{"id":12143,"date":"2020-03-03T16:32:11","date_gmt":"2020-03-03T21:32:11","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12143"},"modified":"2020-09-16T11:06:42","modified_gmt":"2020-09-16T15:06:42","slug":"lets-encrypt-to-revoke-3-million-ssl-certificates-on-march-4","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/lets-encrypt-to-revoke-3-million-ssl-certificates-on-march-4\/","title":{"rendered":"Let\u2019s Encrypt to Revoke 3 Million SSL Certificates on March 4"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"the-world\u2019s-leading-free-ssl-provider-announces-that-millions-of-certificates-are-being-revoked-due-to-a-bug-they-discovered-days-ago-\u2014-giving-subscribers-potentially-only-hours-to-respond\">The world\u2019s leading free SSL provider announces that millions of\ncertificates are being revoked due to a bug they discovered days ago \u2014 giving subscribers\npotentially only hours to respond<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt, the world\u2019s biggest free SSL certificate authority (CA), announced to subscribers today (March 3) that <a href=\"https:\/\/community.letsencrypt.org\/t\/2020-02-29-caa-rechecking-bug\/114591\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">they discovered a bug<\/a> that\u2019s causing them to revoke more than 3 million SSL\/TLS certificates by tomorrow, March 4 (at 00:00 UTC at the earliest). The trouble? Their announcement barely gives their users time to react.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Due to the short revocation timeline that\u2019s stipulated by\nthe CA\/B Forum\u2019s baseline requirements, it means that Let\u2019s Encrypt had to rush\nto inform users about the revocation that\u2019ll be completed in less than 24\nhours. That means, unfortunately for LE certificate subscribers \u2014 people like\nyou, possibly \u2014 that your certificates may be affected and you may not know it.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But why do they need to revoke these certificates at all? What\ndoes this mean for Let\u2019s Encrypt SSL subscribers? And what should you do if\nyou\u2019re one of those whose certificates are affected?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">What we&#8217;re hashing out&#8230;<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewbox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#the-world\u2019s-leading-free-ssl-provider-announces-that-millions-of-certificates-are-being-revoked-due-to-a-bug-they-discovered-days-ago-\u2014-giving-subscribers-potentially-only-hours-to-respond\">The world\u2019s leading free SSL provider announces that millions of\ncertificates are being revoked due to a bug they discovered days ago \u2014 giving subscribers\npotentially only hours to respond<\/a><ol><\/ol><\/li><li><a href=\"#what\u2019s-the-situation-with-let\u2019s-encrypt\u2019s-mass-revocation\">What\u2019s the Situation with Let\u2019s Encrypt\u2019s Mass Revocation?<\/a><ol><\/ol><\/li><li><a href=\"#why-caa-records-matter-in-the-certificate-issuance-process\">Why CAA Records Matter in the Certificate Issuance Process<\/a><ol><\/ol><\/li><li><a href=\"#let\u2019s-encrypt-appeals-for-exemption\">Let\u2019s Encrypt Appeals for Exemption<\/a><ol><\/ol><\/li><li><a href=\"#why-a-let\u2019s-encrypt-revocation-is-such-a-big-deal\">Why a Let\u2019s Encrypt Revocation is Such a Big Deal<\/a><ol><li><a href=\"#not-everyone-knows-that-they-may-be-affected\">Not Everyone Knows That They May Be Affected<\/a><ol><\/ol><\/li><li><a href=\"#le-rate-limits-hamper-users\">LE Rate Limits Hamper Users <\/a><ol><\/ol><\/li><li><a href=\"#le-subscribers-have-limited-visibility-and-support\">LE Subscribers Have Limited Visibility and Support<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#what-you-should-do-if-you\u2019re-using-any-let\u2019s-encrypt-certificates\">What You Should Do If You\u2019re Using Any Let\u2019s Encrypt Certificates<\/a><ol><li><a href=\"#step-one-check-your-certificates\">Step One: Check Your Certificates<\/a><ol><\/ol><\/li><li><a href=\"#renew-your-certificates\">Renew Your Certificates<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#final-thoughts\">Final Thoughts<\/a><ol><\/ol><\/li><\/ol><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what\u2019s-the-situation-with-let\u2019s-encrypt\u2019s-mass-revocation\">What\u2019s the Situation with Let\u2019s Encrypt\u2019s Mass Revocation?<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"850\" height=\"915\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-error.png\" alt=\"Graphic: security issue errors for Let's Encrypt certificates in cPanel\" class=\"wp-image-12144 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-error.png 850w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-error-279x300.png 279w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-error-768x827.png 768w\" sizes=\"auto, (max-width: 850px) 100vw, 850px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">On Feb. 29, Let\u2019s Encrypt discovered a bug in their code was allowing the issuance of SSL\/TLS certificates that didn\u2019t go through proper domain record checks. This is resulting in a mass revocation of 3,048,289 valid SSL certificates out of their 116 million. That\u2019s 2.6% of all of their existing certificates! <\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<p class=\"wp-block-paragraph\">So, if you don\u2019t renew your affected SSL\/TLS certificate(s) before the March 4 revocation deadline, you\u2019re going to find yourself in hot water. If Let\u2019s Encrypt revokes your cert before you have a chance to renew, your website users will see ugly security warnings that may drive them away from your website. These messages will continue to display until you renew your certificate!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jacob Hoffman-Andrews, lead developer for Let\u2019s Encrypt, <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1619047\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">posted on Mozilla\u2019s Bugzilla web forum<\/a> to explain the issue more in depth: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>On 2020-02-29 UTC, Let\u2019s Encrypt found a bug in our CAA code. Our CA software, Boulder, checks for CAA records at the same time it validates a subscriber\u2019s control of a domain name. Most subscribers issue a certificate immediately after domain control validation, but we consider a validation good for 30 days. That means in some cases we need to check CAA records a second time, just before issuance. Specifically, we have to check CAA within 8 hours prior to issuance (per BRs \u00a73.2.2.8), so any domain name that was validated more than 8 hours ago requires rechecking.<\/em> <\/p><p><em>The bug: when a certificate request contained N domain names that needed CAA rechecking, Boulder would pick one domain name and check it N times. What this means in practice is that if a subscriber validated a domain name at time X, and the CAA records for that domain at time X allowed Let\u2019s Encrypt issuance, that subscriber would be able to issue a certificate containing that domain name until X+30 days, even if someone later installed CAA records on that domain name that prohibit issuance by Let\u2019s Encrypt.\u201d<\/em> <\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">So, what does all of this mean? What we\u2019re talking about here\nrelates to checks of certificate authority authorization (CAA) records.&nbsp; <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-caa-records-matter-in-the-certificate-issuance-process\">Why CAA Records Matter in the Certificate Issuance Process<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A CAA record is a resource that was created to help prevent fraudulent SSL\/TLS certificates from being issued for any domain and to help strengthen the PKI ecosystem. It\u2019s a DNS record on the domain that <a href=\"https:\/\/www.thesslstore.com\/blog\/caa-checking-mandatory\/\">every issuing CA is required to<\/a> check. It\u2019s an easy way for a CA to know whether they\u2019re authorized to issue a certificate for a domain: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>If a CAA record exists, it means that only the CA(s)\nlisted can issue certificates for that specific domain.<\/li><li>If a CAA record doesn\u2019t exist, it means that any\nCA can issue a certificate for the domain in question.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So, whenever a certificate authority issues an SSL\/TLS certificate, they\u2019re required to follow specific steps outlined in the CA\/Browser Forum\u2019s baseline requirements (BR) documentation. The CA\/B Forum is an industry body that consists of CAs, browsers, and device manufacturers. They&#8217;re responsible for outlining and enforcing requirements relating to the industry. BR \u00a73.2.2.8 (CAA Records) stipulates the following: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>As part of the issuance process, the CA MUST check for CAA records and follow the processing instructions found, for each dNSName in the subjectAltName extension of the certificate to be issued, as specified in RFC 6844 as amended by Errata 5065 (Appendix A). If the CA issues, they MUST do so within the TTL of the CAA record, or 8 hours, whichever is greater<\/em>.  <\/p><p><em>This stipulation does not prevent the CA from checking CAA records at any other time.\u201d<\/em>  <\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This essentially means that Let\u2019s Encrypt was required to\ncheck the CAA records within 8 hours prior to the certificate being issued. If\nthey don\u2019t meet these requirements, whether because of the bug or for any other\nreason, they must mass revoke any certificates that weren\u2019t issued with proper\nCAA checks. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"let\u2019s-encrypt-appeals-for-exemption\">Let\u2019s Encrypt Appeals for Exemption<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Bearing all of this in mind, Let\u2019s Encrypt has found itself in the unenviable position of needing to revoke millions of certificates. So, they informed users but first tried to <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1619179\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">request a certificate revocation exemption<\/a> with one of the major web browsers, Mozilla Firefox. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, <a href=\"https:\/\/wiki.mozilla.org\/CA\/Responding_To_An_Incident#Revocation\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Mozilla pointed them to their docs for guidance<\/a> for what actions CAs, like Let\u2019s Encrypt, should take with regard to certificate mis-issuances: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The CA should cease issuance from the affected\nportion of the public key infrastructure (PKI) to properly diagnose the cause\nof the issue; or<\/li><li>The CA should explain why they have chosen to\nnot do so.&nbsp; <\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, any affected CA that decides to restart\nreissuance once the cause of their problems is diagnosed must have a process in\nplace that prevents additional mis-issuances. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mozilla also offers guidance for situations requiring certificate\nrevocation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Mozilla recognizes that in some&nbsp;<strong>exceptional<\/strong>&nbsp;circumstances, revoking misissued certificates within the prescribed deadline may cause significant harm, such as when the certificate is used in critical infrastructure and cannot be safely replaced prior to the revocation deadline, or when the volume of revocations in a short period of time would result in a large cumulative impact to the web. However, Mozilla does not grant exceptions to the BR revocation requirements. It is our position that your CA is ultimately responsible for deciding if the harm caused by following the requirements of BR section 4.9.1 outweighs the risks that are passed on to individuals who rely on the web PKI by choosing not to meet this requirement.\u201d<\/em> <\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">It <em>may<\/em> cause significant harm? Yeah, that\u2019s quite the\nunderstatement. However, revoking certificates that aren\u2019t properly issued is\nan absolute must for any CA. So, Let\u2019s Encrypt is doing the right thing by\nrevoking the certificates. But that doesn\u2019t mean this response isn\u2019t causing\nissues for subscribers or indicative of larger issues.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-a-let\u2019s-encrypt-revocation-is-such-a-big-deal\">Why a Let\u2019s Encrypt Revocation is Such a Big Deal<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Okay, so virtually every CA has found themselves having to\nrevoke SSL\/TLS certificates at one time or another. But why is this particular\nsituation causing such a stir? <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"not-everyone-knows-that-they-may-be-affected\">Not Everyone Knows That They May Be Affected<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt says that they emailed \u201caffected\nsubscribers for whom we have contact information.\u201d However, because\nLet\u2019s Encrypt doesn\u2019t have contact information for all of their customers (you\nknow, seeing as how they\u2019re basically just a domain validation SSL certificate\nprovider), it means that they may not reach people in time for them to update\ntheir certificates before the revocation becomes effective. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They did, however, post on the Let\u2019s Encrypt forum a <a href=\"https:\/\/unboundtest.com\/caaproblem.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">link to a tool<\/a> you can use to see if you\u2019re using an affected certificate. But this doesn\u2019t help if you don\u2019t receive a notification and you don\u2019t check their forums daily for news on the off chance there might be a sudden revocation announced. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is indicative of a larger issue of visibility for Let\u2019s Encrypt users \u2014 one that can be very costly issue for affected organizations. Considering that KeyFactor and the Ponemon Institute estimate that <a href=\"https:\/\/cdn2.hubspot.net\/hubfs\/408597\/Keyfactor%20White%20Papers\/Keyfactor-Ponemon%20Institute%20Report%20-%20The%20Impact%20of%20Unsecured%20Digital%20Identities.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">unplanned certificate outages due to expired certificates<\/a> can cost more than $11 million, imagine how costly it can be for organizations that don\u2019t know that they\u2019re experiencing outages for reasons beyond their control!<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"le-rate-limits-hamper-users\">LE Rate Limits Hamper Users <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There was a lot of chatter on the Let\u2019s Encrypt forum about <a href=\"https:\/\/letsencrypt.org\/docs\/rate-limits\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">rate limits<\/a>. But what does that mean? According to their documentation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Let\u2019s Encrypt provides rate limits to ensure fair usage by as many people as possible. We believe these rate limits are high enough to work for most people by default. We\u2019ve also designed them so renewing a certificate almost never hits a rate limit, and so that large organizations can gradually increase the number of certificates they can issue without requiring intervention from Let\u2019s Encrypt.\u201d <\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Basically, Let\u2019s Encrypt has several types of rate limits:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>New Certificate Orders (for ACME clients):<\/strong>\n300 per account, per 3 hours.<\/li><li><strong>Pending Authorizations:<\/strong> 300 per account.<\/li><li><strong>Certificates Per Registered Domain:<\/strong> 50\nper week.<\/li><li><strong>Names Per Certificate:<\/strong> 100.<\/li><li><strong>Duplicate Certificate:<\/strong> 5 per week.<\/li><li><strong>Failed Validation:<\/strong> 5 failures per\naccount, per hostname, per hour.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Surely the rate limits reset in instances of revocation,\nthough, right? Apparently not. The document goes on to state that \u201c<strong>Revoking\ncertificates does not reset rate limits<\/strong>, because the resources used to\nissue those certificates have already been consumed.