← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1719451 Ca Certificate Compliance

PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case involves PKIoverheid's discovery that KPN's Certificate Policy Statement (CPS) included a forbidden domain validation method (3.2.2.4.6). The issue was identified following a discussion in the Mozilla dev-security-policy mailing list. In response, KPN initiated an analysis and began drafting a new version of their CPS. The CA has since implemented a modified ballot template to improve compliance checks and is exploring automation for detecting CPS updates. The issue has been resolved, and the new processes are expected to prevent similar occurrences in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.85 11 comments
Chronology
  1. KPN identified a forbidden domain validation method in their CPS.
  2. PKIoverheid confirmed the use of a new ballot template.
  3. Automation for detecting CPS changes was implemented.
Thread Activity
  1. Logius representative — KPN noticed a message from Andrew Ayer regarding the forbidden validation method.
  2. Logius representative — KPN started analysis and informed PKIoverheid.
  3. Logius representative — Automation for CPS detection was expected to be ready within two weeks.
  4. Logius representative — The bug was proposed to be closed.
Participants
Logius representative Community commenter
Similar Local Cases
#1609706 RESOLVED Ca Certificate Compliance Opened 2020-01-16 · Closed 2024-06-30 · 86% similar
PKIoverheid: Missing Intermediate CA from audit statement
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 71% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 70% similar
DigiCert: Issuance of Cert with Compromised Key
#1680378 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-12-02 · Closed 2023-02-22 · 70% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 70% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1304895 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-09-22 · Closed 2023-02-22 · 70% similar
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
#1695786 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-03-01 · Closed 2023-02-22 · 69% similar
SECOM: Unqualified domain name in SAN
#1598390 RESOLVED Ca Certificate Compliance Opened 2019-11-21 · Closed 2024-05-09 · 69% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action