Live data from Hacker News

Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

letsencrypt.status.io

21–30 of 97 posts

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#21

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

Wonder what incident that even could have been.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#22

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

>pieces of critical Internet infrastructure that just quietly hums away in the background,

And donation supported no less

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#23
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

Useful context: https://letsencrypt.org/2026/01/15/6day-and-ip-general-avail...

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#24
post #6

Hopefully it's just a technical issue and not something like a key compromise. This could have disastrous effects considering how much of the web runs on LE certs these days. Granted if it's configured properly everyone should have 30 days of leeway before having to issue new certs...

"We have been made aware of a potential incident and are shutting down all issuance" seems to lean towards the latter and not simply a technical issue :(

Josh Aas is on the thread. It's a compliance issue, they expect to be issuing shortly.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#26
post #11

Earlier quoted context omitted.

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

You're holding your 6-day cert wrong

Thought that was the iPhone 6

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#28
post #19

This is a compliance incident, we should be issuing again shortly. Update: Issuance is back up. Update: Preliminary incident report: https://bugzilla.mozilla.org/show_bug.cgi?id=2038351

> This is a compliance incident

Uh. I don't know if I like the sound of that...

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#30
post #19

This is a compliance incident, we should be issuing again shortly. Update: Issuance is back up. Update: Preliminary incident report: https://bugzilla.mozilla.org/show_bug.cgi?id=2038351

Thanks for the assurance, jaas! Keep up the good work
Post reply on HN