← Internet Security Research Group cases
Bugzilla #1972745
Certificate Problem Report
Let's Encrypt: Deployed Unreviewed Boulder Code
RESOLVED
FIXED
Internet Security Research Group
AI Summary
An incident occurred when a core developer of Let's Encrypt accidentally tagged a release of their CA software, Boulder, based on an unreviewed commit. This release was deployed before the issue was detected. Upon review, it was confirmed that the unreviewed code did not affect the CA's operation. The incident was reported by a third party, and while no certificates were impacted, the event highlighted gaps in the review process for release tags. Let's Encrypt has since implemented improvements to their automation and review processes to prevent similar occurrences in the future.
Chronology
- Release tagged with unreviewed commit
- Incident detected and reviewed
- Report closure summary provided
Participants
Jacob Hoffman-Andrews
Mike Shaver
Aaron
External References
Similar Local Cases
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
Let's Encrypt: CAA Rechecking bug
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Incomplete revocation for CAA rechecking bug
Let's Encrypt: OCSP responses with no revocationReason
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours