PKIoverheid: Overdue audit statements for intermediate certificates
This case reports that audit statements were past-due for several PKIoverheid intermediate certificates. The CA owner (Government of The Netherlands, PKIoverheid/Logius) listed multiple QuoVadis-operated intermediate certificates with standard audit period end dates of 05/31/2019. In response, Logius stated that QuoVadis had delayed the ETSI audit due to factors including COVID restrictions and additional work, and that the audit statements were signed on October 6 and filed in CCADB on October 12. Mozilla noted that the provided audit letter link failed ALV validation due to a protocol violation error (CR must be followed by LF) and asked for a fix so ALV could run. Logius later provided an updated explanation and indicated that the PDF would be accessible via the BSI VerifEye directory, and that they filed the updated PDF link in CCADB to test ALV. Mozilla confirmed that the ALV process could run and closed the case. The bug is resolved as FIXED.
- Audit statements for multiple PKIoverheid intermediate certificates were signed by the auditor.
- The audit statements were filed in CCADB.
- Mozilla reported ALV validation failures when attempting to download the audit letter from the provided link.
- A new BSI VerifEye link to the audit PDF was provided and Logius clarified auditor/audit-letter content; Mozilla confirmed ALV could run.
- Mozilla representative — Opened the bug stating audit statements were past-due for multiple QuoVadis-operated PKIoverheid intermediate certificates and provided a CCADB audit delay reference link.
- Logius representative — Explained that QuoVadis’ ETSI audit was delayed (including COVID restrictions) and said the audit statements were signed on October 6 and filed in CCADB on October 12.
- Mozilla representative — Reported that the audit letter link failed ALV with a protocol violation error and asked for the issue to be fixed so ALV could run.
- Community commenter — Asked whether there was any update.
- Logius representative — Said QuoVadis would post an updated document to fix the issue and that they would update the bug after posting.
- Mozilla representative — Noted the case was potentially resolved with an attachment submission and that Mozilla policy requires the auditor to explain the delay in providing the audit letter.
- Mozilla representative — Reported ALV still failed with the same protocol violation error and asked for a better PDF version location and clarification about “(not in scope)”.
- DigiCert — Provided direct BSI VerifEye access links to the audit PDF and where to find it.
- Logius representative — Clarified auditor inputs about ALV functioning, the VerifEye directory change, and the meaning of “Not In Scope,” and stated they filed the new PDF link in CCADB for testing.
- Mozilla representative — Confirmed ALV could run and closed the case.