← Internet Security Research Group cases
Bugzilla #2044788 Ca Certificate Compliance Self Reported Incident Incident Revocation Issue Audit Finding

Let's Encrypt: CRLs Temporarily Missing Revoked Serials

ASSIGNED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-reported incident by Let’s Encrypt about CRL publication. Let’s Encrypt said monitoring detected that a database replication issue, triggered during a period of network instability, caused recently added revocation entries to be temporarily omitted from some published CRLs before the affected certificates expired. The full report states that subsequent CRL updates correctly contained the affected entries, that no invalid certificates were produced, and that issuance was not stopped. Let’s Encrypt reported the incident window as 2026-06-03 06:30 UTC to 2026-06-03 11:28 UTC and said 2791 revoked certificates were affected across 6295 incorrect removal events, with zero certificates remaining valid. Later comments added that remediation items were still ongoing, that a follow-up audit of Boulder database interactions found several read operations where replication lag could create compliance concerns, and that Let’s Encrypt planned further technical work to reduce that risk. The thread also notes that the bad-key-revoker reads only from the primary database and that Let’s Encrypt does not serve any other forms of revocation information.

Model: gpt-5.4-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-07-26 06:01 UTC Confidence: 0.93 7 comments
Chronology
  1. Let’s Encrypt reports a database replication issue that temporarily omitted recently added revocation entries from some published CRLs.
  2. Let’s Encrypt posts a full incident report with impact counts, timeline, and confirmation that no invalid certificates were produced.
  3. Let’s Encrypt requests that the CRL Next Update field be set to 2026-07-17 while remediation items remain ongoing.
  4. Let’s Encrypt reports completion of an audit of Boulder database interactions and requests a later Next-Update date.
Thread Activity
  1. Internet Security Research Group — Posted a preliminary incident report saying crl-monitor detected CRLs temporarily missing recently added revoked serial entries due to a database replication issue.
  2. Internet Security Research Group — Posted the full incident report with the timeline, impact counts, and statement that revocations were not delayed and no invalid certificates were produced.
  3. Internet Security Research Group — Requested that the Next Update field be set to 2026-07-17 because remediation items were still ongoing.
  4. Internet Security Research Group — Reported completion of an audit of database interactions in Boulder release tag v0.20260713.0 and requested setting Next-Update to 2026-09-30.
  5. Community commenter — Asked questions about replication-lag detection, mitigation timing, deferred safeguards, the follow-up audit, and whether fixes would be shared upstream.
  6. Internet Security Research Group — Answered that stalled replication is already detected, explained the mitigation delay, described the audit findings, and said the bad-key-revoker reads only from the primary database.
Participants
Internet Security Research Group Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 89% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 87% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 79% similar
Let's Encrypt: Improper encoding of wildcard certificates
#1486650 RESOLVED Self Reported Incident Revocation Issue Opened 2018-08-27 · Closed 2023-02-22 · 79% similar
Let's Encrypt: OCSP "unauthorized" responses
#1684112 RESOLVED Ca Certificate Compliance Opened 2020-12-23 · Closed 2023-02-22 · 79% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 79% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 79% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 78% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action