← Internet Security Research Group cases
Bugzilla #2044788
Certificate Problem Report
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
ASSIGNED
Internet Security Research Group
AI Summary
Let's Encrypt reported an incident where several Certificate Revocation Lists (CRLs) temporarily omitted recently-added revoked entries due to a database replication issue. This problem was detected through their monitoring system. Subsequent updates to the CRLs correctly included the affected entries. The incident raised concerns regarding compliance with relevant policies that mandate revocation entries must not be removed until after the expiration date of the revoked certificates.
Chronology
- Incident detected and reported
- Status updated
Participants
Phil Porada
External References
Similar Local Cases
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Early CRL Removal Incident
Let's Encrypt: Non-BR-Compliant Certificate Issuance
Let's Encrypt: Case-sensitive CAA tag processing
Let's Encrypt: OCSP responses with no revocationReason
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate