← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #2032063 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Ct Logging Issue

Hongkong Post incident report and closure request for invalid embedded SCT signatures

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post / Certizen reported a self-disclosed incident involving four OV TLS certificates that contained invalid embedded SCT signatures. The issue was first identified after a certificate problem report was received on 13 April 2026, and the CA said the affected certificates had been issued between 3 and 12 December 2025. The CA stated that its issuance software embedded Base64-encoded SCT data from the Let’s Encrypt Sycamore 2027h1 CT log directly into the certificate SCT extension instead of decoding it to binary, resulting in malformed SCT extensions and non-compliance with RFC 6962 and TLS BR Section 7.1.2.11.3. The CA revoked all four affected certificates by 22 April 2026 and removed the CT log from the issuance system as an immediate mitigation. It then deployed CT log linting, trained staff, worked with the software vendor on a fix, and completed patch testing and production deployment by 13 June 2026. On 28 June 2026, the CA submitted a closure summary requesting closure of the incident, and CCADB posted a final call for comments stating the bug would be closed around 2026-07-06 if no further questions were received. The bug is now resolved.

Model: gpt-5.4-mini Generated: 2026-06-14 05:17 UTC Revised: 2026-07-08 20:29 UTC Confidence: 0.98 13 comments
Chronology
  1. An update to the eligible CT log list was applied to the certificate issuance system for OV and EV certificate profiles.
  2. The first affected OV TLS certificate was issued with invalid embedded SCT signatures.
  3. The last affected OV TLS certificate was issued with invalid embedded SCT signatures.
  4. A certificate problem report was received about a certificate with an invalid embedded SCT signature.
  5. All four affected certificates had been revoked.
  6. The software patch was deployed to production and SCT signature validation testing across the updated CT log list was completed.
  7. The CA submitted a closure summary requesting closure of the incident.
Thread Activity
  1. Certizen representative — Submitted a preliminary incident report describing the invalid embedded SCT issue, the temporary CT log removal, re-issuance, and revocation of the original certificate.
  2. Certizen representative — Reported that three additional affected certificates were identified and that all affected certificates were revoked.
  3. Certizen representative — Provided a full incident report with the root cause, impact, and timeline.
  4. Certizen representative — Updated action items, including revocation completion, CT log linting training, and ongoing software/testing improvements.
  5. Certizen representative — Reported that the vendor had provided a patch and that the CA was testing it before production deployment.
  6. Certizen representative — Reported that the patch was deployed to production and that all action items were completed.
  7. Certizen representative — Stated that all action items had been completed and that a closure report would be submitted if no additional questions were received.
  8. Certizen representative — Submitted a report closure summary requesting closure of the incident.
  9. CCADB representative — Posted a final call for comments or questions and said the report would be closed on approximately 2026-07-06 if none were received.
Participants
Certizen representative CCADB representative
External References
Similar Local Cases
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 82% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 81% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 81% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 80% similar
Microsoft PKI Services: OCSP Non-Compliance
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 80% similar
Netlock: unspecifed revocation code (0) in CRL
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 80% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-06-29 · 80% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#1804843 RESOLVED Certificate Misissuance Opened 2022-12-09 · Closed 2023-04-19 · 80% similar
Hongkong Post: Subject CN converted to Unicode representation incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action