PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
This case involves PKIoverheid's failure to revoke certain certificates within the required timeframe of 7 days, as highlighted in Bug 1649964. The CA acknowledged the delay and indicated that a detailed incident report would be provided. Subsequent communications outlined a remediation plan, including the replacement of certificates under the 'Staat der Nederlanden Root CA - G3' with new certificates under the 'Staat der Nederlanden EV Root CA'. By early 2021, PKIoverheid reported that they had replaced up to 95% of the affected TLS certificates and were in the process of revoking the remaining certificates. The bug was resolved with a status of 'FIXED'.
- Bug opened to track incident response regarding delayed revocation.
- PKIoverheid reported that 95% of TLS certificates had been replaced and planned revocation of remaining certificates.
- Bug closed after confirming resolution of the revocation issue.
- Mozilla representative — Opening this bug to track incident response report on, and discussion regarding, CAs not yet revoked.
- Logius representative — Logius PKIoverheid requires more than 7 days to revoke the certificates affected by Bug 1649964.
- Logius representative — Up to 95% of the TLS-certificates have been replaced; remaining certificates will be revoked between January 11 and 22.
- Mozilla representative — I'll close this bug on or about next Wednesday, 31-March-2021.