← Internet Security Research Group cases
Bugzilla #1955721
Certificate Problem Report
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt identified multiple instances of failing to remediate or document critical vulnerabilities within the required 96-hour timeframe. This issue arose during their weekly vulnerability scans, where they discovered that not all vulnerabilities were addressed as per their policies. The incident was self-reported while preparing for a WebTrust audit. A total of 58 vulnerabilities were noted, but there was no evidence of system compromise. The organization has since updated its vulnerability response procedures and conducted training to prevent future occurrences.
Chronology
- Non-compliance start date
- Non-compliance identified date
- Non-compliance end date
- Training on new procedures completed
- Incident report closure expected
Participants
Phil Porada
Lena
Preston Locke
Zacharias Bjorngren
Chrome Root Program
External References
Similar Local Cases
Let's Encrypt: No Meaningful Subject Distinguished Name
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Deployed Unreviewed Boulder Code
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Delayed revocation for removed gTLD