Let's Encrypt TLS-ALPN issue

Bottom line: You’re probably going to hear about Let’s Encrypt revoking a bunch of certificates again. Unless you get a direct email from them, it almost certainly doesn’t apply to you.

Just to hopefully get ahead of the curve… Let’s Encrypt has discovered a bug in the TLS-ALPN validation process as it was implemented before 26 January 2022, and will shortly begin revoking certificates issued using that method before that time:

This should not affect any stock Nethserver installation–by default, Nethserver uses the HTTP-01 challenge. And the guides I’ve written use DNS validation, and also won’t be affected by this.

7 Likes