← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1586125 Policy Compliance

PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
AI Summary

The case addresses the lack of Baseline Requirements (BR) audits for several subordinate CAs under PKIoverheid that are capable of issuing TLS certificates, which violates Mozilla's Root Store Policy. The CA acknowledged the issue and outlined a remediation plan, including revocation of certain certificates and migration to a new root CA. The situation was complicated by the need to avoid service disruptions for users reliant on these certificates. Ultimately, the root CA expired in March 2020, resolving the compliance issue.

Model: gpt-4o-mini Generated: 2026-06-13 20:01 UTC Confidence: 0.95
Chronology
  1. Bug reported by Kathleen Wilson regarding lack of BR audits.
  2. PKIoverheid acknowledges the issue and begins investigation.
  3. Revocation of personal QSCD cards with S/MIME certificates completed.
  4. Root CA expired, resolving the compliance issue.
Participants
Kathleen Wilson Jorik van 't Hof Ryan Sleevi Wayne Thayer David Weissenberg
Similar Local Cases
#1596923 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2024-06-30 · 74% similar
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
#1609706 RESOLVED Policy Compliance Opened 2020-01-16 · Closed 2024-06-30 · 66% similar
PKIoverheid: Missing Intermediate CA from audit statement
#1391864 RESOLVED Policy Compliance Opened 2017-08-19 · Closed 2023-02-22 · 66% similar
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
#1719451 RESOLVED Policy Compliance Opened 2021-07-07 · Closed 2023-02-22 · 65% similar
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
#1578809 RESOLVED Policy Compliance Opened 2019-09-04 · Closed 2023-02-22 · 65% similar
PKIoverheid: Compliance issues CIBG TLS certificates
#1374381 RESOLVED Policy Compliance Opened 2017-06-19 · Closed 2023-02-22 · 64% similar
SwissSign: BRs require full annual audits
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 64% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1575530 RESOLVED Policy Compliance Opened 2019-08-21 · Closed 2023-02-22 · 64% similar
Camerfirma: Govern d'Andorra audits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action