← Government of Hong Kong (SAR), Hongkong Post, Certizen cases
Bugzilla #408949 Ca Certificate Root Program

Hongkong Post Root CA 1 inclusion request for SSL trust

RESOLVED FIXED Government of Hong Kong (SAR), Hongkong Post, Certizen
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is Hongkong Post’s request to add the Hongkong Post Root CA 1 certificate to Mozilla’s trusted root store with SSL trust enabled. The request was opened by Stephen Choy of Hongkong Post in December 2007 and later accepted by Mozilla for review. During information gathering, Mozilla asked about the certificate hierarchy, outsourcing, and CRL behavior; Hongkong Post clarified that the root and its subordinate CA services were operated by E-Mice Solutions and that the request was for SSL trust only. Mozilla initially held the request pending CRL-related concerns, including that the full CRL was not discoverable via CRLDP and that the CRL nextUpdate period was one month. Hongkong Post later said it would change the server certificate CRLDP to the full CRL and set nextUpdate to 10 days, and Mozilla confirmed those action items were completed. Mozilla then filed bug 541499 against NSS for the actual inclusion changes, and the bug was marked RESOLVED FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 12:05 UTC Revised: 2026-06-16 17:21 UTC Confidence: 0.96 86 comments
Chronology
  1. Hongkong Post requested inclusion of Hongkong Post Root CA 1 with SSL trust enabled.
  2. Mozilla completed its assessment and recommended approval for SSL use only.
  3. Mozilla confirmed the CRL-related action items were completed and filed the NSS implementation bug 541499.
Thread Activity
  1. Hkpo representative — Hongkong Post opened the request to include Hongkong Post Root CA 1 and enable SSL trust.
  2. Mozilla representative — Mozilla began information gathering on the root, hierarchy, outsourcing, and testing details.
  3. Hkpo representative — Hongkong Post clarified the hierarchy, said E-Mice operated the services, and stated the email trust bit was intended if policy allowed.
  4. Hkpo representative — Hongkong Post asked Mozilla to proceed with enabling the SSL trust bit only.
  5. Mozilla representative — Mozilla said the request was ready for public discussion but noted the CRL issue and asked whether the critical CRLDP flag could be removed.
  6. Mozilla representative — Mozilla summarized the assessment and recommended approval for Hongkong Post Root CA 1 with websites trust only.
  7. Hecker representative — Mozilla approved the request subject to the caveat that the full CRL must be discoverable via CRLDP before future CRLDP support.
  8. Mozilla representative — Mozilla confirmed both CRL-related action items were completed and said it would create the NSS bug for inclusion.
  9. Mozilla representative — Bug 541499 was filed against NSS for the actual changes.
Participants
Hkpo representative Community commenter E-mice representative Mozilla representative Hecker representative Bolyard representative Startcom representative Rossde representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#373537 RESOLVED Ca Certificate Root Program Opened 2007-03-11 · Closed 2022-11-14 · 100% similar
Hongkong Post root cert inclusion
#1464306 RESOLVED Ca Certificate Root Program Opened 2018-05-25 · Closed 2022-11-14 · 89% similar
Add Hongkong Post renewal root certificate "Hongkong Post Root CA 3"
#520557 RESOLVED Ca Certificate Root Program Opened 2009-10-05 · Closed 2022-11-14 · 88% similar
Add Actalis Authentication Root CA certificate
#455878 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-09-18 · Closed 2022-11-14 · 87% similar
Add CA Disig root certificate into browser
#343756 RESOLVED Ca Certificate Root Program Opened 2006-07-06 · Closed 2022-11-14 · 86% similar
Request to add SwissSign root CA certificate
#359069 RESOLVED Ca Certificate Root Program Opened 2006-11-01 · Closed 2022-11-14 · 86% similar
Request to add two additional IdenTrust root CA certificates
#370627 RESOLVED Ca Certificate Root Program Opened 2007-02-16 · Closed 2022-11-14 · 86% similar
Add S-TRUST root certificates
#378882 RESOLVED Ca Certificate Root Program Opened 2007-04-26 · Closed 2022-11-14 · 86% similar
Add Deutsche Telekom CA cert for T-system Trust Center

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action