registry problems - remove in Feb 2018
87cdeef4-a32f-4f89-90b2-d979766f66fd
Revocation Entry
- Status
- enabled
- Serial
04AA1BCE3ACEC5AFFA9024742262A8A9A416- Last Modified
- 2017-11-03 21:33:12 UTC
- Schema
- 1552493010014
Issuer
- DN
- C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X3
- DN SHA-256
b9729f1a1eff55f205ee6147c91c474285224a4b7d68d4a5e6177df3a8d4ea48- Issuer DER
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQDExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMw==
Context
- Bugzilla
- 1414039
- Action
- OneCRL entries were added for revoked end-entity certificates chaining to Let's Encrypt Authority X3. The thread states the primary google.tg certificate was added to OneCRL in Bug 1414089 and was live by 2017-11-02, and the local OneCRL data tied to Bug 1414039 shows 39 additional enabled entries created by j**********c@mozilla.com on 2017-11-03 with the label "registry problems - remove in Feb 2018"; one of those entries was last modified on 2017-11-06.
- Confidence
- Explicit in OneCRL thread · 0.97
CCADB Link
- Issuer CA
- Let's Encrypt Authority X3
- CA Owner
- Internet Security Research Group
AI Summary
Generated 2026-06-30 11:42 UTC · Model: gpt-5.4Bug 1414039 concerns attacker-obtained Let's Encrypt certificates for .tg domains during a compromise of the .tg registry, initially highlighted by a certificate for google.tg that Google reported was being used in the wild. Mozilla participants discussed that Firefox pinning likely already blocked the specific google.tg certificate, but still decided OneCRL entries should be added. The bug thread states that the primary certificate was added to OneCRL in Bug 1414089 and later confirms that additional Let's Encrypt certificates revoked for the same incident were also added. The local OneCRL data for this bug shows 39 enabled entries, all under issuer "Let's Encrypt Authority X3," created by j**********c@mozilla.com on 2017-11-03, with the public label "registry problems - remove in Feb 2018," plus one entry created on 2017-11-02. J.C. Jones stated that these serials were certificates "now revoked by Let's Encrypt for this incident" and that he was producing the OneCRL change. Kathleen Wilson approved the descriptive OneCRL label and later summarized that Mozilla had added OneCRL entries for the subject certificate and other .tg certificates that Let's Encrypt revoked. The thread explicitly ties the revocations to a .tg registry compromise affecting domain information and nameserver records, not to a CA key compromise or CA shutdown. The exact CCADB candidate-report state or revocation-reason code is not stated in the thread.
OneCRL entries were added for revoked end-entity certificates chaining to Let's Encrypt Authority X3. The thread states the primary google.tg certificate was added to OneCRL in Bug 1414089 and was live by 2017-11-02, and the local OneCRL data tied to Bug 1414039 shows 39 additional enabled entries created by j**********c@mozilla.com on 2017-11-03 with the label "registry problems - remove in Feb 2018"; one of those entries was last modified on 2017-11-06.
Explicitly stated as manually adding certificates that Let's Encrypt had already revoked for the incident; no CCADB candidate-report state, revocation reason code, or qualifying CCADB field is stated.
Explicitly stated .tg registry compromise / alteration of domain name and NS information, initially reported by Google for google.tg and later discussed with statements from the .tg registry and Let's Encrypt about temporary suspension and later resumption of .tg issuance.
Explicit in OneCRL thread · 0.97
- 2017-11-02Kathleen Wilson opened Bug 1414039 after relaying Adam Langley's report of an attacker-controlled google.tg certificate issued by Let's Encrypt and reportedly used in the wild.
- 2017-11-02Mozilla participants agreed OneCRL was appropriate even though Firefox pinning likely blocked the specific google.tg certificate.
- 2017-11-02J.C. Jones said he was working on the OneCRL change and later reported the primary certificate had been added to OneCRL in Bug 1414089 and was live.
- 2017-11-02J.C. Jones reported Let's Encrypt Operations had blocked issuance for *.tg as of 13:43 PDT.
- 2017-11-03Kathleen Wilson confirmed the primary google.tg certificate was present in OneCRL.
- 2017-11-03J.C. Jones posted 39 Let's Encrypt serial numbers that were "now revoked by Let's Encrypt for this incident" and said he was producing the OneCRL change.
- 2017-11-03Kathleen Wilson proposed the public OneCRL label "registry problems - remove in Feb 2018," and later approved the resulting OneCRL entries.
- 2017-11-09Kathleen Wilson summarized that Mozilla had added OneCRL entries for the subject certificate and other .tg certificates revoked by Let's Encrypt.
- 2017-11-15Kathleen Wilson recorded additional incident details indicating the registry problem likely began around 2017-10-25 and was considered resolved by the registry on 2017-11-10.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1552493010014,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1414039",
"who": "jc@mozilla.com",
"why": ".",
"name": "registry problems - remove in Feb 2018",
"created": "2017-11-03T20:43:04.723390Z"
},
"enabled": true,
"issuerName": "MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQDExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMw==",
"serialNumber": "BKobzjrOxa/6kCR0ImKoqaQW",
"id": "87cdeef4-a32f-4f89-90b2-d979766f66fd",
"last_modified": 1509744792287
}