PKIoverheid: TSP CPS lacks problem reporting instructions
The bug concerns a CPS document published for a TSP (KPN) under PKIoverheid (Logius) that was missing a required section: section 1.5.2 problem reporting instructions. Logius stated it first became aware of the problem because Bugzilla bugpost 1596923 notified it that the CPS disclosed for a specific crt.sh SHA-256 did not include section 1.5.2. In response, Logius asked KPN to investigate and noted that the information normally listed in section 1.5.2 had been misplaced under section 4.9.3 (per RFC 3647). KPN then published an updated CPS, and Logius described that the issue stemmed from KPN’s mistaken belief about where the SC6 ballot-required information should be located, combined with human error during Logius’s review of the returned ballot form. Logius also described a preventive measure for recurrence: applying a “4-eyes principle” (dual control) during review of returned ballot forms. The bug was marked as a duplicate of bug 1596923 and is currently resolved as DUPLICATE.
- Logius was notified via Bugzilla bugpost 1596923 that the TSP CPS disclosed for a specific crt.sh SHA-256 lacked section 1.5.2.
- Logius asked KPN to investigate; Logius reported the missing section content was misplaced under section 4.9.3.
- KPN published an updated CPS.
- Wayne Thayer commented that a mistake was made in the correction; Logius asked KPN to correct it.
- KPN published an updated CPS on the KPN certificaat.kpn.com URL.
- Logius representative — Jorik van 't Hof explained how Logius became aware of the missing CPS section 1.5.2, the timeline of actions taken with KPN, the cause described, and a preventive dual-control measure.
- Community commenter — Ryan Sleevi marked the bug as a duplicate of bug 1596923.