← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1719451
Ca Certificate Compliance
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case involves PKIoverheid's discovery that KPN's Certificate Policy Statement (CPS) included a forbidden domain validation method (3.2.2.4.6). The issue was identified following a discussion in the Mozilla dev-security-policy mailing list. In response, KPN initiated an analysis and began drafting a new version of their CPS. The CA has since implemented a modified ballot template to improve compliance checks and is exploring automation for detecting CPS updates. The issue has been resolved, and the new processes are expected to prevent similar occurrences in the future.
Chronology
- KPN identified a forbidden domain validation method in their CPS.
- PKIoverheid confirmed the use of a new ballot template.
- Automation for detecting CPS changes was implemented.
Thread Activity
- Logius representative — KPN noticed a message from Andrew Ayer regarding the forbidden validation method.
- Logius representative — KPN started analysis and informed PKIoverheid.
- Logius representative — Automation for CPS detection was expected to be ready within two weeks.
- Logius representative — The bug was proposed to be closed.
Participants
Logius representative
Community commenter
External References
Similar Local Cases
PKIoverheid: Missing Intermediate CA from audit statement
e-commerce monitoring GmbH: CN domain not in SAN
DigiCert: Issuance of Cert with Compromised Key
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
SECOM: Unqualified domain name in SAN
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs