← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #2032063
Certificate Problem Report
Hongkong Post: Certificates with invalid embedded SCT signature
ASSIGNED
Government of Hong Kong (SAR), Hongkong Post, Certizen
AI Summary
Hongkong Post received a certificate problem report regarding certificates with invalid embedded Signed Certificate Timestamps (SCTs). An investigation revealed that the issue was caused by a CT log that was improperly processed during a recent update, leading to the issuance of certificates with malformed SCT extensions. Four certificates were affected, all of which have since been revoked. The CA has implemented corrective actions and is currently testing a software patch to prevent future occurrences.
Chronology
- CT log removed from issuance system
- Certificate problem report received
- All affected certificates revoked
- Patch deployment planned
Participants
Man Ho
External References
Similar Local Cases
Hongkong Post: Subject CN converted to Unicode representation incident
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
Hongkong Post: TLS certificates with basicConstraints not marked as critical
Hongkong Post: Delayed response to CPR
Hongkong Post e-Cert CA 1 - 10 issuing certificates without subject alternative name extension
Telekom Security: Wrong jurisdiction entries in certificates
Digicert: Government Entity listed instead of registration number
NAVER Cloud Trust Services: Encoding non-conformity in SCT extensions