PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Network Zone Disaster Recovery Firewall Rules and Review
- Relevant Policies:
- ETSI 319 401 (REQ-7.8-05, -06)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #10 – Firewall Rules and Review
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that for the DR (Disaster Recovery) site no active target actual document was available for certain network zones and that no firewall rulebase review and hardening review had been performed during the audit period. This was recorded by the CAB as a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: N/A
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing.
-
-
Relevant policies:
-
ETSI 319 401 REQ-7.8-05: The TSP shall explicitly forbid or deactivate not needed connections and services.
-
ETSI 319 401 REQ-7.8-06: The TSP shall review the established rule set on a regular basis.
-
-
Source of incident disclosure: Finding by CAB during annual ETSI audit.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates. -
Incident heuristic: N/A
Timeline
-
11-Jul-2025: Auditor identifies finding.
-
17-Jul-2025: Created Corrective Action Plan.
-
12-Jul-2025: Corrective Action Plan Approved by auditor.
-
Aug-2025: Firewall review executed, no findings.
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: No review of firewall rules on disaster recovery site.
-
Description: During the review of firewall rules and hardening, the absence of the DR site was not noticed, because this environment was missing from the scheduled review plan. This indicates a gap in the process for defining and maintaining the review schedule, where not all relevant environments were properly identified and included.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: Changes in the environment were correctly handled.
-
What didn’t go well: N/A
-
Where we got lucky:
-
The environment setup is not subject to frequent changes.
-
When the firewall review was executed no findings were identified.
-
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute DR firewall review | Mitigate | Root Cause # 1 | review done and reported to compliance | Aug 2025 | Completed |
| Implement check to ensure all environments are included in the firewall review schedule to prevent future omissions. | Detect | Root Cause # 1 | Checks are implemented | 2025-10-11 | In progress |
| Add periodic firewall review to go-live checklist. | Prevent | Root Cause # 1 | Update checklist and discuss with operations | 2025-10-11 | In progress |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.
| Assignee | ||
Comment 3•11 months ago
|
||
For this audit finding action item #1 had been completed previously. After discussions with KPN we determined that action item #2 was a duplicate of action item #3. Action item #3 has been resolved by KPN in the meantime so that means all action items have been completed.
To summarise:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute DR firewall review | Mitigate | Root Cause # 1 | review done and reported to compliance | Aug 2025 | Completed |
| Implement check to ensure all environments are included in the firewall review schedule to prevent future omissions. | Detect | Root Cause # 1 | Checks are implemented | 2025-10-11 | Won't fix (duplicate of #3) |
| Add periodic firewall review to go-live checklist. | Prevent | Root Cause # 1 | Update checklist and discuss with operations | 2025-10-11 | Completed |
Comment 4•9 months ago
|
||
Could you confirm whether the NCSSRs were impacted by this bug and why they weren’t listed under ‘Relevant Policies’?
| Assignee | ||
Comment 5•9 months ago
|
||
Hi Dustin, thanks for your reply. The NCSSRs were in scope for this audit (specifically version 2.0.3). The audit criteria under "relevant policies" bullet in this bug were directly taken from the audit report (statement of non-conformity). As to why the CAB didn't include the NCSSRs for this specific finding, we're not exactly sure, so KPN has asked the CAB (BSI) for clarification. This might take a few days. Thanks.
| Assignee | ||
Comment 6•9 months ago
|
||
Hi Dustin,
We have gotten a response from BSI (the CAB) regarding the applicability of NetSec in general with regards to this audit finding and together with KPN have made an assessment about the applicability of specific NCCSR requirements. Our questions to BSI and their answer are posted below verbatim accompanied by our our assessment below that.
1. Should NCSSRs be explicitly mentioned in the report for this type of finding?
The audit was conducted as an assertion-based audit, where KPN confirmed compliance with the applicable requirements outlined in the Statement of Applicability and the Overview of Applicability. These requirements include ETSI standards, NCSSRs, and the PKIoverheid Programme of Requirements, among others. For reporting purposes, each non-conformity is referenced against the requirement that most directly addresses the issue. In this case, ETSI EN 319 401 REQ-7.7-01 fully covers the observed condition (unsupported software). Referencing ETSI ensures clarity and consistency in the report, while all applicable criteria were evaluated during the audit.
