Home Let’s Encrypt Bug Leads to 3 Million HTTPS Certs Revoked!

Let’s Encrypt Bug Leads to 3 Million HTTPS Certs Revoked!

Recently, a bug has been found in Let’s Encrypt in their CAA code. This means that they now have to go over approved sites and potentially strip them of their TLS HTTPS certificate. Let’s Encrypt have become Let’s Revoke. We are hoping this is only a temporary situation in their security business.

What was happening is that people would submit a certain amount of domains in to be checked. Let’s say 5 domain names. The code would pick one domain and check it 5 times. If we say that this one domain was certified, all 5 of the domains sent though would get certified.

let's encrypt bug

Let’s Encrypt said that they had confirmed the bug at 03:08 UTC and stopped issueing TSL Certs at 03:10 UTC. They developed a fix for the bug about two hours later and then re-enabled issuance. Any affected certificate owners have been notified by email according to Let’s Encrypt. The owners of the certificates have until 00:00 UTC on March 4th to renew and replace their HTTPS certificates.

Due to the bug, named Boulder, Let’s Encrypt will be revoking 3,048,289 currently-valid certificates. As large as that number may seem, it is only 2.6% of their total 116 million (approx.) active certificates.

If a website has a SSL certificate, this means that any data that you’ve exchanged with this site is securely encrypted. It also makes sure that the site you’re visiting is the legitimate one and not a malicious scam site. As well as this, have you ever noticed that you trust a site with a SSL cert more than a site without one?

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the tech industry for major developments, new product launches, AI breakthroughs, video game releases and other newsworthy events. Editors assign relevant stories to staff writers or freelance contributors with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Get the biggest tech headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Tech News

    Explore the latest in tech with our Tech News. We cut through the noise for concise, relevant updates, keeping you informed about the rapidly evolving tech landscape with curated content that separates signal from noise.

    In-Depth Tech Stories

    Explore tech impact in In-Depth Stories. Narrative data journalism offers comprehensive analyses, revealing stories behind data. Understand industry trends for a deeper perspective on tech's intricate relationships with society.

    Expert Reviews

    Empower decisions with Expert Reviews, merging industry expertise and insightful analysis. Delve into tech intricacies, get the best deals, and stay ahead with our trustworthy guide to navigating the ever-changing tech market.