← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1887888 Delayed Revocation

Hongkong Post delayed revocation incident for TLS certificates with non-critical basicConstraints

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post CA reported a delayed revocation incident involving 46 TLS certificates issued with basicConstraints not marked as critical, referencing the related misissuance bug 1887008. The CA said 45 of the 46 affected certificates were not revoked within the required 5-day window because replacement certificates could not be coordinated quickly enough with affected subscribers, many of which were Hong Kong government bureaus, departments, and financial institutions. The CA also described a certificate issuance system bug that interfered with replacement issuance until a vendor patch was applied, and it later said it would not treat subscriber operational limitations as a reason to delay revocation in future cases. Over the course of the thread, Hongkong Post provided status updates, added action items for linting, system upgrades, customer education, and operational procedure changes, and eventually stated that all affected certificates had been revoked. The bug remained open for follow-up and closure summary discussion until Mozilla indicated it would close the incident after the final updates.

Model: gpt-5.4-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.97 38 comments
Chronology
  1. Hongkong Post became aware of the certificate problem and began examining it with its compliance team.
  2. Hongkong Post confirmed that 45 of 46 affected TLS certificates had not been revoked within 5 days.
  3. Hongkong Post stated that all affected certificates had been revoked.
  4. Hongkong Post posted a closure summary and asked for the incident to be closed.
Thread Activity
  1. Certizen representative — Hongkong Post filed a preliminary incident report describing 46 affected certificates and explaining that 45 were not revoked in time.
  2. Google representative — Ryan Dickson said the incident report had gone stale and did not meet CCADB incident-report expectations.
  3. Certizen representative — Hongkong Post explained the delay, said the issue was tied to its certificate issuance system, and outlined initial action items.
  4. Certizen representative — Hongkong Post said it was committed to the BR revocation timelines and revised its action items to include procedure updates and risk-management changes.
  5. Mozilla representative — Mozilla said it would close the incident on 2025-02-28 unless there were further questions or issues.
Participants
Certizen representative Google representative Mozilla representative Community commenter Apple representative Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1886665 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2025-02-28 · 100% similar
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 91% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 89% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 89% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 88% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 88% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 88% similar
Buypass: Delayed revocation of TLS certificates
#1886532 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2025-02-21 · 87% similar
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action