PKIoverheid: Removal of websites trust bit for "Staat der Nederlanden Root CA – G3"
PKIoverheid (Logius) requested Mozilla to remove the "websites" trust bit for its "Staat der Nederlanden Root CA – G3" root. The request was triggered by a stated "Delegated OCSP Responder EKU" non-compliance with Baseline Requirements section 4.9.9 and the resulting vulnerability. Mozilla agreed to resolve the issue by disabling the "websites" trust bit starting 1 February 2021. PKIoverheid asked Mozilla to make the appropriate NSS root store changes for the specified root fingerprint. Kathleen Wilson confirmed the action to turn off the Websites trust bit, and David Weissenberg indicated they opted for option 1 and requested the websites trust bit be turned off for the root. Kathleen Wilson filed Bug #1687822 for the NSS code changes, and the current bug status is RESOLVED with resolution FIXED.
- PKIoverheid requested Mozilla disable the "websites" trust bit for the "Staat der Nederlanden Root CA – G3" root starting 1 February 2021 due to Baseline Requirements non-compliance.
- PKIoverheid confirmed it wanted option 1 (turn off the Websites trust bit) and provided the root fingerprint for the change.
- Mozilla filed a separate bug for NSS code changes to implement the trust-bit update.
- Logius representative — Requested Mozilla disable the "websites" trust bit for "Staat der Nederlanden Root CA – G3" from 1 February 2021 due to "Delegated OCSP Responder EKU" non-compliance and vulnerability, and asked for confirmation after implementation.
- Logius representative — Noted the email trust bit for the root is enabled and requested it remain enabled.
- Mozilla representative — Asked which action to take: turn off the Websites trust bit entirely or set "Distrust for TLS After" to February 1, 2021.
- Logius representative — Confirmed they want option 1 and requested Mozilla turn off the Websites trust bit for the specified root fingerprint.
- Mozilla representative — Filed Bug #1687822 for the NSS code changes.