Hongkong Post incident report and closure request for invalid embedded SCT signatures
Hongkong Post / Certizen reported a self-disclosed incident involving four OV TLS certificates that contained invalid embedded SCT signatures. The issue was first identified after a certificate problem report was received on 13 April 2026, and the CA said the affected certificates had been issued between 3 and 12 December 2025. The CA stated that its issuance software embedded Base64-encoded SCT data from the Let’s Encrypt Sycamore 2027h1 CT log directly into the certificate SCT extension instead of decoding it to binary, resulting in malformed SCT extensions and non-compliance with RFC 6962 and TLS BR Section 7.1.2.11.3. The CA revoked all four affected certificates by 22 April 2026 and removed the CT log from the issuance system as an immediate mitigation. It then deployed CT log linting, trained staff, worked with the software vendor on a fix, and completed patch testing and production deployment by 13 June 2026. On 28 June 2026, the CA submitted a closure summary requesting closure of the incident, and CCADB posted a final call for comments stating the bug would be closed around 2026-07-06 if no further questions were received. The bug is now resolved.
- An update to the eligible CT log list was applied to the certificate issuance system for OV and EV certificate profiles.
- The first affected OV TLS certificate was issued with invalid embedded SCT signatures.
- The last affected OV TLS certificate was issued with invalid embedded SCT signatures.
- A certificate problem report was received about a certificate with an invalid embedded SCT signature.
- All four affected certificates had been revoked.
- The software patch was deployed to production and SCT signature validation testing across the updated CT log list was completed.
- The CA submitted a closure summary requesting closure of the incident.
- Certizen representative — Submitted a preliminary incident report describing the invalid embedded SCT issue, the temporary CT log removal, re-issuance, and revocation of the original certificate.
- Certizen representative — Reported that three additional affected certificates were identified and that all affected certificates were revoked.
- Certizen representative — Provided a full incident report with the root cause, impact, and timeline.
- Certizen representative — Updated action items, including revocation completion, CT log linting training, and ongoing software/testing improvements.
- Certizen representative — Reported that the vendor had provided a patch and that the CA was testing it before production deployment.
- Certizen representative — Reported that the patch was deployed to production and that all action items were completed.
- Certizen representative — Stated that all action items had been completed and that a closure report would be submitted if no additional questions were received.
- Certizen representative — Submitted a report closure summary requesting closure of the incident.
- CCADB representative — Posted a final call for comments or questions and said the report would be closed on approximately 2026-07-06 if none were received.