 2024-06-28 · 58% similar
Certainly: Serving invalid or incomplete CRLs
#1798053 RESOLVED Certificate Problem Report Opened 2022-10-28 · Closed 2023-02-22 · 57% similar
Certainly: Serving Bad OCSP Responses
#1448986 RESOLVED Certificate Problem Report Opened 2018-03-26 · Closed 2023-02-22 · 52% similar
Entrust: IP Address in dNSName form
#1532399 RESOLVED Certificate Problem Report Opened 2019-03-04 · Closed 2023-02-22 · 51% similar
TrustCor: Insufficient Serial Number Entropy
#1551362 RESOLVED Certificate Problem Report Opened 2019-05-14 · Closed 2023-02-22 · 50% similar
Sectigo: "Some-State" in stateOrProvinceName
#1636544 RESOLVED Certificate Problem Report Opened 2020-05-08 · Closed 2023-02-22 · 50% similar
IdenTrust: OCSP Outage

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action