← Internet Security Research Group cases
Bugzilla #2038351 Certificate Misissuance

Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU

RESOLVED Internet Security Research Group
AI Summary

Let's Encrypt issued three Cross-Certified Subordinate CA Certificates that did not comply with CCADB policy, specifically lacking the required serverAuth EKU extension. This non-compliance was identified on May 8, 2026, leading to a temporary halt in certificate issuance while the issue was assessed. The affected certificates were revoked on May 13, 2026, and replacements were issued that adhered to both CCADB Policy and Let's Encrypt's updated CP/CPS. The incident was reported by a third party and has been addressed with a full incident report to be published by May 22, 2026.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 0.90
Chronology
  1. Three Cross-Certified Subordinate CA Certificates issued
  2. Non-compliance identified
  3. Affected certificates revoked
  4. Full incident report to be published
Participants
Phil Porada Pawel Szafka Aaron Gable Brad Let's Encrypt Petra Barzin
Similar Local Cases
#1752670 RESOLVED Certificate Misissuance Opened 2022-01-29 · Closed 2024-05-09 · 54% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 52% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1735247 RESOLVED Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 52% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1398427 RESOLVED Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 48% similar
Let's Encrypt: CAA Misissuances
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 48% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1887096 RESOLVED Certificate Misissuance Opened 2024-03-22 · Closed 2024-09-06 · 47% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1874196 RESOLVED Certificate Misissuance Opened 2024-01-11 · Closed 2024-03-27 · 47% similar
SwissSign: difference in upper and lower case between CN field and SAN
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 44% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action