← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1719451
Policy Compliance
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The case addresses a compliance issue where KPN's CPS included a forbidden domain validation method. This was highlighted in a discussion by Andrew Ayer, prompting PKIoverheid to investigate. KPN acknowledged the oversight and has since implemented measures to prevent future occurrences, including a new ballot template and automated notifications for CPS updates. The issue has been resolved with the implementation of these corrective actions.
Chronology
- KPN acknowledges the issue raised by Andrew Ayer.
- KPN begins drafting a new version of the CPS.
- New ballot template implemented by PKIoverheid.
- Automation for CPS detection completed.
Participants
David Weissenberg
Ryan Sleevi
Robert Leyting
External References
Similar Local Cases
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
PKIoverheid: Compliance issues CIBG TLS certificates
PKIoverheid: Missing Intermediate CA from audit statement
PKIoverheid / QuoVadis: CPS inconsistencies
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy