Open Bug 2062418 Opened 5 days ago Updated 6 minutes ago

Let's Encrypt: CPS missing root program attestation

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

People

(Reporter: aaron, Assigned: aaron)

Details

(Whiteboard: Next update 2026-08-24 [ca-compliance] [policy-failure] )

Preliminary Incident Report

Summary

  • Incident description: The Let's Encrypt / ISRG CP/CPS does not include explicit statements of adherence to root program policies. We were aware of the upcoming requirement and had tracked it in our public CP/CPS repository, but failed to make the necessary updates by the policy effective date.
  • Relevant policies: Chrome Root Program Policy v1.8, Section 1.1.3:

    Effective June 15, 2026, a Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.

  • Source of incident disclosure: Self Reported. (GTS filed a similar incident in Bug 2058261, which was noted by our compliance review tooling. GTS also sent an email highlighting that incident to some LE engineers, but did not do so through official incident reporting channels.)

We will publish a full incident report by 2026-08-24.

Flags: needinfo?(incident-reporting)
Assignee: nobody → aaron
Flags: needinfo?(incident-reporting)
Whiteboard: Next update 2026-08-24 [ca-compliance] [policy-failure]

Yesterday evening, 2026-08-13, Let's Encrypt PMA published ISRG CP/CPS v6.2, including an edit to Section 1.1 that brings us into compliance with Section 1.1.3 of the Chrome Root Program Policy.

We're still planning to publish a full incident report on or before 2026-08-24.

You need to log in before you can comment on or make changes to this bug.