← Internet Security Research Group cases
Bugzilla #2060359 Self Reported Incident Closure Request Opened By Ca Single Ca Owner

Let’s Encrypt self-reported preliminary incident report on keyCompromise revocation reason code; Mozilla agreed to close INVALID

RESOLVED INVALID Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let’s Encrypt opened this bug as a self-reported preliminary incident report about a certificate revoked with the CRL reasonCode "keyCompromise." The CA said it used that reason code because it suspected a key compromise at the time of revocation, but later determined that the certificate’s key was not actually compromised. Let’s Encrypt asked Mozilla to close the issue as INVALID if Mozilla agreed that the situation was not a compliance incident. Mozilla reviewed the explanation and said the use of keyCompromise was reasonable under the circumstances because the revocation was based on a suspected compromise. Mozilla stated it was in favor of closing the issue as INVALID and proposed closing it on or about 2026-08-12. Let’s Encrypt later followed up to request closure as INVALID because the proposed close date had passed and the bug remained open. The bug is now resolved INVALID.

Model: gpt-5.4-mini Generated: 2026-08-04 07:22 UTC Revised: 2026-08-16 08:00 UTC Confidence: 0.98 3 comments
Chronology
  1. Let’s Encrypt revoked a certificate using reasonCode keyCompromise under suspicion of key compromise.
  2. Let’s Encrypt later determined the certificate’s key was not compromised, while other keys for the same domain name were.
Thread Activity
  1. Internet Security Research Group — Opened a self-reported preliminary incident report and asked Mozilla to close the bug as INVALID if it agreed.
  2. Mozilla representative — Mozilla agreed with Let’s Encrypt’s analysis, said the circumstances did not constitute a compliance incident, and proposed closing the issue as INVALID on or about 2026-08-12.
  3. Internet Security Research Group — Let’s Encrypt requested closure as INVALID because the proposed close date had passed and the bug remained open.
Participants
Internet Security Research Group Mozilla representative
Similar Local Cases
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 84% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#2044788 ASSIGNED Self Reported Incident Revocation Issue Incident Remediation Tracking Opened 2026-06-03 Still Open · 79% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 79% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 79% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#2062418 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-08-10 Still Open · 78% similar
Let's Encrypt: CPS missing root program attestation
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 78% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 78% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 78% similar
Let's Encrypt: Early CRL Removal Incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action