← Internet Security Research Group cases
Bugzilla #2062418 Ca Certificate Compliance Ca Documents Self Reported Incident Policy Document Issue Cp Cps Document

Let's Encrypt self-reported missing root program attestation in CP/CPS

NEW Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-reported compliance incident from Internet Security Research Group / Let's Encrypt. The issue was that the ISRG CP/CPS did not explicitly state adherence to the latest Chrome Root Program policy and the CCADB Policy by the policy effective date. Aaron Gable said the team knew about the upcoming requirement and had tracked it in the public CP/CPS repository, but did not make the needed update in time. Let's Encrypt later published ISRG CP/CPS v6.2 with an edit to Section 1.1 intended to bring the document into compliance. The thread says a full incident report was planned for 2026-08-24.

Model: gpt-5.4-mini Generated: 2026-08-16 08:20 UTC Confidence: 0.99 5 comments
Chronology
  1. Chrome Root Program Policy v1.8 effective date for explicit CP/CPS adherence statements.
  2. Let's Encrypt disclosed that its CP/CPS lacked the required root program attestation language.
  3. Let's Encrypt published ISRG CP/CPS v6.2 with an edit to Section 1.1 to address the requirement.
  4. Let's Encrypt planned to publish a full incident report.
Thread Activity
  1. Internet Security Research Group — Opened the bug as a preliminary incident report and stated the CP/CPS lacked explicit adherence statements required by Chrome Root Program Policy v1.8 and CCADB Policy.
  2. Internet Security Research Group — Identified the source of incident disclosure as self-reported and said a full incident report would follow by 2026-08-24.
  3. Internet Security Research Group — Said ISRG CP/CPS v6.2 had been published with an edit to Section 1.1 bringing the document into compliance.
Participants
Internet Security Research Group Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 88% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 87% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 85% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#2044788 ASSIGNED Ca Certificate Compliance Self Reported Incident Incident Revocation Issue Opened 2026-06-03 Still Open · 80% similar
Let's Encrypt: CRLs Temporarily Missing Revoked Serials
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 78% similar
Let's Encrypt: Improper encoding of wildcard certificates
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 77% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 77% similar
Microsoft PKI Services: Policy document bug
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 76% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action