← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1408647
Certificate Misissuance
Logius: Staat der Nederlanden CA trust issue (WiV)
RESOLVED
WONTFIX
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The case addresses concerns regarding the trustworthiness of the Staat der Nederlanden CA, operated by PKIoverheid, in light of new surveillance laws that empower the Dutch intelligence services to intercept encrypted communications. The law allows for the use of 'false keys' to access systems, raising significant privacy and security issues for users of Mozilla products. The bug report suggests revoking trust in this CA due to these legal provisions, which could facilitate man-in-the-middle attacks. The case has been marked as resolved with a 'WONTFIX' resolution.
Chronology
- Initial report of trust issue due to new surveillance law.
- Discussion on checks and balances of PKIoverheid's CA operations.
- Case marked as resolved.
Participants
cris.vanpelt@gmail.com
kathleen.a.wilson@gmail.com
mark.janssen@logius.nl
jeroen@bohol.ph
guido.leenders@invantive.com
the_djmaze@hotmail.com
ryan.sleevi@gmail.com
leyyyyy@gmail.com
yuhongbao_386@hotmail.com
gerv@mozilla.org
hopefox34@yahoo.com
External References
Similar Local Cases
Google Trust Services: 63 bit serial numbers in some certificates
GlobalSign: 4 Misissued certificates with invalid CN
GlobalSign: AT&T SSL certificates without the AIA extension
Telia: Misissued certificate - Invalid wildcard format
SHA-1 issuance by DigiCert roots
Amazon Trust Services: Certificates issued for "testing.com"
StartCom's key for bogus www.mozilla.com certificate should be destroyed
DigiCert / Verizon: Reserved/Intranet domain name