← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1649964
Certificate Problem Report
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The PKIoverheid CA issued OCSP Delegated Responder certificates without the required 'id-pkix-ocsp-nocheck' response, violating Baseline Requirements. This issue was reported and acknowledged by Logius, which recognized the associated security risks. A remediation plan was developed to revoke affected certificates and replace them with new ones, while minimizing disruption to critical services. The revocation process was complex due to the reliance on these certificates in various sectors, leading to a phased approach for replacement and revocation.
Chronology
- Issue reported to Mozilla
- Logius acknowledges the issue
- Remediation plan outlined
- Request for removal of trust filed
- Closure of the case planned
Participants
Ryan Sleevi
Jorik van 't Hof
David Weissenberg
External References
Similar Local Cases
PKIoverheid: CIBG insufficient serial number entropy
PKIoverheid: TSP CPS lacks problem reporting instructions
PKIoverheid: Delayed S/MIME audit report for MoD PKIoverheid G3 CA
QuoVadis / PKIoverheid: incorrect OCSP response for precertificate
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders
PKIoverheid: KPN Insufficient Serial Number Entropy
Camerfirma: Incorrect OCSP Delegated Responder Certificate