Let's Encrypt discovers a bug in its Certification Authority Authorization code, meaning affected users need to manually force-renew certs to avoid downtime
Let's Encrypt users will need to manually force-renew once to avoid downtime. — On Leap Day, Let's Encrypt announced …
The stakes are familiar from recent history: when 80+ US government TLS certificates went unrenewed during the shutdown, NASA and DOJ sites simply vanished from browsers. This time the failure is on the CA side, but the remedy — a one-time manual force-renewal — puts the burden back on site operators.
First-order effects
Affected Let's Encrypt subscribers must run a manual force-renewal or their certificates will lapse into browser warnings and downtime; the CA's support channels absorb a wave of one-off intervention requests.
Second-order effects
Operators who treated ACME renewal as fire-and-forget are pushed toward expiry monitoring and fallback tooling, while commercial certificate authorities gain a talking point for selling managed-renewal services against a free rival's reliability stumble.
Third-order effects
If a single free CA's code defect can threaten web-wide availability, the ecosystem drifts toward multi-CA redundancy and treats certificate-authority software itself as critical infrastructure warranting the same scrutiny as the certificates it issues.
The trend: HTTPS issuance is consolidating around automated, free certificate authorities whose internal failures now propagate directly into site downtime at web scale.
On March 4, we will revoke 2.6% of currently active Let's Encrypt certificates. These certificates were affected by a compliance bug. Please see the details at: https://community.letsencrypt.org/ ...
That compliance bug being that when a certificate request contained N domain names that needed CAA rechecking, LE's homegrown CA-software Boulder would pick one domain name and check it N times. https://twitter.com/... /c @thegrugq
Let's Encrypt to revoke 3 Mill. TLS certificates due to a bug. You can check your certificates at https://checkhost.unboundtest.com/ to see if you are affected. If your cert is affected, you should simply renew it. #letsencrypt #revoke #ssl #sslcertificates #bug https://twitter.c…
And yet you still refuse to revoke certificates of phishing sites. I bet people have lost a bazillionty dollars more due to phish behind Let's Encrypt certs than they ever will to this bug. https://twitter.com/...
THANK YOU @hanno for “lecaa” tool to easily check a (long) list of domains for affected @letsencrypt certificates being revoked on (March 4! https://github.com/... Info: https://community.letsencrypt.org/ ... Also this thread from @Scott_Helme with *GREAT* info: https://twitter.c…
I suspect most people are aware but just in case you're not, Let's Encrypt are going to revoke over 3 millions certs due to a bug -> https://community.letsencrypt.org/ ...
Our SRE team just fixed all of our Let's Encrypt certificates because *a user* let us know they were going to be revoked in < 12 hours. We still have gotten zero notifications from @letsencrypt about this revocation happening. Heads up if this affects you: https://community.letse…