Let's Encrypt is revoking 3 million certs

If you use Let’s Encrypt ask your host to refresh your certificates. Let’s Encrypt found a bug that compromises the security of their system and starting tomorrow they’re revoking about 3 million certs that were created with the method that had the bug. Refreshing your certs will solve the problem. If your host knows for sure that you’re OK, that’s probably good enough. Their system is going to be overwhelmed with refresh requests so if you don’t need the refresh, don’t do it.

https://www.bbc.com/news/technology-51719588

What a wonderful way to start the day tomorrow. Thanks for the heads up Jay. Always appreciate your updates.

Thank you, Jay. I just renewed my certificates, just in case.

More detailed info for anyone who’s interested…

https://community.letsencrypt.org/t/…march-4/114864

And here’s a tool to see if your site is affected:

https://checkhost.unboundtest.com/

Hadn’t heard of this. Thanks for the info Jay.

They’ve decided not to revoke after all…

https://apple.news/AwMNueM8qM-20HpVzbrr2AQ

All Let’s Encrypt certs expire in 90 days anyway…

Thanks for the info Jay!