← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1746421
Certificate Problem Report
PKIoverheid: (KPN) Incorrect Subject OrganizationName
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The PKIoverheid CA identified an issue with 16 certificates that incorrectly listed the organization name as 'Dienst Uitvoering Onderwijs test', which does not correspond to the Dutch trade register. The problem was first reported on December 6, 2021, and the certificates were revoked on December 16, 2021. KPN, the issuing entity, has since amended its validation procedures to prevent similar issues in the future. A post-mortem report was filed, and guidelines for validation have been formalized.
Chronology
- Abuse report sent to Logius
- Reminder sent to Logius
- Certificates revoked by KPN
Participants
David Weissenberg
External References
Similar Local Cases
QuoVadis / PKIoverheid: incorrect OCSP response for precertificate
PKIoverheid: Delayed S/MIME audit report for MoD PKIoverheid G3 CA
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders
PKIoverheid: KPN Insufficient Serial Number Entropy
PKIoverheid: CIBG insufficient serial number entropy
PKIoverheid: TSP CPS lacks problem reporting instructions