← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1391864 Delayed Revocation

Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns certificates issued by Staat der Nederlandend / PKIoverheid (PKIoverheid) that were reported as non-compliant with CA/Browser Forum Baseline Requirements, specifically BR Ballot 164 regarding sequential-looking serial numbers. The incident was raised on mozilla.dev.security.policy on 19 July 2017, and Mozilla notified the Policy Authority (PA) PKIoverheid on 20 July 2017. PKIoverheid initiated an internal incident, had DDY (its CA) postpone further issuing on 21 July 2017, and later restarted issuing compliant certificates on 24 July 2017. The thread states that a total of 777 non-compliant certificates were issued from 30 September 2016 up to 21 July 2017, and that DDY would revoke and replace them on or before 31 August 2017. Mozilla granted an extension to the 24-hour revocation time on 27 July 2017, and the bug was marked Resolved with an expectation of continued updates on the proposed timelines. As of 1 September 2017, Mark Janssen reported that all 777 certificates had been logged to crt.sh, and that all were revoked except 18 *.ind.nl certificates, with remaining non-revoked certificates described as related to the Dutch Immigration Office and stated to be difficult to revoke without severe disturbance; he expected the last few certificates to be replaced and revoked the following week.

Model: gpt-5.4-nano Generated: 2026-06-13 17:07 UTC Revised: 2026-06-16 19:07 UTC Confidence: 0.86 5 comments
Chronology
  1. A non-compliant certificate issuance issue was posted on mozilla.dev.security.policy.
  2. Mozilla notified the Policy Authority (PA) PKIoverheid about non-compliant certificates from DDY.
  3. PKIoverheid began investigating and DDY postponed further certificate issuance.
  4. DDY delivered an action plan and PKIoverheid requested restarting issuance of compliant certificates.
  5. DDY installed a first production certificate and began revoking and replacing certificates.
  6. Mozilla granted PKIoverheid an extension to the 24-hour revocation time.
  7. PKIoverheid reported logging and revocation status for the 777 non-compliant certificates.
Thread Activity
  1. Community commenter — Filed the bug requesting PKIoverheid respond with details about awareness, cessation of problematic issuance, certificate lists, remediation steps, and justification regarding revocation timing.
  2. Logius representative — Provided a detailed incident timeline, stated DDY stopped issuing, reported 777 non-compliant certificates, explained the cause, and described remediation and an extension request/grant for revocation timing.
  3. Community commenter — Marked the bug Resolved, stating the responses demonstrate holistic awareness and that continued updates were expected on the proposed timelines.
  4. Logius representative — Attached an Excel file listing the affected certificates (crt.sh IDs).
  5. Logius representative — Reported that all 777 certificates were logged, that all were revoked except 18 *.ind.nl certificates, and that remaining non-revoked certificates related to the Dutch Immigration Office were expected to be replaced and revoked the next week.
Participants
Community commenter
Similar Local Cases
#1652922 RESOLVED Delayed Revocation Opened 2020-07-15 · Closed 2023-02-22 · 80% similar
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
#1652604 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 79% similar
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
#1651481 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 68% similar
Entrust: Late Revocation due to SHA-256 hash algorithm
#1742195 RESOLVED Delayed Revocation Opened 2021-11-20 · Closed 2023-02-22 · 67% similar
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days
#1655698 RESOLVED Delayed Revocation Opened 2020-07-28 · Closed 2023-02-22 · 66% similar
Telekom Security: CRL also contained unrevoked certificates
#1748634 RESOLVED Ca Certificate Compliance Delayed Revocation Remediation Tracking Opened 2022-01-05 · Closed 2023-02-22 · 66% similar
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
#1652610 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 65% similar
SECOM: Delayed Revocation of CA Certificate with OCSP EKU Issue
#1516561 RESOLVED Delayed Revocation Opened 2018-12-27 · Closed 2023-02-22 · 63% similar
DigiCert: Underscores - Canadian Imperial Bank of Commerce

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action