Let’s Encrypt preliminary incident report on use of keyCompromise reasonCode
Let’s Encrypt opened this bug as a preliminary incident report about a certificate that was revoked with the CRL reasonCode "keyCompromise." The report says the reason code was used because Let’s Encrypt suspected a key compromise at the time of revocation, but later determined that the certificate’s key was not actually compromised. The commenter states that other keys for the same domain name were compromised instead. The report cites Mozilla’s CA/Revocation Reasons guidance and says the team believes the case is not a compliance incident. Let’s Encrypt asked Mozilla to close the issue as INVALID if Mozilla agrees, and said it would file a full incident report by 2026-08-14 if not.
- Let’s Encrypt revoked a certificate using reasonCode keyCompromise under suspicion of key compromise.
- Let’s Encrypt later determined the certificate’s key was not compromised, while other keys for the same domain name were.
- Internet Security Research Group — Opened a self-reported preliminary incident report describing the revocation reasonCode issue and asked Mozilla to close the bug as INVALID if it agrees.