← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1804843 Certificate Misissuance

Hongkong Post: Subject CN converted to Unicode representation incident

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post (HKPost CA) reported a self-discovered incident involving eight TLS server certificates that triggered zlint errors. The CA said it became aware of the problem after receiving an email report on 2022-12-07 that one of its issued TLS certificates had got a zlint error. HKPost identified that the subject CN contained the subscriber’s domain name in Chinese characters encoded as ISO/IEC 10646, but not encoded as P-Labels, and confirmed the issue as an incident in its CA system. The CA stopped approving certificate applications with Chinese domain names, developed and tested a fix, and began system changes in production; it also informed subscribers of the eight certificates and arranged for re-issuance. On 2022-12-13, HKPost stated that all concerned TLS certificates were revoked. The CA also described remediation to improve linting by implementing a pre-certificate linting enhancement that runs zlint before sending to CT logs, which it later said was implemented in production and that its linting process logs showed no new errors or exceptions.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.90 6 comments
Chronology
  1. HKPost received a report that a TLS certificate it issued triggered a zlint error and began investigating.
  2. HKPost confirmed the incident, developed a fix, and began production system changes while preparing re-issuance for affected subscribers.
  3. HKPost deployed the fix and started re-issuing the eight affected TLS certificates.
  4. HKPost revoked all concerned TLS certificates.
  5. HKPost implemented a pre-certificate zlint linting enhancement in production.
Thread Activity
  1. Certizen representative — Created the incident report describing how HKPost discovered the zlint error, identified the subject CN encoding issue, and outlined remediation steps including re-issuance and planned revocation.
  2. Certizen representative — Provided an update that all concerned TLS certificates were revoked and said a plan to improve linting would follow.
  3. Certizen representative — Explained that the issuance system lacked support for external linting like zlint and described an enhancement to run zlint on pre-certificates before CT logs.
  4. Certizen representative — Reported that the pre-certificate linting enhancement had been successfully tested and implemented to production.
  5. Mozilla representative — Stated an intention to close the bug on or about 19-Apr-2023 if no further comments or questions.
  6. Certizen representative — Reported that linting process logs for TLS certificates issued so far showed no new errors or exceptions.
Participants
Certizen representative Mozilla representative
Similar Local Cases
#1836694 RESOLVED Certificate Misissuance Policy Document Issue Opened 2023-06-05 · Closed 2023-09-29 · 95% similar
Hongkong Post: Invalid EV cert businessCategory
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 80% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1906470 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 71% similar
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 71% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 70% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1845269 RESOLVED Certificate Misissuance Incident Opened 2023-07-25 · Closed 2023-09-29 · 70% similar
NAVER Cloud Trust Services: commonName not in SAN
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 70% similar
Financijska agencija (Fina): Mis-issued certificates
#1888060 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 69% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action