Could Let's Encrypt ever get distrusted?

Hi @C0nw0nk,

Let's Encrypt tries hard to work with the root program operators to make sure that we're always complying with the rules related to certificate issuance.

It is always possible for any CA to misissue certificates, for example because of a software bug. Let's Encrypt had a minor incident of this sort back in 2015, involving six certificates:

Hopefully there are no other bugs in Let's Encrypt's infrastructure that will cause future misissuance events (and there are ongoing audits and testing projects that try to prevent this), but it's hard to be completely sure that it can never happen.

Many of the conflicts between root programs and CAs in the past involved root program complaints that CAs deliberately violated their own policies or failed to be transparent about problems (for example, trying to cover them up rather than acknowledging them). Let's Encrypt always aims to be extremely transparent and so this sort of conflict with root programs seems unlikely to me. If we make a mistake, we aim to acknowledge it publicly and work with the root programs as necessary to make sure it doesn't happen again.

1 Like