← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1886722 Delayed Revocation

Hongkong Post: Delayed response to a certificate problem report (CPR)

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post CA received a certificate problem report from d**********t@gmail.com but failed to respond in a complete and/or timely manner because the email was treated as junk. The CA stated this was a violation of CABF BR #4.9.3, which requires a continuous 24x7 ability to accept and respond to revocation requests and Certificate Problem Reports. The CA’s contact person acknowledged the Chrome Root Program email on 2024-03-18 and began examining the incident with the compliance team, which confirmed the issue and planned remediation. The CA submitted a case to update the certificate problem reporting mechanism by moving to a dedicated mailbox (c**********r@eCert.gov.hk) and stated compliance team members would directly monitor that address. In a final report, the CA described root cause as the CPR email being classified as junk and listed action items including dedicating the new reporting email address and training technical support staff to verify junk mail and monitor the mechanism. In response to Mozilla’s follow-up, the CA confirmed that junk-mail filters were functioning more effectively and that it rechecked for valid CPR instances in the last 6 months without finding any overlooked cases, and requested closure of the bug.

Model: gpt-5.4-nano Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.50 8 comments
Chronology
  1. An email reporting a certificate problem was received in Hongkong Post’s (obsoleted) certificate problem reporting address but was classified as junk.
  2. Chrome Root Program notified Hongkong Post of the delayed response issue; Hongkong Post acknowledged and started compliance review.
  3. Hongkong Post posted the bug describing the delayed response to the CPR.
  4. Hongkong Post initiated a CCADB update to change the certificate problem reporting email address to c**********r@eCert.gov.hk.
  5. Hongkong Post submitted a final report for the incident and remediation actions.
  6. Hongkong Post confirmed junk-mail filters improved and requested closure of the bug.
Thread Activity
  1. Certizen representative — Opened an incident report stating Hongkong Post failed to respond to a CPR in a complete and/or timely manner because the email was treated as junk, citing CABF BR #4.9.3 and describing the timeline and remediation action items.
  2. Community commenter — Asked about Hongkong Post’s email triage process and whether other legitimate CPRs may have been missed.
  3. Certizen representative — Explained that staff monitors emails during work hours, prioritizes based on urgency, and that they reviewed for other legitimate CPRs over the past 24 months without finding missed cases.
  4. Certizen representative — Reported submitting a CCADB update to change the CPR reporting mechanism to a dedicated mailbox (c**********r@eCert.gov.hk) monitored by the compliance team.
  5. Certizen representative — Submitted a final report reiterating the delayed CPR response, root cause (junk classification), and completed action items including the new dedicated email address and training/monitoring steps.
  6. Mozilla representative — Asked whether remediation items were working and whether junk-mail filters had been refined.
  7. Certizen representative — Confirmed junk-mail filters are functioning more effectively, rechecked for valid CPR instances in the last 6 months, found none overlooked, and requested closure.
  8. Mozilla representative — Indicated the bug would be closed the next day unless questions remained.
Participants
Certizen representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1886665 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2025-02-28 · 69% similar
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 61% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1886406 RESOLVED Ca Certificate Compliance Opened 2024-03-20 · Closed 2024-08-28 · 47% similar
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
#1885754 RESOLVED Delayed Revocation Opened 2024-03-16 · Closed 2024-09-13 · 42% similar
Entrust: CPR was not responded to in 24 hours
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 42% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
#1896553 RESOLVED Delayed Revocation Opened 2024-05-14 · Closed 2025-02-12 · 41% similar
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
#1888882 RESOLVED Delayed Revocation Opened 2024-04-01 · Closed 2025-03-27 · 41% similar
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)
#1905509 RESOLVED Delayed Revocation Opened 2024-06-29 · Closed 2025-05-08 · 40% similar
NETLOCK: CPR was not responded to in 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action