Hi Josh, Does Let's Encrypt plan to implement any systematic or programmatic fixes to ensure certificates are promptly revoked in the future?
Did you perform a scan of all your issued certificates to see if any others were effected? Alex On Sat, Sep 9, 2017 at 8:14 PM, josh--- via dev-security-policy < [email protected]> wrote: > Thank you for bringing this oversight to our attention. The certificate in > question has been revoked. > > The original incident report from July 16 was accidentally considered > closed on the basis of a fix for our infrastructure without actually > revoking the certificate that led to the report. > > Reading the recorded conversation, it seems we got overly focused on fix > for our infrastructure and lost sight of the fact that the certificate > itself needed to be revoked. I imagine our guard was let down a bit by the > fact that the cert was issued specifically to test us, it wasn't a weak key > "in the wild." > > Let’s Encrypt has checked for some forms of weak keys since we launched, > and we added additional checks that would have caught this on July 20, > 2017. We were already in the process of developing and deploying the > additional checks before we received the original report from Hanno. > > On Saturday, September 9, 2017 at 2:22:07 PM UTC-5, Hanno Böck wrote: > > Hi, > > > > A while ago I tested how some CAs would react to certificate requests > > with debian weak keys. > > > > I was able to get a certificate from Let's Encrypt with a debian weak > > key. Here is it: > > https://crt.sh/?id=173588030 > > > > I reported this to Let's Encrypt. They told me that they are aware they > > weren't checking debian weak keys, but they were in the process of > > deploying a check: > > https://github.com/letsencrypt/boulder/pull/2765 > > > > I don't know if this is active by now, but I assume so. > > > > Maybe notable: The certificate hasn't been revoked, despite me > > reporting it. However I haven't explicitely asked for revocation (and I > > could revoke it myself, given that I have the private key). > > > > > > I have also tried to get a cert with a debian weak key from the > > free trial offerings from Comodo and Symantec. Both rejected the > > request. > > > > -- > > Hanno Böck > > https://hboeck.de/ > > > > mail/jabber: [email protected] > > GPG: FE73757FA60E4E21B937579FA5880072BBB51E42 > > _______________________________________________ > dev-security-policy mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security-policy > _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

