← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1887008 Ca Certificate Compliance

Hongkong Post: TLS certificates with basicConstraints not marked as critical

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post identified a compliance issue where some TLS certificates were issued with the basicConstraints extension present but without the critical flag set, violating BR 7.1.2.7.6. This issue was discovered during an investigation related to another bug report. A total of 46 affected certificates were identified, primarily issued to government departments in Hong Kong SAR. The CA has halted issuance of new certificates and is collaborating with customers to replace the affected ones. All affected certificates have since been revoked, and the CA has implemented measures to prevent future occurrences, including upgrading their linting tools and certificate issuance system.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.90 17 comments
Chronology
  1. Hongkong Post notified of TLS certificates issued with basicConstraints extension but without the critical flag set.
  2. All affected certificates were revoked.
Thread Activity
  1. Certizen representative — Preliminary report on the compliance issue regarding basicConstraints extension.
  2. Certizen representative — All affected certificates were revoked.
  3. Certizen representative — Finalized all action items related to the incident and requested closure of the bug.
Participants
Certizen representative Mozilla representative
External References
Similar Local Cases
#1886406 RESOLVED Ca Certificate Compliance Opened 2024-03-20 · Closed 2024-08-28 · 100% similar
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 79% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1906470 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 75% similar
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
#1680378 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-12-02 · Closed 2023-02-22 · 73% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 72% similar
IdenTrust: Mis-Issued EV Certificates
#1749089 RESOLVED Ca Certificate Compliance Opened 2022-01-08 · Closed 2023-02-22 · 72% similar
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 72% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1879845 RESOLVED Ca Certificate Compliance Opened 2024-02-12 · Closed 2024-10-02 · 72% similar
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action