Thank you for bringing this oversight to our attention. The certificate in 
question has been revoked.

The original incident report from July 16 was accidentally considered closed on 
the basis of a fix for our infrastructure without actually revoking the 
certificate that led to the report.

Reading the recorded conversation, it seems we got overly focused on fix for 
our infrastructure and lost sight of the fact that the certificate itself 
needed to be revoked. I imagine our guard was let down a bit by the fact that 
the cert was issued specifically to test us, it wasn't a weak key "in the wild."

Let’s Encrypt has checked for some forms of weak keys since we launched, and we 
added additional checks that would have caught this on July 20, 2017. We were 
already in the process of developing and deploying the additional checks before 
we received the original report from Hanno.

On Saturday, September 9, 2017 at 2:22:07 PM UTC-5, Hanno Böck wrote:
> Hi,
> 
> A while ago I tested how some CAs would react to certificate requests
> with debian weak keys.
> 
> I was able to get a certificate from Let's Encrypt with a debian weak
> key. Here is it:
> https://crt.sh/?id=173588030
> 
> I reported this to Let's Encrypt. They told me that they are aware they
> weren't checking debian weak keys, but they were in the process of
> deploying a check:
> https://github.com/letsencrypt/boulder/pull/2765
> 
> I don't know if this is active by now, but I assume so.
> 
> Maybe notable: The certificate hasn't been revoked, despite me
> reporting it. However I haven't explicitely asked for revocation (and I
> could revoke it myself, given that I have the private key).
> 
> 
> I have also tried to get a cert with a debian weak key from the
> free trial offerings from Comodo and Symantec. Both rejected the
> request.
> 
> -- 
> Hanno Böck
> https://hboeck.de/
> 
> mail/jabber: [email protected]
> GPG: FE73757FA60E4E21B937579FA5880072BBB51E42

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to