I am reading very intresting and very important stuff in the firefox bugtracker.

they seem to plan to distrust LE explicity if there wont be the complete audit within the timelimit which is “within ninety (90) days of issuing the first Publicly-Trusted Certificate.” the first public LE Cert is for helloworld which was issued sep 12 20:22:00 UTC and as it’s conveniently valid for 90 days we can just take the expiration as timelimit for the audit which is dec 11 20:22:00 the the way, that is

since the cert has changed now, here’s the data from CT:

as this spells out serious trouble I just want to ask how the audit is going.

Problem with openssl and verify CAfile

The second issue was opened by someone outside of Mozilla (who happens to be a commercial CA reseller, I wonder what his motives are). It’s already been closed with “RESOLVED INVALID”. It’s just FUD. No one from Mozilla has in any way indicated that there’s a problem.


for now. the baseline requirements still stand so they need to have an audit within 90 days from the first cert.

Baseline 8.1 states

The point-in-time readiness assessment SHALL be completed no earlier than twelve (12) months prior to issuing Publicly-Trusted Certificates and SHALL be followed by a complete audit under such scheme within ninety (90) days of issuing the first Publicly-Trusted Certificate.

shall = must for the people who arent that good in english.
in short they need a readiness assessment (which already happened) and after that they must geta full audit within 90 days after first cert.


At least some of the discussion seems to be that the finalized audit can be completed on a longer timeframe.

It’s an acronym standing for Fear Uncertainty and Doubt.

~~ For those terms, I always recommend to refer to RFC 2119, which states:

SHOULD: This word, or the adjective “RECOMMENDED”, mean that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications must be understood and carefully weighed before choosing a different course.

The word “MUST” is defined separately. ~~

If you’re correcting someone, do it correctly: the term “SHALL” is defined in the same paragraph as “MUST”: 1. (They are equal.) He didn’t say anything about “SHOULD” :wink:


No one said you should have known those things, that’s why I replied. Mozilla’s response to the issue seems to indicate that their interpretation of the policies is that LE has more than 90 days to provide the audit report to them. I would be surprised if a project co-founded and sponsored by Mozilla would somehow forget about Mozilla policies.


yes but the audit itself still has to be done in 90 days after first cert, and the audit time is most certainly written in the baseline requirements, and that is friday.

also I think if they would have gotten such an important step completed I think it would be in the blog by long.


It would not be completed until they got a report. Announcing that it’s completed is like telling everyone in your family you completed some college class while you’re still waiting for the report on your last exam (which you might have failed) - doesn’t really mean much.


the point is they have to have it completed and gotten their report within 90 days iirc, but the point is that it doesnt exactly matter when LE gives the report to mozilla. that’s how I think it is.


As far as I understand… they have till this weekend to complete a full audit. They have 30 more days to file the full report. If they fail, IdenTrust would have to revoke the cert.


Also see Independent audits of Let's Encrypt finished


here also the direct links to the docs.

