ANS Documentation

Improve This Doc
  • Cloud
  • Domains and DNS management
    • Domain Name Management
    • SafeDNS
    • SSL Certificates
      • Purchasing and Renewing
      • Generating A CSR (Certificate Sigining Request)
      • Validating your Certificate
      • ANS SSL Types
      • Self Signed Certificates
      • Using Server Name Indication (SNI)
      • Extended Validation Certificates
      • Generating a PFX file
      • Handling Private Keys
      • Let’s Encrypt
    • Reverse DNS Records
  • Backup and High Availability
  • eCommerce Stacks
  • Security
  • Email
  • Monitoring and usage management
  • Networking
  • Operating systems
  • Webcelerator
  • MyUKFast
  • Home >
  • Domains and DNS management >
  • SSL Certificates >
  • Let’s Encrypt >
  • Revocation of TLS-ALPN-01 Validated Certificates

Let’s Encrypt Revocation of TLS-ALPN-01 Validated Certificates¶

Overview¶

On 26th January 2022, Let’s Encrypt notified customers via email that on 28th January 2022 they will revoke any certificates issued in the last 90 days and validated by the TLS-ALPN-01 challenge. Irregularities were discovered in Let’s Encrypt’s implementation of the TLS-ALPN-01 challenge, and as such any certificates issued prior to 26th January using TLS-ALPN-01 are to be considered misissued.

This revocation only affects certificates issued and validated with the TLS-ALPN-01 challenge. Unless you receive an email regarding this from your ACME SSL provider/client then you do not need to take any action.

Warning

You are not impacted if using Certbot, ACME.sh, AutoSSL or SSLit!

Affected Software Information¶

Note

For a more comprehensive, non-exhaustive, list of affected software, please use the following Let’s Encrypt link.

  • https://community.letsencrypt.org/t/questions-about-renewing-before-tls-alpn-01-revocations/170449

Please note that UKFast are not responsible for external links, and the inclusion of any external URL should not be interpreted as an endorsement of that site, its content, or any product or service it may provide.

UKFast’s Response¶

UKFast encourage any client using this specific validation method, or any of the software listed in this comprehensive but non-exhaustive link to make appropriate amendments to their Let’s Encrypt validation configuration.

  • Let’s Encrypt Challenge Types

Next Article > Reverse DNS Records

  • Useful Links
  • SMB
  • Enterprise
  • Channel
  • Public Sector
  • ANS Data Centres
  • About ANS
  • Careers
  • Blog
  • Get in touch
  •  
  • Sales 0800 458 4545
  • Support 0800 230 0032
  • Get in touch

© ANS Group Limited | Terms and Conditions | Corporate Guidance | Sitemap
ANS Group Limited, registered in England and Wales, company registration number 03176761, registered office 1 Archway, Birley Fields, Manchester M15 5QJ