← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1267332 Self Reported Incident

Hongkong Post e-Cert CA 1 - 10 issuing certificates without subject alternative name extension

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The Hongkong Post e-Cert CA 1 - 10 was found to be issuing certificates that lacked the required subject alternative name (SAN) extension. This issue was identified by Mozilla's Dana Keeler, who noted that the CA had issued several such certificates, including one as recently as July 2016. In response, the CA confirmed that it had ceased issuing SSL certificates from this subCA as of January 1, 2016, and transitioned to a new BR-compliant subCA. The CA has since taken steps to ensure compliance with the Baseline Requirements. The issue was ultimately resolved by adding the problematic certificates to OneCRL.

Model: gpt-4o-mini Generated: 2026-06-13 14:03 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.85 12 comments
Chronology
  1. Discovery of non-compliant certificates issued by Hongkong Post e-Cert CA 1 - 10.
  2. Certificates from Hongkong Post e-Cert CA 1 - 10 added to OneCRL.
Thread Activity
  1. Mozilla representative — Hongkong Post e-Cert CA 1 - 10 has been issuing certificates that do not have a subject alternative name extension.
  2. Certizen representative — "Hongkong Post e-Cert CA 1 - 10" is an old SHA-1 subCA which had been stopped issuing SSL certificates since 1 January 2016.
  3. Mozilla representative — This was issued from "Hongkong Post e-Cert CA 1 - 10" in July, so there still appears to be an issue here.
  4. Mozilla representative — This is in direct violation of the CA/Browser Forum's Baseline requirements.
  5. Mozilla representative — Closing this bug as resolved/fixed, because the 'Hongkong Post e-Cert CA 1 - 10' certificates were added to OneCRL.
Participants
Mozilla representative Certizen representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1520299 RESOLVED Self Reported Incident Opened 2019-01-15 · Closed 2023-02-22 · 80% similar
Hongkong Post / Certizen: Failure to report misissuance
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 77% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 75% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1390998 RESOLVED Self Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
Kamu SM: Non-BR-Compliant Certificate Issuance
#1390979 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
certSIGN: Non-BR-Compliant Certificate Issuance
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 70% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1391064 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-08-16 · Closed 2023-02-22 · 69% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1398259 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-09-08 · Closed 2023-02-22 · 69% similar
SECOM: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action