Closed Bug 1983272 Opened 1 year ago Closed 9 months ago

PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #12 – Outdated Software

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pkioverheid, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Outdated/Unsupported Software on CMS Servers
  • Relevant Policies:
    • ETSI 319 401 (REQ-7.7-03, REQ-7.14.2-13X)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → pkioverheid
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Full Incident Report - ETSI Finding #12 - Outdated Software

Summary

  • CA Owner CCADB unique ID: A000068

  • Incident description: The CAB noted that certain servers had software installed that was not up-to-date or not needed for the services which were provided by those servers. The procedure to monitor and update this was not deemed effective and as such a minor non-conformity was noted.

  • Timeline summary:

    • Non-compliance start date: Q3 2024

    • Non-compliance identified date: 11-Jul-2025

    • Non-compliance end date: Ongoing

  • Relevant policies:

    • ETSI 319 401 REQ-7.7-03: Change control procedures shall be applied for releases, modifications and emergency software fixes of any operational software and changes to the configuration which applies the TSP's security policy.

    • ETSI 319 401 REQ-7.14.2-13X: TSP shall implement specific processes for managing ICT component life cycle and availability and associated security risks.

  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: N/A

  • Incident heuristic: N/A

  • Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)

  • Analysis: N/A

  • Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU emailProtection were no longer included in publicly trusted certificates.

  • Incident heuristic: N/A

Timeline

  • Q3-2024: A change was executed to install new versions of several software packages, however, the old software was not properly removed.

  • 11-Jul-2025: Auditor identifies finding.

  • 17-Jul-2025: Created Corrective Action Plan.

  • 12-Aug-2025: Corrective Action Plan Approved by auditor.

Related Incidents

N/A

Root Cause Analysis

Contributing Factor 1: No automatic process for software update management.

  • Description: The process for removing outdated software versions and ensuring consistent deployment across all systems is not yet automated, resulting in manual steps that may lead to version mismatches or incomplete cleanup.

  • Timeline: See main timeline.

  • Detection: Audit finding by CAB.

  • Interaction with other factors: No.

  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: Needed software updates were detected.

  • What didn’t go well: Insufficient attention was given to remove old versions of packages/software.

  • Where we got lucky: N/A

  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Automate software update management Prevent/Detect Root Cause #1 Report when implemented 2025-10-11 In progress

Appendix

N/A

PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.

We're currently monitoring this bug and are open to comments and questions. With regards to the single action item we currently don't have any substantial updates but it is being worked on (automation has been deployed to a staging environment). We'll update this bug shortly.

KPN has reported that they the sole action item for this incident report. As such, we'll be submitting a closure request shortly since remediation is complete, but in the meantime we're open to any comments or questions the community might have. Thanks.

Report Closure Summary

  • Incident description: The CAB noted that certain servers had software installed that was not up-to-date or not needed for the services which were provided by those servers. The procedure to monitor and update this was not deemed effective and as such a minor non-conformity was noted.
  • Incident Root Cause(s): The process for removing outdated software versions and ensuring consistent deployment across all systems is not yet automated, resulting in manual steps that may lead to version mismatches or incomplete cleanup.
  • Remediation description: KPN implemented a system to automate software updates on the affected systems to reduce the risk of (human) error.
  • Commitment summary: Going forward on top of the action items,periodic reviews of software deployment and asset configurations will be conducted to ensure systems remain aligned with security and compliance requirements.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2025-11-19.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2025-11-19] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 9 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2025-11-19] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.