Hi Josh,

Does Let's Encrypt plan to implement any systematic or programmatic fixes
to ensure certificates are promptly revoked in the future?

Did you perform a scan of all your issued certificates to see if any others
were effected?

Alex

On Sat, Sep 9, 2017 at 8:14 PM, josh--- via dev-security-policy <
[email protected]> wrote:

> Thank you for bringing this oversight to our attention. The certificate in
> question has been revoked.
>
> The original incident report from July 16 was accidentally considered
> closed on the basis of a fix for our infrastructure without actually
> revoking the certificate that led to the report.
>
> Reading the recorded conversation, it seems we got overly focused on fix
> for our infrastructure and lost sight of the fact that the certificate
> itself needed to be revoked. I imagine our guard was let down a bit by the
> fact that the cert was issued specifically to test us, it wasn't a weak key
> "in the wild."
>
> Let’s Encrypt has checked for some forms of weak keys since we launched,
> and we added additional checks that would have caught this on July 20,
> 2017. We were already in the process of developing and deploying the
> additional checks before we received the original report from Hanno.
>
> On Saturday, September 9, 2017 at 2:22:07 PM UTC-5, Hanno Böck wrote:
> > Hi,
> >
> > A while ago I tested how some CAs would react to certificate requests
> > with debian weak keys.
> >
> > I was able to get a certificate from Let's Encrypt with a debian weak
> > key. Here is it:
> > https://crt.sh/?id=173588030
> >
> > I reported this to Let's Encrypt. They told me that they are aware they
> > weren't checking debian weak keys, but they were in the process of
> > deploying a check:
> > https://github.com/letsencrypt/boulder/pull/2765
> >
> > I don't know if this is active by now, but I assume so.
> >
> > Maybe notable: The certificate hasn't been revoked, despite me
> > reporting it. However I haven't explicitely asked for revocation (and I
> > could revoke it myself, given that I have the private key).
> >
> >
> > I have also tried to get a cert with a debian weak key from the
> > free trial offerings from Comodo and Symantec. Both rejected the
> > request.
> >
> > --
> > Hanno Böck
> > https://hboeck.de/
> >
> > mail/jabber: [email protected]
> > GPG: FE73757FA60E4E21B937579FA5880072BBB51E42
>
> _______________________________________________
> dev-security-policy mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security-policy
>
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to