2. Do you consider this non-conformity a breach of NCSSRs, or is reporting under ETSI sufficient?
The non-conformity also falls under NCSSR obligations (e.g., timely remediation of unsupported components) and PKIOverheid requirements. The audit team reviewed all applicable frameworks as part of the full-scope audit required by, for example, Mozilla Root Store Policy and Microsoft Trusted Root Certificate Program requirements. For reporting purposes, the finding was mapped to ETSI EN 319 401 because it most directly addresses the issue. This does not diminish the relevance of other frameworks, which remain part of the audit scope. In general, a TSP should ensure that any corrective action plan addresses compliance across all obligations.
As to the specific NCCSR criteria applicable to this finding, we’ve concluded that " 1.2.2 – CA Infrastructure Security" is applicable in this case, specifically the part about minimizing unnecessary active components and capabilities. We’ll update this bug accordingly.
| Assignee | ||
Comment 7•8 months ago
|
||
As indicated in our previous post we hereby restate our incident report, now fully reflecting the applicable audit criteria including the NCSSRs. We've also updated the end date for the non-compliance based on the completion of the action items and updated the table with the action items itself to reflect that too.
Full Incident Report - ETSI Finding #10 – Firewall Rules and Review
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that for the DR (Disaster Recovery) site no active target actual document was available for certain network zones and that no firewall rulebase review and hardening review had been performed during the audit period. This was recorded by the CAB as a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: N/A
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: 10-Sep-2025.
-
-
Relevant policies:
-
ETSI 319 401 REQ-7.8-05: The TSP shall explicitly forbid or deactivate not needed connections and services.
-
ETSI 319 401 REQ-7.8-06: The TSP shall review the established rule set on a regular basis.
-
Network and Certificate System Security Requirements section 1.2.2 – CA Infrastructure Security: CA Infrastructure and Network Boundary Controls MUST be implemented and configured in a manner that minimizes unnecessary active components and capabilities such that:
-
- All connections, communications, applications, services, protocols, and ports not used are removed and/or disabled; and
- only connections, communications, applications, services, protocols, and ports necessary and approved under the Principle of Least Privilege are enabled.
- Source of incident disclosure: Finding by CAB during annual ETSI audit.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates. -
Incident heuristic: N/A
Timeline
-
11-Jul-2025: Auditor identifies finding.
-
17-Jul-2025: Created Corrective Action Plan.
-
12-Jul-2025: Corrective Action Plan Approved by auditor.
-
Aug-2025: Firewall review executed, no findings.
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: No review of firewall rules on disaster recovery site.
-
Description: During the review of firewall rules and hardening, the absence of the DR site was not noticed, because this environment was missing from the scheduled review plan. This indicates a gap in the process for defining and maintaining the review schedule, where not all relevant environments were properly identified and included.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: Changes in the environment were correctly handled.
-
What didn’t go well: N/A
-
Where we got lucky:
-
The environment setup is not subject to frequent changes.
-
When the firewall review was executed no findings were identified.
-
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute DR firewall review | Mitigate | Root Cause # 1 | review done and reported to compliance | Aug 2025 | Completed |
| Implement check to ensure all environments are included in the firewall review schedule to prevent future omissions. | Detect | Root Cause # 1 | Checks are implemented | 2025-10-11 | Won't fix (duplicate of #3) |
| Add periodic firewall review to go-live checklist. | Prevent | Root Cause # 1 | Update checklist and discuss with operations | 2025-10-11 | Completed |
Appendix
N/A
Comment 8•8 months ago
|
||
Report Closure Summary
- Incident description: The CAB noted that for the Disaster Recovery (DR) site no active target document was available for certain network zones and that no firewall rulebase review and hardening review had been performed during the audit period. This was recorded by the CAB as a minor non-conformity.
- Incident Root Cause(s): The DR site was not included in the scheduled firewall review due to a gap in the process for defining and maintaining the review plan. Not all relevant environments were properly identified and included.
- Remediation description: KPN has taken several steps to address the identified issue. These included:
- Executing the firewall review for the DR site (completed August 2025, no findings).
- Adding a check to ensure all environments are included in the firewall review schedule.
- Updating the go-live checklist to include periodic firewall review requirements.
- Commitment summary: KPN commits to periodically evaluating and improving the firewall review process to align with ETSI requirements and best practices. Lessons learned from this incident have been incorporated into process updates to prevent recurrence.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 9•8 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-01-13.
Updated•8 months ago
|
Description
•