Hongkong Post: Subject CN converted to Unicode representation incident
Hongkong Post (HKPost CA) reported a self-discovered incident involving eight TLS server certificates that triggered zlint errors. The CA said it became aware of the problem after receiving an email report on 2022-12-07 that one of its issued TLS certificates had got a zlint error. HKPost identified that the subject CN contained the subscriber’s domain name in Chinese characters encoded as ISO/IEC 10646, but not encoded as P-Labels, and confirmed the issue as an incident in its CA system. The CA stopped approving certificate applications with Chinese domain names, developed and tested a fix, and began system changes in production; it also informed subscribers of the eight certificates and arranged for re-issuance. On 2022-12-13, HKPost stated that all concerned TLS certificates were revoked. The CA also described remediation to improve linting by implementing a pre-certificate linting enhancement that runs zlint before sending to CT logs, which it later said was implemented in production and that its linting process logs showed no new errors or exceptions.
- HKPost received a report that a TLS certificate it issued triggered a zlint error and began investigating.
- HKPost confirmed the incident, developed a fix, and began production system changes while preparing re-issuance for affected subscribers.
- HKPost deployed the fix and started re-issuing the eight affected TLS certificates.
- HKPost revoked all concerned TLS certificates.
- HKPost implemented a pre-certificate zlint linting enhancement in production.
- Certizen representative — Created the incident report describing how HKPost discovered the zlint error, identified the subject CN encoding issue, and outlined remediation steps including re-issuance and planned revocation.
- Certizen representative — Provided an update that all concerned TLS certificates were revoked and said a plan to improve linting would follow.
- Certizen representative — Explained that the issuance system lacked support for external linting like zlint and described an enhancement to run zlint on pre-certificates before CT logs.
- Certizen representative — Reported that the pre-certificate linting enhancement had been successfully tested and implemented to production.
- Mozilla representative — Stated an intention to close the bug on or about 19-Apr-2023 if no further comments or questions.
- Certizen representative — Reported that linting process logs for TLS certificates issued so far showed no new errors or exceptions.