Let's Encrypt: CRLs Temporarily Missing Revoked Serials
This case is a self-reported incident by Let’s Encrypt about CRL publication. Let’s Encrypt said monitoring detected that a database replication issue, triggered during a period of network instability, caused recently added revocation entries to be temporarily omitted from some published CRLs before the affected certificates expired. The full report states that subsequent CRL updates correctly contained the affected entries, that no invalid certificates were produced, and that issuance was not stopped. Let’s Encrypt reported the incident window as 2026-06-03 06:30 UTC to 2026-06-03 11:28 UTC and said 2791 revoked certificates were affected across 6295 incorrect removal events, with zero certificates remaining valid. Later comments added that remediation items were still ongoing, that a follow-up audit of Boulder database interactions found several read operations where replication lag could create compliance concerns, and that Let’s Encrypt planned further technical work to reduce that risk. The thread also notes that the bad-key-revoker reads only from the primary database and that Let’s Encrypt does not serve any other forms of revocation information.
- Let’s Encrypt reports a database replication issue that temporarily omitted recently added revocation entries from some published CRLs.
- Let’s Encrypt posts a full incident report with impact counts, timeline, and confirmation that no invalid certificates were produced.
- Let’s Encrypt requests that the CRL Next Update field be set to 2026-07-17 while remediation items remain ongoing.
- Let’s Encrypt reports completion of an audit of Boulder database interactions and requests a later Next-Update date.
- Internet Security Research Group — Posted a preliminary incident report saying crl-monitor detected CRLs temporarily missing recently added revoked serial entries due to a database replication issue.
- Internet Security Research Group — Posted the full incident report with the timeline, impact counts, and statement that revocations were not delayed and no invalid certificates were produced.
- Internet Security Research Group — Requested that the Next Update field be set to 2026-07-17 because remediation items were still ongoing.
- Internet Security Research Group — Reported completion of an audit of database interactions in Boulder release tag v0.20260713.0 and requested setting Next-Update to 2026-09-30.
- Community commenter — Asked questions about replication-lag detection, mitigation timing, deferred safeguards, the follow-up audit, and whether fixes would be shared upstream.
- Internet Security Research Group — Answered that stalled replication is already detected, explained the mitigation delay, described the audit findings, and said the bad-key-revoker reads only from the primary database.