← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1886406 Ca Certificate Compliance

Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post CA reported a compliance issue regarding the policyQualifiers attribute in the Certificate Policies extension of TLS certificates, which did not align with the updated Baseline Requirements effective from September 15, 2023. The CA acknowledged the oversight and committed to removing the non-compliant attribute from non-EV TLS certificates while ensuring compliance for EV TLS certificates. A total of 1,176 affected certificates were identified, primarily issued to government entities in Hong Kong. The CA has revoked 1,090 of these certificates and implemented new pre-issuance linting tools to prevent future occurrences. The case is now resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.85 19 comments
Chronology
  1. All affected certificates were revoked.
Thread Activity
  1. Certizen representative — Created an incident report regarding the compliance issue with the Certificate Policies extension.
  2. Certizen representative — Resumed issuance of TLS certificates after patching the system.
  3. Certizen representative — Confirmed that all affected certificates have been revoked.
  4. Certizen representative — Requested closure of the bug as all action items have been finalized.
Participants
Certizen representative Sectigo Community commenter Mozilla representative
External References
Similar Local Cases
#1887008 RESOLVED Ca Certificate Compliance Opened 2024-03-22 · Closed 2024-08-28 · 100% similar
Hongkong Post: TLS certificates with basicConstraints not marked as critical
#1871113 RESOLVED Ca Certificate Compliance Opened 2023-12-20 · Closed 2024-05-15 · 81% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 80% similar
Certigna: TLS certificates with Basic constraint non-critical
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 79% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 77% similar
Financijska agencija (Fina): Mis-issued certificates
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 77% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1724458 RESOLVED Ca Certificate Compliance Opened 2021-08-06 · Closed 2023-02-22 · 76% similar
Sectigo: Mojibake in certificate Subject fields
#1839305 RESOLVED Ca Certificate Compliance Opened 2023-06-20 · Closed 2024-06-30 · 76% similar
Buypass: Domain validation method using externally operated DNS tools

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action