← Internet Security Research Group cases
Bugzilla #2062418 Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Cp Cps Document

Let's Encrypt self-reported CP/CPS compliance gap for missing root program and CCADB attestation

ASSIGNED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-reported compliance incident from Internet Security Research Group / Let's Encrypt. The issue was that the ISRG CP/CPS did not explicitly state adherence to the Chrome Root Program Policy and the CCADB Policy by the required effective date. Let’s Encrypt said it had tracked the requirement in its public CP/CPS repository, but failed to make the necessary updates in time. The full incident report states the non-compliance period ran from 2026-06-15 to 2026-08-13 and that zero certificates were affected. Let’s Encrypt published ISRG CP/CPS v6.2 on 2026-08-13 with the required attestation language added. As of the latest thread activity, the remediation items are still in progress, one follow-up item has been completed, and Let’s Encrypt requested the next update date of 2026-11-20.

Model: gpt-5.4-mini Generated: 2026-08-16 08:20 UTC Revised: 2026-09-13 08:01 UTC Confidence: 0.99 11 comments
Chronology
  1. Chrome Root Program Policy v1.8 requirement for explicit CP/CPS adherence statements became effective.
  2. Let's Encrypt disclosed that its CP/CPS lacked the required root program and CCADB adherence statements.
  3. Let's Encrypt published ISRG CP/CPS v6.2 with the required attestation language added.
  4. Let's Encrypt published a full incident report.
  5. Let's Encrypt said review steps for CCADB and root program policies had been added to the PMA quarterly meeting template and requested a next update date of 2026-11-20.
Thread Activity
  1. Internet Security Research Group — Opened a preliminary incident report and said the CP/CPS lacked explicit adherence statements required by Chrome Root Program Policy v1.8 and the CCADB Policy.
  2. Internet Security Research Group — Stated the disclosure was self-reported and said a full incident report would follow by 2026-08-24.
  3. Internet Security Research Group — Said ISRG CP/CPS v6.2 had been published with an edit to Section 1.1 that brought the document into compliance with Section 1.1.3 of the Chrome Root Program Policy.
  4. Internet Security Research Group — Posted the full incident report, including the non-compliance dates, zero affected certificates, and confirmation that the issue was a strict policy compliance violation.
  5. Internet Security Research Group — Reported that remediation items remain in progress and listed action items with one complete and others ongoing.
  6. Internet Security Research Group — Said review steps for CCADB and root program policies had been added to the PMA quarterly meeting template and requested a next update of 2026-11-20.
  7. Internet Security Research Group — Said there were no significant updates and that all three remediation items due 2026-11-20 were still in progress.
Participants
Internet Security Research Group Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 89% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 87% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 87% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 86% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#2044788 ASSIGNED Ca Certificate Compliance Self Reported Incident Delayed Revocation Audit Finding Opened 2026-06-03 Still Open · 80% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#2060359 RESOLVED Self Reported Incident Closure Request Opened By Ca Single Ca Owner Opened 2026-08-03 · Closed 2026-08-13 · 78% similar
Let’s Encrypt: Use of keyCompromise reasonCode for certificate revoked under suspicion of key compromise
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 78% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 78% similar
Let's Encrypt: Improper encoding of wildcard certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action