← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1609706
Policy Compliance
PKIoverheid: Missing Intermediate CA from audit statement
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The case involves the missing Intermediate CA 'UZI-register Medewerker niet op naam CA G21' from the audit statement provided by CIBG for the years 2017/2018 and 2018/2019. The issue arose due to a misinterpretation of Mozilla's requirements by both Logius and CIBG, leading to the CA being omitted from the audit scope. The CA ceased issuing certificates in June 2017, and all certificates have since been revoked. The CA is now officially revoked and listed on the CRL. Logius has committed to improving internal processes to prevent future delays in reporting compliance issues.
Chronology
- Logius notified by CCADB about missing CA fingerprint.
- Bug 1605126 opened regarding related issues.
- Creation of this bug due to internal discussions.
- All certificates revoked.
- CA officially revoked and placed on CRL.
Participants
Jorik van 't Hof
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
PKIoverheid / QuoVadis: CPS inconsistencies
PKIoverheid: Compliance issues CIBG TLS certificates
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
GoDaddy: inconsistent disclosure of externally-operated intermediate
Camerfirma: Outdated audit statements for intermediate certs