Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders
This case records an incident involving OCSP responders for Staat der Nederlandend / PKIoverheid (PKIoverheid TSPs). The issue was that, per BR section 4.9.10 effective 2013-08-01, OCSP responders must not respond with a “good” status for unissued certificates. Kathleen Wilson opened the bug to record the CA’s incident report after problems with the CA’s OCSP responders were discussed in the mozilla.dev.security.policy forum. Mark Janssen provided a timeline stating that PKIoverheid received notification of a possible BR 4.9.10 violation on 2017-08-29, investigated with KPN, and determined the problem applied to a specific OCSP responder (ocsp2.managedpki.com) while other certificates used a different responder (ocsp3) that was compliant. The thread states that ocsp2 was fixed on 2017-08-31 and that PKIoverheid planned prevention measures including active monitoring of OCSP responses with input/output validation, effective no later than 2017-10-01. Ryan Sleevi asked whether the monitoring mechanism was deployed, and Mark Janssen confirmed on 2017-10-16 that it had been implemented and that things appeared in order. The bug is resolved as FIXED.
- PKIoverheid received notification of a possible BR 4.9.10 OCSP responder violation and began investigation with KPN.
- The non-compliant OCSP responder (ocsp2.managedpki.com) was fixed so it would not return “Good” for unknown serial numbers.
- PKIoverheid’s planned prevention measure (active OCSP monitoring with input/output validation) was targeted to be effective no later than this date.
- PKIoverheid confirmed the prevention monitoring mechanism had been implemented.
- Mozilla representative — Requested an incident report in the bug, citing BR section 4.9.10 and noting the problem was fixed as of 2017-08-31 and the bug’s purpose was to record the incident report.
- Logius representative — Provided an incident timeline and cause, stating the issue applied to ocsp2.managedpki.com and that a configuration change was not executed; also described planned prevention measures including active monitoring and input/output validation.
- Community commenter — Asked Mark to confirm whether the planned monitoring mechanism had been deployed.
- Logius representative — Confirmed PKIoverheid implemented the monitoring mechanism and that it appears everything is in order.