Closed Bug 1983275 Opened 1 year ago Closed 8 months ago

PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #15 – Outdated Software

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pkioverheid, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Keyfactor EJBCA version out of support
  • Relevant Policies:
    • ETSI 319 401 (REQ-7.7-01)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → pkioverheid
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Full Incident Report - ETSI Finding #15 – Outdated Software

Summary

  • CA Owner CCADB unique ID: A000068

  • Incident description: The CAB noted that the CA/VA software used by KPN was out-of-support by the supplier at the time of the audit. This was observed as a minor non-conformity.

  • Timeline summary:

    • Non-compliance start date: Jul-2024

    • Non-compliance identified date: 11-Jul-2025

    • Non-compliance end date: Ongoing.

  • Relevant policies:

    • ETSI 319 401 REQ-7.7-01: The TSP shall use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them.
  • Source of incident disclosure: Audit finding by CAB.

Impact

  • Total number of certificates: N/A

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: N/A

  • Incident heuristic: N/A

  • Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)

  • Analysis: N/A

  • Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU emailProtection were no longer included in publicly trusted certificates.

  • Incident heuristic: N/A

Timeline

  • Jan-2024: A proper LCM plan/upgrade preparation plan was not created for the CA application.

  • Jul-2024: End of support for the then used version of the CA application.

  • 11-Jul-2025: Auditor identifies finding.

  • 17-Jul-2025: Created Corrective Action Plan.

  • 12-Aug-2025: Corrective Action Plan Approved by auditor.

Related Incidents

N/A

Root Cause Analysis

Contributing Factor 1: Absence of a proper LCM plan/upgrade path

  • Description: The deployment of the CA application was postponed because there was no clear plan in place to manage its upgrade, because the onboarding process for software did not include proper assignment of responsibility.

  • Timeline: See main timeline.

  • Detection: Audit finding by CAB.

  • Interaction with other factors: No

  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A

  • What didn’t go well: N/A

  • Where we got lucky: The previous version of the CA software didn’t contain any known security issues.

  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Integration of the CA software manufacturer’s release plan of the CA software in the LCM process. Mitigate Root Cause #1 implemented release plan 2025-10-11 In progress
Add check to update LCM in go-live checklist for new services/applications. Prevent Root Cause #1 Delivered checklist and discussed with operations (report back) 2025-10-11 In progress

Appendix

N/A

PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.

A status update from our end:

The status of the action item is then as follows:

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Integration of the CA software manufacturer’s release plan of the CA software in the LCM process. Mitigate Root Cause #1 implemented release plan 2025-10-25 in progress
Add check to update LCM in go-live checklist for new services/applications. Prevent Root Cause #1 Delivered checklist and discussed with operations (report back) 2025-10-11 Completed

Unfortunately 100% completion of action item #1 wasn't managed before the due date. KPN has indicated that they're almost done and now estimates that action item #1 will now be completed by November 4, 2025 at the latest.

KPN has finished action item #1. WIth that, all action items are complete and with that we'll be posting a Closure summary shortly.

Report Closure Summary

  • Incident description: The CAB noted that the CA/VA software used by KPN was out-of-support by the supplier at the time of the audit. This was observed as a minor non-conformity.
  • Incident Root Cause(s): The deployment of the CA application was postponed because there was no clear plan in place to manage its upgrade, because the onboarding process for software did not include proper assignment of responsibility.
  • remediation description: KPN has updated the go-live checklist for new software/applications to include LCM checks and has also integrated the release plan provided by the supplier of the CA software in her own LCM/deployment process
  • Commitment summary: KPN commits to periodically evaluating and updating the lifecycle management (LCM) process and the go-live checklist, ensuring that all future hardware and software is updated and supported in a timely manner, and that responsibilities are clearly assigned.

All Action Items disclosed in this report have been completed as described, and we request its closure.

Since this is an S/MIME CA, the S/MIME Baseline Requirements incorporate the NCSSRs, which require timely remediation of unsupported software. Could you confirm whether the NCSSRs were impacted by this bug and why they weren’t listed under ‘Relevant Policies’?

Hi Dustin, thanks for your reply. The NCSSRs were in scope for this audit (specifically version 2.0.3). The audit criteria under "relevant policies" bullet in this bug were directly taken from the audit report (statement of non-conformity). As to why the CAB didn't include the NCSSRs for this specific finding, we're not exactly sure, so KPN has asked the CAB (BSI) for clarification. This might take a few days. Thanks.

