Let’s Encrypt self-reported preliminary incident report on keyCompromise revocation reason code; Mozilla agreed to close INVALID
Let’s Encrypt opened this bug as a self-reported preliminary incident report about a certificate revoked with the CRL reasonCode "keyCompromise." The CA said it used that reason code because it suspected a key compromise at the time of revocation, but later determined that the certificate’s key was not actually compromised. Let’s Encrypt asked Mozilla to close the issue as INVALID if Mozilla agreed that the situation was not a compliance incident. Mozilla reviewed the explanation and said the use of keyCompromise was reasonable under the circumstances because the revocation was based on a suspected compromise. Mozilla stated it was in favor of closing the issue as INVALID and proposed closing it on or about 2026-08-12. Let’s Encrypt later followed up to request closure as INVALID because the proposed close date had passed and the bug remained open. The bug is now resolved INVALID.
- Let’s Encrypt revoked a certificate using reasonCode keyCompromise under suspicion of key compromise.
- Let’s Encrypt later determined the certificate’s key was not compromised, while other keys for the same domain name were.
- Internet Security Research Group — Opened a self-reported preliminary incident report and asked Mozilla to close the bug as INVALID if it agreed.
- Mozilla representative — Mozilla agreed with Let’s Encrypt’s analysis, said the circumstances did not constitute a compliance incident, and proposed closing the issue as INVALID on or about 2026-08-12.
- Internet Security Research Group — Let’s Encrypt requested closure as INVALID because the proposed close date had passed and the bug remained open.