Revoking certain certificates on March 4

Could you tell me please how to renew the certificate within ISPCOnfig? I tried to remove SSL and Letscencrípt and add it again, but the tool says the certification still need to be renewed!

Ok this is complete crap. Fine, there was a bug. I have less than 12 hours to fix this and right now I am 2500 miles from home on vacation, and all I have with me is a cell phone and a bad 3rd world internet connection. It was a complete fluke that the notification email even got to me before this weekend, as I am in Waikiki on a ship that pulls out in a few hours.

I deliberately manually updated certs to avoid this problem while I was gone, and because you guys are giving us literally no time to fix it before you revoke them you are not only screwing up my vacation I don’t even know if I can maintain a connection long enough to get this done. Nor do I know for certain that the one other person with access is available to talk to before you revoke.


In addition to this rate limit override, we just deployed another global rate limit override from 300/3h to 10000/3h for newOrdersPerAccount.


I would be great if you could mention this in your blog. When I got the mail it looked like some phishing attempt, especially because the Let’s Encrypt homepage doesn’t mention this at all.


Is LE going to publish their after-incident summary publicly?

I’m excited to hear if there will be any lessons learned for your processes :slight_smile:


We will definitely be conducting an internal post-mortem and will likely share some of it publicly. We have provided an initial Incident Report with more details including some remediation items. here


I had a DNS issue (my secondaries weren’t getting NOTIFY) so I’m getting too many failed authorization requests.

How long till that goes away?

(I fixed the notify issue, and validated that it works with your staging server).

Then they should have sent out the notice 5 days ago, not waited and then give us 12 hours to fix. 4 days ago I was still at home, not on vacation in the middle of the ocean

Unfortunately, we have no way to know whether prior certs are still in use after they’ve been renewed. Renewal does not invalidate the old certificate, and some subscribers may use different certificates simultaneously on different endpoints for the same hostname (e.g. CDNs).


I just created a bash script to review if your domains are affected:



while IFS= read -r line
echo “Domain to check -> $DOMAIN”
OUTPUT=curl -XPOST -d "fqdn=$DOMAIN" | grep "because it is affected by" | wc -l
#curl -XPOST -d “fqdn=$DOMAIN” | grep “because it is affected by” | wc -l
if [[ $OUTPUT -eq 1 ]]; then
echo “$DOMAIN should be replaced”
echo “$line” >> domains_to_renew
echo $OUTPUT
echo “$DOMAIN not affected”
done < “$input”

Hope it can help someone.


Thanks @kimbo89 – I’ll give this a try !


Ok, apparently I’ve waited long enough and the new cert got issued.


We are working on increasing that rate limit now. Thank you for your patience.


maybe someone will find it obvious, but please DON’T RENEW all your certificates with “certbot renew --force-renewal” but only the affected ones, with “certbot certonly --force-renewal -d”!


We have also increased the Invalid Authorizations Per Account rate limit from 5 to 10.


