Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
This case concerns certificates issued by Staat der Nederlandend / PKIoverheid (PKIoverheid) that were reported as non-compliant with CA/Browser Forum Baseline Requirements, specifically BR Ballot 164 regarding sequential-looking serial numbers. The incident was raised on mozilla.dev.security.policy on 19 July 2017, and Mozilla notified the Policy Authority (PA) PKIoverheid on 20 July 2017. PKIoverheid initiated an internal incident, had DDY (its CA) postpone further issuing on 21 July 2017, and later restarted issuing compliant certificates on 24 July 2017. The thread states that a total of 777 non-compliant certificates were issued from 30 September 2016 up to 21 July 2017, and that DDY would revoke and replace them on or before 31 August 2017. Mozilla granted an extension to the 24-hour revocation time on 27 July 2017, and the bug was marked Resolved with an expectation of continued updates on the proposed timelines. As of 1 September 2017, Mark Janssen reported that all 777 certificates had been logged to crt.sh, and that all were revoked except 18 *.ind.nl certificates, with remaining non-revoked certificates described as related to the Dutch Immigration Office and stated to be difficult to revoke without severe disturbance; he expected the last few certificates to be replaced and revoked the following week.
- A non-compliant certificate issuance issue was posted on mozilla.dev.security.policy.
- Mozilla notified the Policy Authority (PA) PKIoverheid about non-compliant certificates from DDY.
- PKIoverheid began investigating and DDY postponed further certificate issuance.
- DDY delivered an action plan and PKIoverheid requested restarting issuance of compliant certificates.
- DDY installed a first production certificate and began revoking and replacing certificates.
- Mozilla granted PKIoverheid an extension to the 24-hour revocation time.
- PKIoverheid reported logging and revocation status for the 777 non-compliant certificates.
- Community commenter — Filed the bug requesting PKIoverheid respond with details about awareness, cessation of problematic issuance, certificate lists, remediation steps, and justification regarding revocation timing.
- Logius representative — Provided a detailed incident timeline, stated DDY stopped issuing, reported 777 non-compliant certificates, explained the cause, and described remediation and an extension request/grant for revocation timing.
- Community commenter — Marked the bug Resolved, stating the responses demonstrate holistic awareness and that continued updates were expected on the proposed timelines.
- Logius representative — Attached an Excel file listing the affected certificates (crt.sh IDs).
- Logius representative — Reported that all 777 certificates were logged, that all were revoked except 18 *.ind.nl certificates, and that remaining non-revoked certificates related to the Dutch Immigration Office were expected to be replaced and revoked the next week.