← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1609706 Ca Certificate Compliance

PKIoverheid: Missing Intermediate CA from audit statement

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

PKIoverheid (Logius) filed this bug after CCADB notified it that the fingerprint of the issuing CA “UZI-register Medewerker niet op naam CA G21” was missing from an audit statement supplied by CIBG for the 2017/2018 yearly audit. Logius stated that the CA in question had been “skipped” in the yearly audit in 2017/2018 and 2018/2019, and that this was due to a misinterpretation of Mozilla requirements by both Logius and CIBG. Logius explained that issuance by this CA was halted in June 2017 due to a new ETSI certificate profile requirement that CIBG’s systems could not comply with at the time, and that the CA was intended to be resumed later under a new G3 TSP CA. In response to the discovery, Logius created this bug and later reported remediation steps, including that all certificates were revoked and that the CA would be revoked. The thread states that the CA was revoked and placed on a CRL, and a Fastly participant confirmed the CA was revoked and that remediation was complete. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.86 6 comments
Chronology
  1. Issuance of certificates by the CA “UZI-register Medewerker niet op naam CA G21” was halted due to an ETSI certificate profile requirement that systems could not comply with at the time.
  2. CCADB notified Logius that the fingerprint of the issuing CA was missing from the audit statement for the 2017/2018 yearly audit.
  3. CIBG provided a formal response explaining why the CA was halted and how audits were interpreted.
  4. Logius created the Bugzilla case after internal discussions with CIBG.
  5. Logius reported that all certificates had been revoked and that the CA would be revoked later that week.
  6. Logius reported that the CA was revoked and placed on a CRL.
Thread Activity
  1. Logius representative — Logius described how it became aware of the missing CA fingerprint in the audit statement and outlined the background and remediation timeline.
  2. Community commenter — Ryan asked follow-up questions about the reporting timeline and prevention steps, referencing Mozilla incident-report expectations.
  3. Logius representative — Logius responded with planned process changes for faster disclosure and reporting, and discussed operational context for PKIoverheid TSPs.
  4. Logius representative — Logius stated that all certificates had been revoked and that the CA would be revoked later that week.
  5. Logius representative — Logius reported that the CA “UZI-register Medewerker niet op naam CA G21” was revoked and placed on CRL at http://www.csp.uzi-register.nl/cdp/zorg_csp_ca_g21.crl.
  6. Fastly representative — Fastly confirmed the CA was revoked and that remediation was complete.
Participants
Logius representative Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1719451 RESOLVED Ca Certificate Compliance Opened 2021-07-07 · Closed 2023-02-22 · 86% similar
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 78% similar
Izenpe: Multiple invalid EV certificates issued
#1525710 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-06 · Closed 2023-02-22 · 78% similar
Amazon Trust Services: Test revoked certificates with invalid validity period
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 77% similar
Camerfirma: Govern d'Andorra audits
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 76% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 76% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 76% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 76% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action