← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1985816
Certificate Problem Report
PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
During the 2025 ETSI audit of PKIoverheid's Cleverbase, a minor non-conformity was identified regarding incorrect issuer CA information in the Certification Practice Statement (CPS). The error was due to a mismatch between the listed CA hierarchy and the actual issuing CA. This issue was promptly addressed in the subsequent CPS update. PKIoverheid has implemented procedural and technical controls to prevent recurrence, including a mandatory CPS checklist and automated validation of certificate profile data.
Chronology
- Non-compliance start date
- Non-compliance identified date
- Non-compliance end date
- Final call for comments on Incident Report
- Report closure
Participants
pkioverheid@logius.nl
malcolm.doody@gmail.com
incident-reporting@ccadb.org
External References
Similar Local Cases
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #4 –Training
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #1 – Security Handbook
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #6 – Security Incident Procedure
Firmaprofesional: Delayed preliminary response under BR 4.9.5 (Bug #2009941)
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #8 – Logical Access
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #12 – Outdated Software