← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1520299
Certificate Misissuance
Hongkong Post / Certizen: Failure to report misissuance
RESOLVED
FIXED
Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary
Hongkong Post failed to report the misissuance of 18 certificates due to a lack of validation in their CA system, which allowed organization names longer than 64 characters. The issue was identified in July 2018, and while the certificates were revoked by August 2018, an incident report was not filed. The CA has since implemented measures to prevent future occurrences, including system fixes and enhanced auditing processes.
Chronology
- CA became aware of the misissuance issue.
- All problematic certificates were confirmed revoked.
- Pre-issuance linting feature was successfully applied to the system.
Participants
Wayne Thayer
Man Ho
Ryan Sleevi
External References
Similar Local Cases
Telia: "Some-State" in stateOrProvinceName
Kamu SM: "Some-State" in stateOrProvinceName
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
SECOM: "Default City" in Subject:localityName
Camerfirma: failure to revoke underscores
DigiCert: "Some-State" in stateOrProvinceName
NetLock: CN not in SAN
Camerfirma: MULTICERT organizationName Too Long