PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
The case involves PKIoverheid's failure to conduct a Baseline Requirements (BR) audit for certain subordinate CAs that are technically capable of issuing TLS certificates, which violates Mozilla's Root Store Policy. Kathleen Wilson from Mozilla reported the issue on October 3, 2019. In response, PKIoverheid acknowledged the problem and initiated an investigation, committing to provide an incident report. The CA outlined a remediation plan, including revocation of certain certificates and migration to a new root CA. By March 2020, the affected root CA expired, and all related certificates were confirmed to have expired as well, resolving the compliance issue.
- Mozilla reported lack of BR audits for PKIoverheid's subordinate CAs.
- The root CA expired, along with all underlying CAs and certificates.
- Mozilla representative — Reported the absence of BR audits for PKIoverheid's subordinate CAs.
- Logius representative — Acknowledged the report and stated they were investigating the issue.
- Logius representative — Provided a timeline of actions taken in response to the issue.
- Logius representative — Updated on the revocation of certificates and the remediation plan.
- Logius representative — Confirmed the revocation of QSCD cards with S/MIME certificates.
- Logius representative — Confirmed the expiration of the root CA and all underlying certificates.