← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1573490
Incident
PKIoverheid: CIBG insufficient serial number entropy
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case involves PKIoverheid's CIBG discovering an issue with insufficient entropy in the serial numbers of TLS certificates it issued. The CA became aware of the problem through discussions in the Mozilla security policy forum and initiated an investigation. Following the discovery, CIBG identified that approximately 4,129 certificates were affected. CIBG successfully revoked the problematic certificates by October 8, 2019, with a few exceptions due to their use in critical healthcare systems. The issue has been resolved with all affected certificates revoked.
Chronology
- CIBG indicates that the insufficient entropy issue affects their certificates.
- CIBG confirms that all affected certificates have been revoked.
Thread Activity
- Logius representative — Filed a bug regarding the insufficient serial number entropy issue.
- Logius representative — Confirmed the last certificate will expire on March 20, 2020.
- Logius representative — Reported successful revocation of affected certificates.
- Logius representative — Confirmed all certificates have been revoked.
Participants
Logius representative
Fastly representative
Community commenter
External References
Similar Local Cases
PKIoverheid: Compliance issues CIBG TLS certificates
PKIoverheid: KPN Insufficient Serial Number Entropy
PKIoverheid: Delayed audit statements for intermediate CAs
PKIoverheid: Delayed S/MIME audit report for MoD PKIoverheid G3 CA
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
QuoVadis / PKIoverheid: incorrect OCSP response for precertificate
SECOM: Non-BR-Compliant Certificate Issuance