← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1886665 Delayed Revocation

Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary

Hongkong Post CA faced a significant incident involving the delayed revocation of 1,176 TLS certificates due to a problem with the Certificate Policies extension. Although the CA aimed to revoke these certificates within 5 days of identifying the issue, 1,170 certificates remained unrevoked in time, raising concerns about the continuity of critical e-services for the government of Hong Kong. The delay was attributed to the manual management of certificates by subscribers and the complexities of coordinating replacements. The CA has since implemented action items to streamline the revocation process and ensure compliance with industry standards.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Confidence: 0.95
Chronology
  1. Original problem report received.
  2. Revocation deadline extended to ensure completion of certificate replacements.
  3. Educational materials regarding revocation requirements distributed to all customers.
  4. Closure summary prepared and incident report finalized.
Participants
Man Ho Ryan Dickson Amir Aamidi Tim Callan Ben Wilson
Similar Local Cases
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 78% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 61% similar
Buypass: Delayed revocation of TLS certificates
#1877388 RESOLVED Delayed Revocation Opened 2024-01-30 · Closed 2025-03-14 · 60% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1887110 RESOLVED Delayed Revocation Opened 2024-03-22 · Closed 2025-02-14 · 55% similar
Microsec: Delayed revocation of the misissued certificates
#1825734 RESOLVED Delayed Revocation Opened 2023-03-31 · Closed 2023-06-01 · 50% similar
Asseco DS / Certum: Delayed revocation of SHECA cross certificate
#1896053 RESOLVED Delayed Revocation Opened 2024-05-10 · Closed 2025-07-16 · 49% similar
Digicert: Delayed Revocation for bug 1894560
#1707229 RESOLVED Delayed Revocation Opened 2021-04-23 · Closed 2023-02-22 · 49% similar
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 49% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action