PKIoverheid: Incorrect OCSP Delegated Responder Certificate
The case involves PKIoverheid's issuance of OCSP Delegated Responder certificates without the required 'id-pkix-ocsp-nocheck' response, violating the CA/Browser Forum Baseline Requirements. The issue was reported by Ryan Sleevi, prompting PKIoverheid to acknowledge the security risk and begin investigating the impact. They confirmed that some CAs could be revoked without issue, while others required careful planning due to their critical role in the PKIoverheid ecosystem. A remediation plan was developed, including revocation of affected CAs and a timeline for replacing certificates. The last of the affected certificates were successfully replaced, and the associated CAs were revoked by early September 2020. The case was resolved with the implementation of corrective actions and a commitment to improve future compliance.
- Initial report of OCSP Delegated Responder certificate issue.
- Revocation of affected EV issuing CAs completed.
- Withdrawal of the G3 root from major trust stores initiated.
- Community commenter — Reported the issuance of OCSP Delegated Responder certificates without required response.
- Logius representative — Confirmed receipt of the report and began investigating the issue.
- Logius representative — Outlined initial impact assessment and revocation plans.
- Logius representative — Updated on the replacement of certificates and revocation of affected CAs.
- Logius representative — Filed a request for the removal of trust for the G3 root.