← Internet Security Research Group cases
Bugzilla #2038351 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Policy Document Issue

Let's Encrypt Gen Y cross-certified subordinate CA certificates missing serverAuth EKU and other CP/CPS/CCADB profile requirements

ASSIGNED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is about Let's Encrypt’s Gen Y cross-certified subordinate CA certificates and their compliance with CCADB Policy and the Let’s Encrypt CP/CPS. The issue was first disclosed by Let's Encrypt as a preliminary incident report after it found that three cross-certified subordinate CA certificates issued on 2025-09-03 were missing the required serverAuth EKU and did not match the expected Subject Organization and pathLenConstraint profile. Let's Encrypt said it temporarily disabled issuance, then deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy before re-enabling issuance. In the full incident report, the company stated that the affected cross-certified subordinate CA certificates were revoked on 2026-05-13 23:14 UTC and replaced with certificates that comply with CCADB Policy v2.1 Section 6.3 and an updated CP/CPS v6.1 profile. The report also says issuance was stopped while scope and impact were confirmed, and that ARI "renew now" responses were served for 688,413 unexpired Subscriber Certificates whose paths might have been affected by the revocations. The thread later focused on whether any subscriber certificates needed revocation; Let's Encrypt stated that the subscriber certificates were not mis-issued and would not be revoked as part of this incident response. The current thread status remains ASSIGNED, with follow-up action items completed and a next update requested for 2026-08-21.

Model: gpt-5.4-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-06-19 19:39 UTC Confidence: 0.96 18 comments
Chronology
  1. Let's Encrypt issued three cross-certified subordinate CA certificates for the Gen Y hierarchy.
  2. Let's Encrypt identified the non-compliance in the Gen Y cross-certified subordinate CA certificates.
  3. The affected cross-certified subordinate CA certificates were revoked and replaced.
Thread Activity
  1. Internet Security Research Group — Opened a preliminary incident report saying the Gen Y cross-certified subordinate CA certificates violated CCADB policy because the required serverAuth EKU was missing and issuance was temporarily disabled.
  2. Internet Security Research Group — Confirmed that the additional cross-signed certificate was also affected and noted a CP/CPS mismatch in the Subject Organization field.
  3. Internet Security Research Group — Stated that the subscriber certificates were not mis-issued and would not be revoked as part of this incident response.
  4. Internet Security Research Group — Reported that the affected cross-certified subordinate CA certificates had been revoked and replaced, and said a full incident report would follow.
  5. Internet Security Research Group — Posted the full incident report describing the three affected certificates, the revocation/replacement timeline, and the ARI responses for potentially affected subscriber certificates.
  6. Internet Security Research Group — Said the CCADB Policy review had been completed during the primary incident response and provided ARI query statistics.
  7. Internet Security Research Group — Requested the next update date be set to 2026-08-21 after completing the two action items due on 2026-06-26.
Participants
Internet Security Research Group Szafka representative Community commenter Sap representative Jesperkristensen representative
Similar Local Cases
#2044788 ASSIGNED Ca Certificate Compliance Self Reported Incident Incident Revocation Issue Opened 2026-06-03 Still Open · 89% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 89% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 89% similar
Let's Encrypt: Early CRL Removal Incident
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 88% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 87% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 86% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 86% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Improper encoding of wildcard certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action