← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1520299 Certificate Misissuance

Hongkong Post / Certizen: Failure to report misissuance

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary

Hongkong Post failed to report the misissuance of 18 certificates due to a lack of validation in their CA system, which allowed organization names longer than 64 characters. The issue was identified in July 2018, and while the certificates were revoked by August 2018, an incident report was not filed. The CA has since implemented measures to prevent future occurrences, including system fixes and enhanced auditing processes.

Model: gpt-4o-mini Generated: 2026-06-13 17:58 UTC Confidence: 0.90
Chronology
  1. CA became aware of the misissuance issue.
  2. All problematic certificates were confirmed revoked.
  3. Pre-issuance linting feature was successfully applied to the system.
Participants
Wayne Thayer Man Ho Ryan Sleevi
Similar Local Cases
#1551372 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 61% similar
Telia: "Some-State" in stateOrProvinceName
#1551369 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 60% similar
Kamu SM: "Some-State" in stateOrProvinceName
#1563574 RESOLVED Certificate Misissuance Opened 2019-07-04 · Closed 2023-02-22 · 59% similar
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
#1548714 RESOLVED Certificate Misissuance Opened 2019-05-02 · Closed 2023-02-22 · 59% similar
SECOM: "Default City" in Subject:localityName
#1524871 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 59% similar
Camerfirma: failure to revoke underscores
#1551363 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 59% similar
DigiCert: "Some-State" in stateOrProvinceName
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 59% similar
NetLock: CN not in SAN
#1481862 RESOLVED Certificate Misissuance Opened 2018-08-08 · Closed 2023-02-22 · 59% similar
Camerfirma: MULTICERT organizationName Too Long

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action