← Internet Security Research Group cases
Bugzilla #1391867 · Certificate Problem Report

Let's Encrypt: Non-BR-Compliant Certificate Issuance

Internet Security Research Group · RESOLVED
AI Summary

This case addresses a compliance issue with Let's Encrypt regarding the issuance of non-Baseline Requirements (BR) compliant certificates. The CA was notified of the problem on August 10, 2017, and promptly applied a fix to their infrastructure. They confirmed that they ceased issuing the problematic certificates and provided a list of affected certificates. The issue stemmed from a mistake in their software code that was not caught during review, but was resolved on the same day it was reported.

Model: gpt-4o-mini Generated: 2026-06-13 11:59 UTC Confidence: 0.95
Chronology
  1. Let's Encrypt notified of compliance issue
  2. Fix applied to production infrastructure
Participants
Kathleen Wilson Josh Aas
External References
Similar Local Cases
#1266942 RESOLVED Certificate Problem Report Opened 2016-04-23 · Closed 2022-11-14 · 51% similar
StartCom: IV without localityName or stateOrProvinceName
#1339339 RESOLVED Certificate Problem Report Opened 2017-02-14 · Closed 2023-02-22 · 50% similar
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
#1353833 RESOLVED Certificate Problem Report Opened 2017-04-05 · Closed 2023-02-22 · 49% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
#1267332 RESOLVED Certificate Problem Report Opened 2016-04-25 · Closed 2022-11-14 · 49% similar
Hongkong Post e-Cert CA 1 - 10 issuing certificates without subject alternative name extension
#1262610 RESOLVED Certificate Problem Report Opened 2016-04-06 · Closed 2023-02-22 · 49% similar
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
#1350615 RESOLVED Certificate Problem Report Opened 2017-03-25 · Closed 2022-11-14 · 48% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1075952 RESOLVED Certificate Problem Report Opened 2014-10-01 · Closed 2022-11-14 · 48% similar
D-Trust: issuing 1024 bit certificates
#1548719 RESOLVED Certificate Problem Report Opened 2019-05-03 · Closed 2023-02-22 · 48% similar
DigiCert: Revoked intermediate certificates not in CRL

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action