← Back to all briefings
Infrastructure 5 min read Published Updated Credibility 40/100

Infrastructure Briefing — Let’s Encrypt mass certificate revocation for CAA bug

Let’s Encrypt disclosed a Certificate Authority Authorization (CAA) rechecking bug that violated issuance rules for roughly three million certificates. The CA announced mass revocation beginning March 4, 2020, requiring site operators to replace affected TLS certificates to avoid outages.

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)

Executive briefing: Let’s Encrypt found its CAA validation code skipped required rechecks before issuing roughly three million TLS certificates. To maintain compliance with CA/Browser Forum rules, the CA announced it would revoke and replace the affected certificates starting March 4, 2020.

Why it matters

  • Service continuity: Unreplaced certificates would trigger browser errors and break production services when revoked.
  • Automation dependence: Many operators rely on unattended ACME renewals; manual intervention was required to replace affected certs before revocation.
  • Governance: Highlights the need for monitoring CA incident disclosures even when using automated certificate management.

Operator actions

  1. Identify impact: Use Let’s Encrypt’s published ACME client logs or the serial-number check tool to flag certificates issued between February 29 and March 3, 2020.
  2. Replace certificates: Reissue and deploy new TLS certificates for all affected domains before revocation deadlines.
  3. Validate automation: Confirm ACME clients correctly perform CAA rechecks and alert on CA incident bulletins.
Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)
Horizontal bar chart of credibility scores per cited source.
Credibility scores for every source cited in this briefing. Source data (JSON)

Continue in the Infrastructure pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Let’s Encrypt
  • CAA
  • TLS certificates
Back to curated briefings