Let's Encrypt Gen Y cross-certified subordinate CA certificates were revoked and replaced after missing EKU and CP/CPS profile requirements
This case concerns Let's Encrypt's Gen Y cross-certified subordinate CA certificates and their compliance with CCADB Policy and the Let's Encrypt CP/CPS. The issue was first raised in a third-party report after the affected cross-signed certificates were found to be missing the required serverAuth EKU, and later discussion identified additional CP/CPS profile mismatches in the Subject Organization field and pathLenConstraint. Let's Encrypt said it temporarily disabled issuance, then deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy before re-enabling issuance. On 2026-05-13, the affected Cross-Certified Subordinate CA Certificates were revoked and replaced with certificates that comply with CCADB Policy v2.1 Section 6.3 and the updated CP/CPS profile. Let's Encrypt also stated that the subscriber certificates beneath these hierarchies were not mis-issued and would not be revoked as part of this incident response. The thread later focused on whether the subscriber certificates were issued in accordance with the CP/CPS; Let's Encrypt answered that they were. The case remains ASSIGNED, and the final updates indicate that the planned action items were completed and the CP/CPS and tooling were updated further in August 2026.
- Let's Encrypt issued three cross-certified subordinate CA certificates for the Gen Y hierarchy.
- The non-compliance in the Gen Y cross-certified subordinate CA certificates was identified.
- The affected cross-certified subordinate CA certificates were revoked and replaced.
- Internet Security Research Group — Opened a preliminary incident report saying the Gen Y cross-certified subordinate CA certificates violated CCADB policy because the required serverAuth EKU was missing and issuance was temporarily disabled.
- Internet Security Research Group — Confirmed that the additional cross-signed certificate was also affected and noted a CP/CPS mismatch in the Subject Organization field.
- Internet Security Research Group — Stated that the subscriber certificates were not mis-issued and would not be revoked as part of this incident response.
- Internet Security Research Group — Reported that the affected cross-certified subordinate CA certificates had been revoked and replaced, and said a full incident report would follow.
- Internet Security Research Group — Posted the full incident report describing the three affected certificates, the revocation/replacement timeline, and the ARI responses for potentially affected subscriber certificates.
- Internet Security Research Group — Said the CCADB Policy review had been completed during the primary incident response and provided ARI query statistics.
- Internet Security Research Group — Requested the next update date be set to 2026-08-21 after completing the two action items due on 2026-06-26.
- Internet Security Research Group — Reported that the remaining action items were complete and described CP/CPS v6.2, new profile lints, and a CCADB policy lint.
- Internet Security Research Group — Explained that the certificates were revoked under BR 4.9.1.2 paragraph 5 and that 'superseded' was the appropriate revocation reason code.