/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Let's Encrypt discovers a bug in its Certification Authority Authorization code, meaning affected users need to manually force-renew certs to avoid downtime

Let's Encrypt users will need to manually force-renew once to avoid downtime.  —  On Leap Day, Let's Encrypt announced …

Ars Technica Jim Salter

Context & Ripple Effects

Let's Encrypt's entire model rests on automation: since its free certificate authority launched and later shipped wildcard certificates with ACME v2, the pitch has been that renewals happen without human intervention. A bug in its Certification Authority Authorization checking code breaks that promise for a slice of its base.

The stakes are familiar from recent history: when 80+ US government TLS certificates went unrenewed during the shutdown, NASA and DOJ sites simply vanished from browsers. This time the failure is on the CA side, but the remedy — a one-time manual force-renewal — puts the burden back on site operators.

First-order effects

  • Affected Let's Encrypt subscribers must run a manual force-renewal or their certificates will lapse into browser warnings and downtime; the CA's support channels absorb a wave of one-off intervention requests.

Second-order effects

  • Operators who treated ACME renewal as fire-and-forget are pushed toward expiry monitoring and fallback tooling, while commercial certificate authorities gain a talking point for selling managed-renewal services against a free rival's reliability stumble.

Third-order effects

  • If a single free CA's code defect can threaten web-wide availability, the ecosystem drifts toward multi-CA redundancy and treats certificate-authority software itself as critical infrastructure warranting the same scrutiny as the certificates it issues.

The trend: HTTPS issuance is consolidating around automated, free certificate authorities whose internal failures now propagate directly into site downtime at web scale.

Discussion

  • @letsencrypt @letsencrypt on x
    On March 4, we will revoke 2.6% of currently active Let's Encrypt certificates. These certificates were affected by a compliance bug. Please see the details at: https://community.letsencrypt.org/ ...
  • @scott_helme Scott Helme on x
    Let's Encrypt identified a bug in their CAA checking and disabled issuance for 2h 12m whilst they patched: https://community.letsencrypt.org/ ...
  • @mrkoot Matthijs R. Koot on x
    That compliance bug being that when a certificate request contained N domain names that needed CAA rechecking, LE's homegrown CA-software Boulder would pick one domain name and check it N times. https://twitter.com/... /c @thegrugq
  • @plesk @plesk on x
    Let's Encrypt to revoke 3 Mill. TLS certificates due to a bug. You can check your certificates at https://checkhost.unboundtest.com/ to see if you are affected. If your cert is affected, you should simply renew it. #letsencrypt #revoke #ssl #sslcertificates #bug https://twitter.c…
  • @threddyrex @threddyrex on x
    Stop ignoring those email reminders and renew your certs. https://twitter.com/...
  • @node5 William Metcalf on x
    And yet you still refuse to revoke certificates of phishing sites. I bet people have lost a bazillionty dollars more due to phish behind Let's Encrypt certs than they ever will to this bug. https://twitter.com/...
  • @thorsheim Per Thorsheim on x
    THANK YOU @hanno for “lecaa” tool to easily check a (long) list of domains for affected @letsencrypt certificates being revoked on (March 4! https://github.com/... Info: https://community.letsencrypt.org/ ... Also this thread from @Scott_Helme with *GREAT* info: https://twitter.c…
  • @garyw_ Gary Williams on x
    I suspect most people are aware but just in case you're not, Let's Encrypt are going to revoke over 3 millions certs due to a bug -> https://community.letsencrypt.org/ ...
  • @sucurisecurity Sucuri on x
    Heads up to Let's Encrypt users! #SSL https://twitter.com/...
  • @nick_craver Nick Craver on x
    Our SRE team just fixed all of our Let's Encrypt certificates because *a user* let us know they were going to be revoked in < 12 hours. We still have gotten zero notifications from @letsencrypt about this revocation happening. Heads up if this affects you: https://community.letse…