PKIoverheid: Delayed S/MIME audit report for MoD PKIoverheid G3 CA
This case involves the Dutch Ministry of Defence (NL-MoD) failing to obtain a valid S/MIME audit statement for the period from September 1, 2023, to September 15, 2024, as required by Mozilla's Root Store Policy v2.9. The issue arose due to a lack of a necessary scope extension audit under ETSI TS 119 411-6, which was not conducted due to miscommunication and misunderstandings regarding auditing requirements. As a result, Logius, the Super-CA, ceased S/MIME issuance from the affected CA and performed a detailed gap analysis to identify deficiencies in compliance with the S/MIME Baseline Requirements. Remediation actions included implementing a self-assessment process for TSPs and improving audit planning and monitoring. The case has now been resolved with commitments for ongoing compliance measures.
- Mozilla adopted version 2.9 of the Mozilla Root Store Policy, mandating compliance with S/MIME Baseline Requirements.
- Non-compliance identified when it became clear that NL-MoD could not obtain a valid S/MIME audit statement.
- Non-compliance period ended as NL-MoD ceased S/MIME issuance.
- Closure statement submitted, detailing remediation and commitments for future compliance.
- Logius representative — Filed a bug regarding the delay in obtaining the S/MIME audit report.
- Logius representative — Submitted a closure statement detailing the incident and remediation actions taken.
- CCADB representative — Final call for comments on the incident report before closure.