HomeSecurityLet's Encrypt revokes 3 million certificates due to bug

Let's Encrypt revokes 3 million certificates due to bug

The Let's Encrypt project is set to revoke more than 3 million TLSdue to a bug discovered in its backend code.

The flaw was discovered in Boulder, Let's Encrypt's server software, which is used to verify users and domains before issuing a TLS certificate.

Let's Encrypt

Specifically, it affects the CAA (Certificate Authority Authorization) standard within Boulder. CAA is a securitythat allows domain owners to prevent Certificate Authorities (CAs) from issuing certificates for their domains.

All Certificate Authorities – like Let's Encrypt – must follow the CAA standard to the letter, or they face severe penalties from browser manufacturers.

However, on Saturday, February 29, as reported in a forum, Let's Encrypt revealed that a bug in Boulder ignored the CAA standard.

The Let's Encrypt team fixed the bug on Saturday after a two-hour effort, and Boulder now verifies CAA fields before issuing new certificates. It's highly unlikely that anyone exploited the bug, the team said.

However, Let's Encrypt announced that it is revoking all certificates issued without proper CAA checks today, in accordance with industry rules as dictated by the CA/B forum.

Only 3 out of 116 million certificates were revoked

According to Let's Encrypt, only 2.6% of certificates are affected by this bug, representing 3,048,289 certificates.

Of these 3 million, one million are duplicates for the same domain/subdomain, putting the actual number of affected certificates at around 2 million.

After revocation, all affected certificates will cause errors in browsers and other applications. So domain owners will need to request a new TLS certificate to replace the old one.

If you want to check which certificates are affected by the bug, you can see the list of TLS certificate serial numbers on this page. Alternatively, you can visit the following website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS