← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #1887888 Delayed Revocation

Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary

Hongkong Post CA issued 46 TLS certificates that did not have the basicConstraints marked as critical. Due to the manual management of these certificates by subscribers and a delay in a system vendor patch, 45 of these certificates were not revoked within the required 5-day period. This delay posed significant risks to critical e-services provided by government and financial institutions in Hong Kong. Hongkong Post has since committed to improving its processes to ensure timely revocation in the future, including upgrading linting tools and enhancing subscriber education on revocation requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Confidence: 0.90
Chronology
  1. Became aware of the error and began examination.
  2. Implemented a system patch to reject non-compliant certificate requests.
  3. Confirmed that all affected certificates were revoked.
  4. Closure summary provided and incident report completed.
Participants
Man Ho Ryan Dickson Mike Shaver Clint Wilson Tim Callan B. Wilson
Similar Local Cases
#1886665 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2025-02-28 · 78% similar
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
#1877388 RESOLVED Delayed Revocation Opened 2024-01-30 · Closed 2025-03-14 · 59% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 58% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1887110 RESOLVED Delayed Revocation Opened 2024-03-22 · Closed 2025-02-14 · 57% similar
Microsec: Delayed revocation of the misissued certificates
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 53% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 53% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1888882 RESOLVED Delayed Revocation Opened 2024-04-01 · Closed 2025-03-27 · 52% similar
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 50% similar
Buypass: Delayed revocation of TLS certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action