← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1391864
Policy Compliance
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The case involves the issuance of non-Baseline Requirements (BR) compliant certificates by the Government of The Netherlands, PKIoverheid. Following reports of non-compliance, the CA was required to cease issuing problematic certificates and provide a remediation plan. The CA confirmed that 777 non-compliant certificates were issued and outlined steps for revocation and replacement. The situation was resolved with the CA implementing new measures to prevent future occurrences, although a few certificates related to the Dutch Immigration Office remain unrevoked due to operational concerns.
Chronology
- Non-compliant certificate reported on mozilla.dev.security.policy
- Mozilla notifies PKIoverheid about non-compliance
- PKIoverheid suspends certificate issuance
- All but 18 problematic certificates revoked
Participants
Kathleen Wilson
Mark Janssen
Ryan Sleevi
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
QuoVadis: Non-BR-Compliant Certificate Issuance
SECOM: Non-BR-Compliant Certificate Issuance
Izenpe: Non-BR-Compliant Certificate Issuance
GoDaddy: Non-BR-Compliant Certificate Issuance
Entrust: Non-BR-Compliant Certificate Issuance
PKIoverheid: Compliance issues CIBG TLS certificates
Kamu SM: Non-BR-Compliant Certificate Issuance