Hongkong Post: Delayed response to a certificate problem report (CPR)
Hongkong Post CA received a certificate problem report from d**********t@gmail.com but failed to respond in a complete and/or timely manner because the email was treated as junk. The CA stated this was a violation of CABF BR #4.9.3, which requires a continuous 24x7 ability to accept and respond to revocation requests and Certificate Problem Reports. The CA’s contact person acknowledged the Chrome Root Program email on 2024-03-18 and began examining the incident with the compliance team, which confirmed the issue and planned remediation. The CA submitted a case to update the certificate problem reporting mechanism by moving to a dedicated mailbox (c**********r@eCert.gov.hk) and stated compliance team members would directly monitor that address. In a final report, the CA described root cause as the CPR email being classified as junk and listed action items including dedicating the new reporting email address and training technical support staff to verify junk mail and monitor the mechanism. In response to Mozilla’s follow-up, the CA confirmed that junk-mail filters were functioning more effectively and that it rechecked for valid CPR instances in the last 6 months without finding any overlooked cases, and requested closure of the bug.
- An email reporting a certificate problem was received in Hongkong Post’s (obsoleted) certificate problem reporting address but was classified as junk.
- Chrome Root Program notified Hongkong Post of the delayed response issue; Hongkong Post acknowledged and started compliance review.
- Hongkong Post posted the bug describing the delayed response to the CPR.
- Hongkong Post initiated a CCADB update to change the certificate problem reporting email address to c**********r@eCert.gov.hk.
- Hongkong Post submitted a final report for the incident and remediation actions.
- Hongkong Post confirmed junk-mail filters improved and requested closure of the bug.
- Certizen representative — Opened an incident report stating Hongkong Post failed to respond to a CPR in a complete and/or timely manner because the email was treated as junk, citing CABF BR #4.9.3 and describing the timeline and remediation action items.
- Community commenter — Asked about Hongkong Post’s email triage process and whether other legitimate CPRs may have been missed.
- Certizen representative — Explained that staff monitors emails during work hours, prioritizes based on urgency, and that they reviewed for other legitimate CPRs over the past 24 months without finding missed cases.
- Certizen representative — Reported submitting a CCADB update to change the CPR reporting mechanism to a dedicated mailbox (c**********r@eCert.gov.hk) monitored by the compliance team.
- Certizen representative — Submitted a final report reiterating the delayed CPR response, root cause (junk classification), and completed action items including the new dedicated email address and training/monitoring steps.
- Mozilla representative — Asked whether remediation items were working and whether junk-mail filters had been refined.
- Certizen representative — Confirmed junk-mail filters are functioning more effectively, rechecked for valid CPR instances in the last 6 months, found none overlooked, and requested closure.
- Mozilla representative — Indicated the bug would be closed the next day unless questions remained.