← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1886406 Certificate Problem Report

Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary

Hongkong Post CA identified a compliance issue with the policyQualifiers attribute in the Certificate Policies extension of TLS certificates, which did not align with the updated Baseline Requirements effective from September 15, 2023. The CA has committed to removing the non-compliant attribute and has already revoked 1,090 affected certificates, covering a significant portion of government services in Hong Kong. The CA is working closely with customers to facilitate the replacement of these certificates and has implemented new pre-issuance checks to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:23 UTC Confidence: 0.95
Chronology
  1. BR for TLS 2.0.0 became effective.
  2. Incident report submitted and 6 mis-issued certificates revoked.
  3. All affected certificates revoked.
  4. All action items finalized; request to close the bug.
Participants
Man Ho Martijn Katerbarg Amir Aamidi B. Wilson
External References
Similar Local Cases
#1887008 RESOLVED Certificate Problem Report Opened 2024-03-22 · Closed 2024-08-28 · 61% similar
Hongkong Post: TLS certificates with basicConstraints not marked as critical
#2032063 ASSIGNED Certificate Problem Report Opened 2026-04-15 Still Open · 60% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1804843 RESOLVED Certificate Problem Report Opened 2022-12-09 · Closed 2023-04-19 · 58% similar
Hongkong Post: Subject CN converted to Unicode representation incident
#1267332 RESOLVED Certificate Problem Report Opened 2016-04-25 · Closed 2022-11-14 · 57% similar
Hongkong Post e-Cert CA 1 - 10 issuing certificates without subject alternative name extension
#1886722 RESOLVED Certificate Problem Report Opened 2024-03-21 · Closed 2024-08-28 · 56% similar
Hongkong Post: Delayed response to CPR
#1945197 RESOLVED Certificate Problem Report Opened 2025-01-31 · Closed 2025-02-28 · 54% similar
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters
#1921598 RESOLVED Certificate Problem Report Opened 2024-09-28 · Closed 2025-02-19 · 52% similar
KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance
#1888104 RESOLVED Certificate Problem Report Opened 2024-03-27 · Closed 2024-07-11 · 52% similar
Disig: TLS certificate with basicConstraints not marked as critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action