PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #12 – Outdated Software
This case is an incident report by PKIoverheid (Policy Authority PKIoverheid) regarding an ETSI audit finding for TSP KPN. The CAB noted a minor non-conformity: certain servers had software installed that was not up-to-date or not needed for the services provided by those servers, and the procedure to monitor and update this was not deemed effective. PKIoverheid reported that the non-compliance began in Q3 2024, was identified by the auditor on 11-Jul-2025, and was considered ongoing at the time of the report. The contributing factor was that the process for removing outdated software versions and ensuring consistent deployment across systems was not automated, leading to manual steps and potential incomplete cleanup. As remediation, KPN implemented a system to automate software updates on the affected systems and PKIoverheid stated that periodic reviews of software deployment and asset configurations would be conducted going forward. The bug was resolved as FIXED, with PKIoverheid requesting closure after stating that all action items were completed as described.
- Q3 2024: a change was executed to install new versions of several software packages, but old software was not properly removed.
- 11-Jul-2025: the auditor identified ETSI Finding #12 about outdated software on certain servers.
- 12-Aug-2025: the corrective action plan was approved by the auditor.
- ~19-Nov-2025: the incident report was expected to be closed if no further comments were received.
- Logius representative — PKIoverheid submitted a preliminary incident report describing a minor non-conformity of outdated/unsupported software on CMS servers, disclosed via the annual ETSI audit.
- Logius representative — PKIoverheid posted the full incident report for ETSI Finding #12, including timeline details, root cause analysis, and an action item to automate software update management (in progress).
- Logius representative — PKIoverheid stated they were monitoring the bug and had no updates on the action items at that time.
- Logius representative — PKIoverheid said the action item was being worked on, with automation deployed to a staging environment.
- Logius representative — PKIoverheid reported that KPN had completed the sole action item and said they would submit a closure request shortly since remediation was complete.
- Logius representative — PKIoverheid provided a report closure summary stating KPN implemented automation for software updates and that periodic reviews would be conducted; they requested closure after stating all action items were completed.
- CCADB representative — CCADB issued a final call for comments and stated the incident report would be closed on approximately 2025-11-19.