← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1605126
Audit Related
PKIoverheid: Missing intermediate CA certificates in WTBR audit statements Staat der Nederlanden 2017/2018
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The Government of The Netherlands, PKIoverheid, identified missing intermediate CA certificates in their WTBR audit statements for the years 2017 and 2018. This issue was discovered during a review of audit records in mid-November 2019, triggered by an ALV warning. The missing certificates were not properly listed in management assertions due to a logical error in their auditing process. The CA has since issued new management assertions and is working with KPMG to rectify the oversight. The case has been resolved with the necessary updates submitted to CCADB.
Chronology
- First management assertion issued listing SHA256 fingerprints.
- Logius noticed missing Domain CA fingerprints during CCADB review.
- New management assertions issued based on earlier statements.
- Bug created to clarify facts and remediation actions.
- New CCADB audit case submitted with updated reports.
- Audit cases processed and bug closed.
Participants
Jorik van 't Hof
Wayne Thayer
Kathleen Wilson
External References
Similar Local Cases
PKIoverheid: Overdue audit statements for intermediate certificates
Camerfirma: Qualified Audit Statements
FNMT: Minor non-conformities in 2020 audit statement
Telia: Qualified BR Audit Statement
ETSI Audit of MULTICERT
Consorci AOC: Insufficient Audit Statements
Asseco DS / Certum: Overdue Audit Statements 2019
Sectigo audit reports