← Internet Security Research Group cases
Bugzilla #2060359 Self Reported Incident Revocation Issue Closure Request

Let’s Encrypt preliminary incident report on use of keyCompromise reasonCode

UNCONFIRMED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt opened this bug as a preliminary incident report about a certificate that was revoked with the CRL reasonCode "keyCompromise." The report says the reason code was used because Let’s Encrypt suspected a key compromise at the time of revocation, but later determined that the certificate’s key was not actually compromised. The commenter states that other keys for the same domain name were compromised instead. The report cites Mozilla’s CA/Revocation Reasons guidance and says the team believes the case is not a compliance incident. Let’s Encrypt asked Mozilla to close the issue as INVALID if Mozilla agrees, and said it would file a full incident report by 2026-08-14 if not.

Model: gpt-5.4-mini Generated: 2026-08-04 07:22 UTC Confidence: 0.97 1 comment
Chronology
  1. Let’s Encrypt revoked a certificate using reasonCode keyCompromise under suspicion of key compromise.
  2. Let’s Encrypt later determined the certificate’s key was not compromised, while other keys for the same domain name were.
Thread Activity
  1. Internet Security Research Group — Opened a self-reported preliminary incident report describing the revocation reasonCode issue and asked Mozilla to close the bug as INVALID if it agrees.
Participants
Internet Security Research Group
Similar Local Cases
#2044788 ASSIGNED Ca Certificate Compliance Self Reported Incident Incident Revocation Issue Opened 2026-06-03 Still Open · 80% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 79% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 78% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1486650 RESOLVED Self Reported Incident Revocation Issue Opened 2018-08-27 · Closed 2023-02-22 · 77% similar
Let's Encrypt: OCSP "unauthorized" responses
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 77% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 76% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 72% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 71% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action