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, basically, this means that LE certificate holders who\nneed to renew their certificates found themselves facing rate limitations of\n300 new orders per account every three hours. A silver lining, though, is that Let\u2019s\nEncrypt has agreed to temporarily: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>double the duplicate certificate limit; <\/li><li>override the global rate limit from 300 per three\nhours to 10,000 per three hours; and <\/li><li>increase the invalid authorizations per account\nrate limit from 5 to 10. <\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"le-subscribers-have-limited-visibility-and-support\">LE Subscribers Have Limited Visibility and Support<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re going to issue a mass revocation, you\u2019d ideally\nwant to give your customers adequate time to respond and give them plenty of\nresources to help them do so. But seeing how Let\u2019s Encrypt is a free CA, all\npeople really have to turn to for help is a bunch of digital documents and web\nforum conversations. Not very helpful \u2014 particularly when you\u2019re on such a\ntight deadline! <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-you-should-do-if-you\u2019re-using-any-let\u2019s-encrypt-certificates\">What You Should Do If You\u2019re Using Any Let\u2019s Encrypt Certificates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So, if you\u2019re one of the unlucky people who are now on the\nbrink of having your Let\u2019s Encrypt certificate(s) revoked, we\u2019re here to help.\nWe\u2019re not just going to tell you to read an insanely long series of web forum\nposts, nor are we going to force you to search a community forum&#8230; We\u2019ll\nactually walk you through the steps here. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"step-one-check-your-certificates\">Step One: Check Your Certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Not sure if your certificates are affected \u2014 and if so, which ones are specifically? You can <a href=\"https:\/\/letsencrypt.org\/caaproblem\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">check your certificate serial numbers<\/a> to see if any match Let\u2019s Encrypt\u2019s list of affected certificates. You\u2019ll want to download the list of affected certificates from the link above and search for lines that start with account IDs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Otherwise, you can use this handy <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/checkhost.unboundtest.com\/\" target=\"_blank\">online tool<\/a> or run a command in your interface (if you\u2019re using Linux or a BSD-like system):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl s_client -connect example.com:443 -showcerts &lt;\/dev\/null 2>\/dev\/null | openssl x509 -text -noout | grep -A 1 Serial\\ Number | tr -d :<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"renew-your-certificates\">Renew Your Certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once you\u2019ve determined that your certificates are, in fact,\naffected, the next step is to renew your certificates. If you were using\ncommercial SSL\/TLS certificates with a longer lifespan than 90 days, it would\nmake more sense to reissue your certificate. However, since this is affecting Let\u2019s\nEncrypt free SSL\/TLS certificates with significantly shorter validity, then it\nmakes sense to simply renew your certificates. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re using an ACME client to renew your certs, you\u2019ll\nneed to refer to its specific documentation relating to the SSL\/TLS certificate\nrenewal process. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re using Certbot, try using the following command: <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>certbot renew --force-renewal<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Lastly, if you\u2019re using cPanel to manage your Let\u2019s Encrypt\ncertificate(s), you can renew yours there as well. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"544\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-renew-1024x544.png\" alt=\"\" class=\"wp-image-12145 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-renew-1024x544.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-renew-300x159.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-renew-768x408.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/LE-renew.png 1525w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">When we tested, we were able to issue a new SSL certificate. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"final-thoughts\">Final Thoughts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every major CA has had instances where they&#8217;ve needed to\nrevoke certificates. And it&#8217;s never a fun process. But as this incident\nhighlights, revocations can cause significantly more problems when they involve\na free CA. The lack of contact details and support capabilities make it harder\nto ensure customers can re-issue certificates quickly to avoid downtime. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The world\u2019s leading free SSL provider announces that millions of certificates are being revoked due to a bug they discovered days ago \u2014 giving subscribers potentially only hours to respond&#8230;<\/p>\n","protected":false},"author":17,"featured_media":12146,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130,17,10200],"tags":[194,163],"class_list":["post-12143","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","category-industry-lowdown","category-monthly-digest","tag-certificate-revocation","tag-revocation","post-with-tags"],"views":22683,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/lets-encrypt-certificate-revocation.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12143"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12143\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12146"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}