← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1836694 Certificate Misissuance

Hongkong Post: Invalid EV cert businessCategory

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary

The Hongkong Post issued an Extended Validation (EV) certificate to Tung Wah Group of Hospitals with an incorrect business category labeled as 'Government Entity'. This categorization was challenged as Tung Wah is a private organization established by legislation, not a government department. The CA acknowledged the misissuance and initiated a corrective process, including reissuing the certificates with the correct designation of 'Private Organization'. The issue has been fully remediated, and measures have been implemented to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 1.00
Chronology
  1. Bug reported regarding incorrect business category on EV certificate.
  2. CA identified the problem and began remediation.
  3. CA deployed changes to correct the business category.
  4. CA confirmed full remediation of the issue.
Participants
lee_yiu_chung@yahoo.com manho@certizen.com rob@sectigo.com bwilson@mozilla.com
Similar Local Cases
#1838371 RESOLVED Certificate Misissuance Opened 2023-06-14 · Closed 2024-01-19 · 55% similar
CFCA: certificate with an incorrect OrganizationName
#1927384 RESOLVED Certificate Misissuance Opened 2024-10-28 · Closed 2025-01-29 · 54% similar
iTrusChina: Issuance of certificates using keys previously reported as compromised
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 53% similar
IdenTrust: unintended creation of a Root CA certificate
#1520299 RESOLVED Certificate Misissuance Opened 2019-01-15 · Closed 2023-02-22 · 51% similar
Hongkong Post / Certizen: Failure to report misissuance
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 48% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1866448 RESOLVED Certificate Misissuance Opened 2023-11-24 · Closed 2024-02-14 · 48% similar
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 48% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 47% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action