PKIoverheid: Compliance issues with CIBG TLS certificates
This case concerns PKIoverheid (Logius) disclosing compliance issues found in TLS certificates issued by CIBG under the “Staat der Nederlanden Root CA – G2”. During a QA check on certificates provided by CIBG for Bug 1573490 (insufficient serial number entropy), Logius found multiple compliance issues and asked CIBG for clarification. Logius reported that CIBG stopped normal issuance of publicy trusted TLS certificates to third parties under that root in December 2017, with a few test certificates issued in March 2018 that were revoked. Logius stated that the affected certificates (3311) contained the forbidden “subject.altname.othername” field and were lacking the CA/Browser Forum Policy OID for OV certificates 2.23.140.1.2.2. Logius also described that it was not aware of the issue until information gathering for Bug 1573490, and it attributed the lack of earlier detection to CP administration and oversight, plus the fact that the certificates were mainly used for machine-to-machine communication and predated CT logging. The bug was published on Bugzilla on 2019-09-04, and the resolution was FIXED; a later comment stated that remediation was complete.
- CIBG stopped normal issuance of publicly trusted TLS certificates to third parties under the “Staat der Nederlanden Root CA – G2” root.
- A few test TLS certificates were issued under the root and were later revoked.
- PKIoverheid (Logius) requested from CIBG a list of certificates in scope for the issue discussed in Bug 1573490.
- Logius performed a QA check on the provided certificates and identified multiple compliance issues.
- Logius published the issue on Bugzilla after determining a remediation approach, including revocation actions.
- Logius representative — Opened the bug and described the compliance issues found in CIBG TLS certificates, including the forbidden subject.altname.othername field and missing OV Policy OID, along with the discovery timeline and planned remediation.
- Community commenter — Asked questions to build a holistic view, including why the issues were not detected earlier by Logius controls or by BSI, and requested explanation of the delay between 2019-03-15 and 2019-08-13.
- Logius representative — Provided detailed explanations for why the issues were not detected earlier, including CP changes, oversight, and BSI’s response, and stated that the delay was an oversight.
- Community commenter — Acknowledged that the questions were answered and indicated follow-ups would be checked with Wayne.
- Fastly representative — Stated that it appears all questions were answered and remediation is complete.