Hi Dustin,

We have gotten a response from BSI (the CAB) regarding the applicability of NetSec in general with regards to this audit finding and together with KPN have made an assessment about the applicability of specific NCCSR requirements. Our questions to BSI and their answer are posted below verbatim accompanied by our our assessment below that.

1. Should NCSSRs be explicitly mentioned in the report for this type of finding?
The audit was conducted as an assertion-based audit, where KPN confirmed compliance with the applicable requirements outlined in the Statement of Applicability and the Overview of Applicability. These requirements include ETSI standards, NCSSRs, and the PKIoverheid Programme of Requirements, among others. For reporting purposes, each non-conformity is referenced against the requirement that most directly addresses the issue. In this case, ETSI EN 319 401 REQ-7.7-01 fully covers the observed condition (unsupported software). Referencing ETSI ensures clarity and consistency in the report, while all applicable criteria were evaluated during the audit.

2. Do you consider this non-conformity a breach of NCSSRs, or is reporting under ETSI sufficient?
The non-conformity also falls under NCSSR obligations (e.g., timely remediation of unsupported components) and PKIOverheid requirements. The audit team reviewed all applicable frameworks as part of the full-scope audit required by, for example, Mozilla Root Store Policy and Microsoft Trusted Root Certificate Program requirements. For reporting purposes, the finding was mapped to ETSI EN 319 401 because it most directly addresses the issue. This does not diminish the relevance of other frameworks, which remain part of the audit scope. In general, a TSP should ensure that any corrective action plan addresses compliance across all obligations.

As to the specific NCCSR criteria applicable to this finding, we’ve concluded that " 4.2 – Vulnerability Management Lifecycle" is applicable in this case. We’ll update this bug accordingly.

As indicated in our previous post we hereby restate our incident report, now fully reflecting the applicable audit criteria including the NCSSRs. We’ve also updated the end date for the non-compliance based on the status of the action items (all completed) and updated the table to reflect this.

Full Incident Report - ETSI Finding #15 – Outdated Software

Summary

  • CA Owner CCADB unique ID: A000068

  • Incident description: The CAB noted that the CA/VA software used by KPN was out-of-support by the supplier at the time of the audit. This was observed as a minor non-conformity.

  • Timeline summary:

    • Non-compliance start date: Jul-2024

    • Non-compliance identified date: 11-Jul-2025

    • Non-compliance end date: 26-Nov-2025.

  • Relevant policies:

    • ETSI 319 401 REQ-7.7-01: The TSP shall use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them.
    • Network and Certificate System Security Requirements section 4.2 – Vulnerability Management Lifecycle: The CA MUST document and follow a vulnerability correction process that includes: 1. identification; 2. review; 3. response; and 4. remediation.
  • Source of incident disclosure: Audit finding by CAB.

Impact

  • Total number of certificates: N/A

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: N/A

  • Incident heuristic: N/A

  • Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)

  • Analysis: N/A

  • Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU emailProtection were no longer included in publicly trusted certificates.

  • Incident heuristic: N/A

Timeline

  • Jan-2024: A proper LCM plan/upgrade preparation plan was not created for the CA application.

  • Jul-2024: End of support for the then used version of the CA application.

  • 11-Jul-2025: Auditor identifies finding.

  • 17-Jul-2025: Created Corrective Action Plan.

  • 12-Aug-2025: Corrective Action Plan Approved by auditor.

Related Incidents

N/A

Root Cause Analysis

Contributing Factor 1: Absence of a proper LCM plan/upgrade path

  • Description: The deployment of the CA application was postponed because there was no clear plan in place to manage its upgrade, because the onboarding process for software did not include proper assignment of responsibility.

  • Timeline: See main timeline.

  • Detection: Audit finding by CAB.

  • Interaction with other factors: No

  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A

  • What didn’t go well: N/A

  • Where we got lucky: The previous version of the CA software didn’t contain any known security issues.

  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Integration of the CA software manufacturer’s release plan of the CA software in the LCM process. Mitigate Root Cause #1 implemented release plan 2025-10-11 Completed
Add check to update LCM in go-live checklist for new services/applications. Prevent Root Cause #1 Delivered checklist and discussed with operations (report back) 2025-10-11 Completed

Appendix

N/A

Since the original closure statement was already posted in comment #6 and the discussion about the applicability of the NCSSRs doesn't impact that, we would like to request closure of this bug unless the community or a root store has any questions or concerns. Thanks!

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2025-12-24.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2025-12-24] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 8 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2025-12-24] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.