← Internet Security Research Group cases
Bugzilla #1319609 · Certificate Misissuance
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
Internet Security Research Group · RESOLVED
AI Summary
This case addresses a misissuance of certificates by Let's Encrypt due to an incomplete blocklist caused by a bug in their issuance script. The issue was identified and resolved, with all affected certificates revoked. The incident highlighted the importance of compliance with the Certification Practice Statement (CPS) and the need for improved testing and policy review. Mozilla has determined that no further action is necessary as the CA has taken appropriate steps to rectify the situation.
Chronology
- Problem with issuance blocklist identified and fixed.
- Case resolved with all affected certificates revoked.
Participants
Kathleen Wilson
Gervase Markham
jaas@kflag.net
External References
Similar Local Cases
Let's Encrypt: CAA Misissuances
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
DigiCert / Inteso San Paulo: Double dot characters
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
SHA-1 issuance by Visa root
SHA-1 issuance by DocuSign root
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
SHA-1 issuance by DigiCert roots