← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1836694 Certificate Misissuance Policy Document Issue

Hongkong Post: Invalid EV cert businessCategory

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post identified a compliance issue regarding the issuance of an Extended Validation (EV) certificate to Tung Wah Group of Hospitals, which was incorrectly categorized as a 'Government Entity'. The CA discovered this issue through a Bugzilla report and initiated an investigation. They confirmed the misclassification and took steps to reissue the affected certificates with the correct business category of 'Private Organization'. Remediation actions included updating their Certificate Policy Statement (CPS) and halting the issuance of new EV certificates until the issue was resolved. The certificates were successfully reissued, and the CA has implemented measures to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.90 14 comments
Chronology
  1. Hongkong Post became aware of the misissuance issue through a Bugzilla report.
  2. Hongkong Post updated their CPS and began the process to reissue the affected EV certificates.
  3. Hongkong Post revoked the incorrectly issued EV certificate.
  4. Hongkong Post confirmed that the issue has been fully remediated.
Thread Activity
  1. Community commenter — Reported that HKPost issued an EV certificate with an incorrect businessCategory.
  2. Certizen representative — Acknowledged the issue and stated that an investigation was underway.
  3. Certizen representative — Confirmed the problem and initiated the incident reporting process.
  4. Certizen representative — Confirmed that the issue has been fully remediated and measures are in place to prevent recurrence.
Participants
Community commenter Certizen representative Sectigo Mozilla representative
External References
Similar Local Cases
#1804843 RESOLVED Certificate Misissuance Opened 2022-12-09 · Closed 2023-04-19 · 95% similar
Hongkong Post: Subject CN converted to Unicode representation incident
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 87% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1829746 RESOLVED Certificate Misissuance Opened 2023-04-24 · Closed 2023-06-02 · 79% similar
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed
#1888714 RESOLVED Certificate Misissuance Opened 2024-03-29 · Closed 2024-07-11 · 77% similar
Entrust: EV Certificate missing Issuer’s EV Policy OID
#1927384 RESOLVED Certificate Misissuance Opened 2024-10-28 · Closed 2025-01-29 · 77% similar
iTrusChina: Issuance of certificates using keys previously reported as compromised
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 77% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 77% similar
Certigna: TLS certificates with Basic constraint non-critical
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 76% similar
Sectigo: Subject field with unvalidated information included in certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action