← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1398251 Self Reported Incident

Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case records an incident involving OCSP responders for Staat der Nederlandend / PKIoverheid (PKIoverheid TSPs). The issue was that, per BR section 4.9.10 effective 2013-08-01, OCSP responders must not respond with a “good” status for unissued certificates. Kathleen Wilson opened the bug to record the CA’s incident report after problems with the CA’s OCSP responders were discussed in the mozilla.dev.security.policy forum. Mark Janssen provided a timeline stating that PKIoverheid received notification of a possible BR 4.9.10 violation on 2017-08-29, investigated with KPN, and determined the problem applied to a specific OCSP responder (ocsp2.managedpki.com) while other certificates used a different responder (ocsp3) that was compliant. The thread states that ocsp2 was fixed on 2017-08-31 and that PKIoverheid planned prevention measures including active monitoring of OCSP responses with input/output validation, effective no later than 2017-10-01. Ryan Sleevi asked whether the monitoring mechanism was deployed, and Mark Janssen confirmed on 2017-10-16 that it had been implemented and that things appeared in order. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:09 UTC Revised: 2026-06-16 19:08 UTC Confidence: 0.86 4 comments
Chronology
  1. PKIoverheid received notification of a possible BR 4.9.10 OCSP responder violation and began investigation with KPN.
  2. The non-compliant OCSP responder (ocsp2.managedpki.com) was fixed so it would not return “Good” for unknown serial numbers.
  3. PKIoverheid’s planned prevention measure (active OCSP monitoring with input/output validation) was targeted to be effective no later than this date.
  4. PKIoverheid confirmed the prevention monitoring mechanism had been implemented.
Thread Activity
  1. Mozilla representative — Requested an incident report in the bug, citing BR section 4.9.10 and noting the problem was fixed as of 2017-08-31 and the bug’s purpose was to record the incident report.
  2. Logius representative — Provided an incident timeline and cause, stating the issue applied to ocsp2.managedpki.com and that a configuration change was not executed; also described planned prevention measures including active monitoring and input/output validation.
  3. Community commenter — Asked Mark to confirm whether the planned monitoring mechanism had been deployed.
  4. Logius representative — Confirmed PKIoverheid implemented the monitoring mechanism and that it appears everything is in order.
Participants
Mozilla representative Logius representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1408647 RESOLVED Self Reported Incident Opened 2017-10-14 · Closed 2022-11-14 · 84% similar
Logius: Staat der Nederlanden CA trust issue (WiV)
#1649964 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 77% similar
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
#1542302 RESOLVED Self Reported Incident Opened 2019-04-05 · Closed 2023-02-22 · 77% similar
E-Tugra: Insufficient serial number entropy
#1398261 RESOLVED Self Reported Incident Opened 2017-09-08 · Closed 2023-02-22 · 76% similar
Visa: Non-BR-Compliant OCSP Responders
#1391064 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-08-16 · Closed 2023-02-22 · 76% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1391087 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 75% similar
Visa: Non-BR-Compliant Certificate Issuance
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 75% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1578505 RESOLVED Self Reported Incident Opened 2019-09-03 · Closed 2024-06-30 · 75% similar
LuxTrust: Outdated audit statement for intermediate certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action