Hongkong Post e-Cert CA 1 - 10 issuing certificates without subject alternative name extension
The Hongkong Post e-Cert CA 1 - 10 was found to be issuing certificates that lacked the required subject alternative name (SAN) extension. This issue was identified by Mozilla's Dana Keeler, who noted that the CA had issued several such certificates, including one as recently as July 2016. In response, the CA confirmed that it had ceased issuing SSL certificates from this subCA as of January 1, 2016, and transitioned to a new BR-compliant subCA. The CA has since taken steps to ensure compliance with the Baseline Requirements. The issue was ultimately resolved by adding the problematic certificates to OneCRL.
- Discovery of non-compliant certificates issued by Hongkong Post e-Cert CA 1 - 10.
- Certificates from Hongkong Post e-Cert CA 1 - 10 added to OneCRL.
- Mozilla representative — Hongkong Post e-Cert CA 1 - 10 has been issuing certificates that do not have a subject alternative name extension.
- Certizen representative — "Hongkong Post e-Cert CA 1 - 10" is an old SHA-1 subCA which had been stopped issuing SSL certificates since 1 January 2016.
- Mozilla representative — This was issued from "Hongkong Post e-Cert CA 1 - 10" in July, so there still appears to be an issue here.
- Mozilla representative — This is in direct violation of the CA/Browser Forum's Baseline requirements.
- Mozilla representative — Closing this bug as resolved/fixed, because the 'Hongkong Post e-Cert CA 1 - 10' certificates were added to OneCRL.