For several our clients, certificate has been revoked, with a reason of “superseded”. For example: blood-sport.ru domain:
blood-sport.ru.pem: revoked
This Update: Aug 3 19:00:00 2017 GMT
Next Update: Aug 10 19:00:00 2017 GMT
Reason: superseded
Revocation Time: Aug 3 19:20:19 2017 GMT
edu-lib.com domain (and several separate websites wich uses subdomains in this domain):
edu-lib.com.pem: revoked
This Update: Aug 2 15:00:00 2017 GMT
Next Update: Aug 9 15:00:00 2017 GMT
Reason: superseded
Revocation Time: Aug 2 15:47:28 2017 GMT
How can we find out what was exact reason for revocation by each of that certificate? Is there any automation for that?
The Let’s Encrypt CA would not perform a revocation for this reason unilaterally. It must have been requested by some kind of client software that was in possession of the cryptographic keys.
Can you find out what software these people are using to renew their certificates? Maybe the software developer thought that the old certificate should be revoked as soon as the new certificate is issued. That is not a requirement from the Let’s Encrypt site; concurrent validity of old and new certificates is fine with us.
Cc @cpu to look into the circumstances that caused these revocations.