← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #2032063 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Ct Logging Issue

Hongkong Post incident report and closure request for invalid embedded SCT signatures

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Hongkong Post / Certizen reported a self-disclosed incident involving four OV TLS certificates that contained invalid embedded SCT signatures. The issue was first identified after a certificate problem report was received on 13 April 2026, and the CA said the affected certificates had been issued between 3 and 12 December 2025. The CA stated that its issuance software embedded Base64-encoded SCT data from the Let’s Encrypt Sycamore 2027h1 CT log directly into the certificate SCT extension instead of decoding it to binary, resulting in malformed SCT extensions and non-compliance with RFC 6962 and TLS BR Section 7.1.2.11.3. The CA revoked all four affected certificates by 22 April 2026 and removed the CT log from the issuance system as an immediate mitigation. It then deployed CT log linting, trained staff, worked with the software vendor on a fix, and completed patch testing and production deployment by 13 June 2026. On 28 June 2026, the CA submitted a closure summary requesting closure of the incident, and CCADB posted a final call for comments stating the bug would be closed around 2026-07-06 if no further questions were received. The bug is now resolved.

Model: gpt-5.4-mini Generated: 2026-06-14 05:17 UTC Revised: 2026-07-08 20:29 UTC Confidence: 0.98 13 comments
Chronology
  1. An update to the eligible CT log list was applied to the certificate issuance system for OV and EV certificate profiles.
  2. The first affected OV TLS certificate was issued with invalid embedded SCT signatures.
  3. The last affected OV TLS certificate was issued with invalid embedded SCT signatures.
  4. A certificate problem report was received about a certificate with an invalid embedded SCT signature.
  5. All four affected certificates had been revoked.
  6. The software patch was deployed to production and SCT signature validation testing across the updated CT log list was completed.
  7. The CA submitted a closure summary requesting closure of the incident.
Thread Activity
  1. Certizen representative — Submitted a preliminary incident report describing the invalid embedded SCT issue, the temporary CT log removal, re-issuance, and revocation of the original certificate.
  2. Certizen representative — Reported that three additional affected certificates were identified and that all affected certificates were revoked.
  3. Certizen representative — Provided a full incident report with the root cause, impact, and timeline.
  4. Certizen representative — Updated action items, including revocation completion, CT log linting training, and ongoing software/testing improvements.
  5. Certizen representative — Reported that the vendor had provided a patch and that the CA was testing it before production deployment.
  6. Certizen representative — Reported that the patch was deployed to production and that all action items were completed.
  7. Certizen representative — Stated that all action items had been completed and that a closure report would be submitted if no additional questions were received.
  8. Certizen representative — Submitted a report closure summary requesting closure of the incident.
  9. CCADB representative — Posted a final call for comments or questions and said the report would be closed on approximately 2026-07-06 if none were received.
Participants
Certizen representative CCADB representative
External References
Similar Local Cases
#2058503 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-28 · Closed 2026-09-02 · 82% similar
GlobalSign: SubCA created with incorrect CPS Policy OID
#2056223 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-20 · Closed 2026-08-08 · 82% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 82% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#2054098 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Remediation Tracking Opened 2026-07-10 · Closed 2026-09-02 · 81% similar
Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 81% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 81% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#2056668 RESOLVED Self Reported Incident Policy Document Issue Incident Opened By Ca Opened 2026-07-21 · Closed 2026-08-31 · 80% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#2052399 RESOLVED Incident Self Reported Incident Repository Issue Remediation Tracking Opened 2026-07-03 · Closed 2026-08-08 · 80% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action