Let's Encrypt Gen Y cross-certified subordinate CA certificates missing serverAuth EKU and other CP/CPS/CCADB profile requirements
This case is about Let's Encrypt’s Gen Y cross-certified subordinate CA certificates and their compliance with CCADB Policy and the Let’s Encrypt CP/CPS. The issue was first disclosed by Let's Encrypt as a preliminary incident report after it found that three cross-certified subordinate CA certificates issued on 2025-09-03 were missing the required serverAuth EKU and did not match the expected Subject Organization and pathLenConstraint profile. Let's Encrypt said it temporarily disabled issuance, then deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy before re-enabling issuance. In the full incident report, the company stated that the affected cross-certified subordinate CA certificates were revoked on 2026-05-13 23:14 UTC and replaced with certificates that comply with CCADB Policy v2.1 Section 6.3 and an updated CP/CPS v6.1 profile. The report also says issuance was stopped while scope and impact were confirmed, and that ARI "renew now" responses were served for 688,413 unexpired Subscriber Certificates whose paths might have been affected by the revocations. The thread later focused on whether any subscriber certificates needed revocation; Let's Encrypt stated that the subscriber certificates were not mis-issued and would not be revoked as part of this incident response. The current thread status remains ASSIGNED, with follow-up action items completed and a next update requested for 2026-08-21.
- Let's Encrypt issued three cross-certified subordinate CA certificates for the Gen Y hierarchy.
- Let's Encrypt identified the non-compliance in the Gen Y cross-certified subordinate CA certificates.
- The affected cross-certified subordinate CA certificates were revoked and replaced.
- Internet Security Research Group — Opened a preliminary incident report saying the Gen Y cross-certified subordinate CA certificates violated CCADB policy because the required serverAuth EKU was missing and issuance was temporarily disabled.
- Internet Security Research Group — Confirmed that the additional cross-signed certificate was also affected and noted a CP/CPS mismatch in the Subject Organization field.
- Internet Security Research Group — Stated that the subscriber certificates were not mis-issued and would not be revoked as part of this incident response.
- Internet Security Research Group — Reported that the affected cross-certified subordinate CA certificates had been revoked and replaced, and said a full incident report would follow.
- Internet Security Research Group — Posted the full incident report describing the three affected certificates, the revocation/replacement timeline, and the ARI responses for potentially affected subscriber certificates.
- Internet Security Research Group — Said the CCADB Policy review had been completed during the primary incident response and provided ARI query statistics.
- Internet Security Research Group — Requested the next update date be set to 2026-08-21 after completing the two action items due on 2026-06-26.