I’m not sure what happened, but it looks like on August 12th the *.forensiq.com certificate was revoked. Our monitoring didn’t pick it up, and it wasn’t until someone was testing something in a browser that we realized the cert was revoked.
Can anyone provide any insights as to why the certificate was revoked? I was able to regenerate one today, and it is currently working without any issues.
According to the public revocation record, it appears letsencrypt holds the state of the record. Would it be possible to learn the reason code to help narrow down the root cause? Thanks.
We publish OCSP responses which include the Reason Code. @amerenda, you can use your certificate to query OCSP and retrieve the Reason.
Please keep two things in mind:
OCSP reason codes are fairly generic, it may not be very illuminating
Revocation of certificates can be performed by any party whom can demonstrate control of all the domain names in a given certificate (Revoking Certificates - Let's Encrypt)