Open
Bug 2074944
Opened 2 days ago
Updated 2 days ago
Let's Encrypt: Root CRLs Missing Reason Code
Categories
(CA Program :: CA Certificate Compliance, task)
CA Program
CA Certificate Compliance
Tracking
(Not tracked)
ASSIGNED
People
(Reporter: aaron, Assigned: aaron)
Details
(Whiteboard: [ca-compliance] [crl-failure])
Preliminary Incident Report
Summary
- Incident description: When Let's Encrypt revoked the Cross-Certified Subordinate CA Certificates of ISRG Root X2, Root YR, and Root YE as part of Bug 2038351, our ceremony tool was configured to revoke them with reason code "superseded". However, due to a bug in the ceremony tool, the reason code entry extension was instead omitted. Only two CRLs (issued by ISRG Root X1 and ISRG Root X2) are impacted. Root CRLs are only issued as part of manual ceremonies, not on an ongoing basis, so the incident is contained.
- Relevant policies:
- TLS BRs, v2.3.0, Section 7.2.2: "
reasonCode… MUST be present unless the CRL entry is for a Certificate not technically capable of causing issuance" - CCADB Policy, v2.1, Section 3.2: "For any revoked subordinate CA certificate, each corresponding revocation entry published to a CRL MUST include a reasonCode extension."
- Microsoft Root Program Requirements, v1.1, Section 2.1.7: "Reason Code must be included in revocations for intermediate certificates."
- Let's Encrypt CP/CPS, v6.2, Section 7.2: "For the status of Subordinate CA Certificates:... RevokedCertificates… Contains: … reasonCode"
- TLS BRs, v2.3.0, Section 7.2.2: "
- Source of incident disclosure: Third Party Reported
Updated•2 days ago
|
Assignee: nobody → aaron
Status: NEW → ASSIGNED
Whiteboard: [ca-compliance] [crl-failure]
You need to log in
before you can comment on or make changes to this bug.
Description
•