Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
Hongkong Post CA reported a compliance issue regarding the policyQualifiers attribute in the Certificate Policies extension of TLS certificates, which did not align with the updated Baseline Requirements effective from September 15, 2023. The CA acknowledged the oversight and committed to removing the non-compliant attribute from non-EV TLS certificates while ensuring compliance for EV TLS certificates. A total of 1,176 affected certificates were identified, primarily issued to government entities in Hong Kong. The CA has revoked 1,090 of these certificates and implemented new pre-issuance linting tools to prevent future occurrences. The case is now resolved with all action items completed.
- All affected certificates were revoked.
- Certizen representative — Created an incident report regarding the compliance issue with the Certificate Policies extension.
- Certizen representative — Resumed issuance of TLS certificates after patching the system.
- Certizen representative — Confirmed that all affected certificates have been revoked.
- Certizen representative — Requested closure of the bug as all action items have been finalized.