Open
Bug 2062418
Opened 5 days ago
Updated 6 minutes ago
Let's Encrypt: CPS missing root program attestation
Categories
(CA Program :: CA Certificate Compliance, task)
CA Program
CA Certificate Compliance
Tracking
(Not tracked)
NEW
People
(Reporter: aaron, Assigned: aaron)
Details
(Whiteboard: Next update 2026-08-24 [ca-compliance] [policy-failure] )
Preliminary Incident Report
Summary
- Incident description: The Let's Encrypt / ISRG CP/CPS does not include explicit statements of adherence to root program policies. We were aware of the upcoming requirement and had tracked it in our public CP/CPS repository, but failed to make the necessary updates by the policy effective date.
- Relevant policies: Chrome Root Program Policy v1.8, Section 1.1.3:
Effective June 15, 2026, a Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.
- Source of incident disclosure: Self Reported. (GTS filed a similar incident in Bug 2058261, which was noted by our compliance review tooling. GTS also sent an email highlighting that incident to some LE engineers, but did not do so through official incident reporting channels.)
We will publish a full incident report by 2026-08-24.
Flags: needinfo?(incident-reporting)
Updated•5 days ago
|
Assignee: nobody → aaron
Flags: needinfo?(incident-reporting)
Whiteboard: Next update 2026-08-24 [ca-compliance] [policy-failure]
Comment 2•2 days ago
|
||
Yesterday evening, 2026-08-13, Let's Encrypt PMA published ISRG CP/CPS v6.2, including an edit to Section 1.1 that brings us into compliance with Section 1.1.3 of the Chrome Root Program Policy.
We're still planning to publish a full incident report on or before 2026-08-24.
You need to log in
before you can comment on or make changes to this bug.
Description
•