← Internet Security Research Group cases
Bugzilla #2038351 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Revocation Issue

Let's Encrypt Gen Y cross-certified subordinate CA certificates were revoked and replaced after missing EKU and CP/CPS profile requirements

ASSIGNED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Let's Encrypt's Gen Y cross-certified subordinate CA certificates and their compliance with CCADB Policy and the Let's Encrypt CP/CPS. The issue was first raised in a third-party report after the affected cross-signed certificates were found to be missing the required serverAuth EKU, and later discussion identified additional CP/CPS profile mismatches in the Subject Organization field and pathLenConstraint. Let's Encrypt said it temporarily disabled issuance, then deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy before re-enabling issuance. On 2026-05-13, the affected Cross-Certified Subordinate CA Certificates were revoked and replaced with certificates that comply with CCADB Policy v2.1 Section 6.3 and the updated CP/CPS profile. Let's Encrypt also stated that the subscriber certificates beneath these hierarchies were not mis-issued and would not be revoked as part of this incident response. The thread later focused on whether the subscriber certificates were issued in accordance with the CP/CPS; Let's Encrypt answered that they were. The case remains ASSIGNED, and the final updates indicate that the planned action items were completed and the CP/CPS and tooling were updated further in August 2026.

Model: gpt-5.4-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-08-30 06:00 UTC Confidence: 0.98 25 comments
Chronology
  1. Let's Encrypt issued three cross-certified subordinate CA certificates for the Gen Y hierarchy.
  2. The non-compliance in the Gen Y cross-certified subordinate CA certificates was identified.
  3. The affected cross-certified subordinate CA certificates were revoked and replaced.
Thread Activity
  1. Internet Security Research Group — Opened a preliminary incident report saying the Gen Y cross-certified subordinate CA certificates violated CCADB policy because the required serverAuth EKU was missing and issuance was temporarily disabled.
  2. Internet Security Research Group — Confirmed that the additional cross-signed certificate was also affected and noted a CP/CPS mismatch in the Subject Organization field.
  3. Internet Security Research Group — Stated that the subscriber certificates were not mis-issued and would not be revoked as part of this incident response.
  4. Internet Security Research Group — Reported that the affected cross-certified subordinate CA certificates had been revoked and replaced, and said a full incident report would follow.
  5. Internet Security Research Group — Posted the full incident report describing the three affected certificates, the revocation/replacement timeline, and the ARI responses for potentially affected subscriber certificates.
  6. Internet Security Research Group — Said the CCADB Policy review had been completed during the primary incident response and provided ARI query statistics.
  7. Internet Security Research Group — Requested the next update date be set to 2026-08-21 after completing the two action items due on 2026-06-26.
  8. Internet Security Research Group — Reported that the remaining action items were complete and described CP/CPS v6.2, new profile lints, and a CCADB policy lint.
  9. Internet Security Research Group — Explained that the certificates were revoked under BR 4.9.1.2 paragraph 5 and that 'superseded' was the appropriate revocation reason code.
Participants
Internet Security Research Group Szafka representative Community commenter Sap representative Jesperkristensen representative
Similar Local Cases
#2044788 ASSIGNED Self Reported Incident Revocation Issue Delayed Revocation Audit Finding Opened 2026-06-03 Still Open · 90% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 90% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 88% similar
Let's Encrypt: Early CRL Removal Incident
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 87% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 86% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 86% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#2054448 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Delayed Revocation Opened 2026-07-13 Still Open · 80% similar
Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Improper encoding of wildcard certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action