← Internet Security Research Group cases
Bugzilla #2044788 Self Reported Incident Revocation Issue Delayed Revocation Audit Finding Remediation Tracking

Let's Encrypt self-reported CRL early-removal incident with follow-up replication-lag audit

ASSIGNED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt self-reported an incident in which monitoring detected that some published CRLs temporarily omitted recently added revocation entries before the affected certificates expired. The thread says the cause was a database replication issue triggered during network instability, and that subsequent CRL updates correctly contained the affected entries. Let’s Encrypt stated that no invalid certificates were produced, issuance was not stopped, and all previously revoked certificates remained revoked. Later comments added that Let’s Encrypt completed an audit of Boulder database interactions and identified several read operations where high replication lag could create compliance concerns. The follow-up discussion also clarified that the bad-key-revoker reads blocked keys and issued certificates from the primary database only, and that Let’s Encrypt does not serve any other forms of revocation information. The bug remains ASSIGNED, with Let’s Encrypt asking for the CRL Next-Update field to be extended while remediation work continues.

Model: gpt-5.4-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-09-06 06:00 UTC Confidence: 0.95 8 comments
Chronology
  1. Let’s Encrypt reports that a database replication issue caused recently added revocation entries to be temporarily omitted from some CRLs.
  2. Let’s Encrypt posts a full incident report with impact counts, timeline, and confirmation that no invalid certificates were produced.
  3. Let’s Encrypt reports completion of an audit of Boulder database interactions and requests a later Next-Update date.
  4. Let’s Encrypt answers follow-up questions about replication lag, mitigation timing, and which Boulder operations read from replicas.
Thread Activity
  1. Internet Security Research Group — Posted a preliminary incident report saying crl-monitor detected CRLs temporarily missing recently added revoked serial entries due to a database replication issue.
  2. Internet Security Research Group — Posted the full incident report with the timeline, impact counts, and statement that revocations were not delayed and no invalid certificates were produced.
  3. Internet Security Research Group — Requested that the Next Update field be set to 2026-07-17 because remediation items were still ongoing.
  4. Internet Security Research Group — Reported completion of an audit of database interactions in Boulder release tag v0.20260713.0 and requested setting Next-Update to 2026-09-30.
  5. Community commenter — Asked questions about replication-lag detection, mitigation timing, deferred safeguards, the follow-up audit, and whether fixes would be shared upstream.
  6. Internet Security Research Group — Answered that stalled replication is already detected, explained the mitigation delay, described the audit findings, and said the bad-key-revoker reads only from the primary database.
Participants
Internet Security Research Group Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 90% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#2062418 ASSIGNED Self Reported Incident Policy Document Issue Cp Cps Document Remediation Tracking Opened 2026-08-10 Still Open · 81% similar
Let's Encrypt: CPS missing root program attestation
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 80% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#2060359 RESOLVED Self Reported Incident Closure Request Opened By Ca Single Ca Owner Opened 2026-08-03 · Closed 2026-08-13 · 79% similar
Let’s Encrypt: Use of keyCompromise reasonCode for certificate revoked under suspicion of key compromise
#1486650 RESOLVED Self Reported Incident Revocation Issue Opened 2018-08-27 · Closed 2023-02-22 · 79% similar
Let's Encrypt: OCSP "unauthorized" responses
#2057448 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-24 Still Open · 78% similar
SwissSign: Invalid Entry in State field
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 78% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 78% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action