← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1408647
Self Reported Incident
Logius: Staat der Nederlanden CA trust issue (WiV)
RESOLVED
WONTFIX
Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case concerns a trust issue related to the Staat der Nederlanden CA, operated by PKIoverheid (Logius), following the enactment of the Dutch 'Wet op de inlichtingen- en veiligheidsdiensten' (WiV) law. The law grants the Dutch intelligence services new powers, including the ability to intercept encrypted communications, which raised concerns about potential misuse of the CA for man-in-the-middle attacks. The CA was requested to revoke its trust due to these implications for user security. The case was ultimately resolved with a WONTFIX status, indicating that no action was taken to revoke trust.
Chronology
- User reported vulnerability to MitM attacks due to new intelligence law.
- Case marked as resolved with WONTFIX status.
Thread Activity
- Community commenter — Reported trust issue due to new law allowing intelligence services to intercept communications.
- Mozilla representative — Requested comments to clarify the situation.
- Logius representative — Indicated need to consult policy advisers regarding the issue.
- Logius representative — Provided details on the checks and balances in place for PKIoverheid.
- Mozilla representative — Expressed concerns about removing trust from government CAs without evidence of misuse.
Participants
Community commenter
Mozilla representative
Logius representative
External References
Similar Local Cases
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #8 – Human Resources Management
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
SECOM: Non-BR-Compliant OCSP Responders
WoSign: Action Items
Visa: Non-BR-Compliant OCSP Responders
StartCom: OCSP responder often returns "unknown" for recently-issued certificates
StartCom: Action Items