PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #15 – Outdated Software
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Keyfactor EJBCA version out of support
- Relevant Policies:
- ETSI 319 401 (REQ-7.7-01)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #15 – Outdated Software
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that the CA/VA software used by KPN was out-of-support by the supplier at the time of the audit. This was observed as a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: Jul-2024
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing.
-
-
Relevant policies:
- ETSI 319 401 REQ-7.7-01: The TSP shall use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them.
-
Source of incident disclosure: Audit finding by CAB.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates. -
Incident heuristic: N/A
Timeline
-
Jan-2024: A proper LCM plan/upgrade preparation plan was not created for the CA application.
-
Jul-2024: End of support for the then used version of the CA application.
-
11-Jul-2025: Auditor identifies finding.
-
17-Jul-2025: Created Corrective Action Plan.
-
12-Aug-2025: Corrective Action Plan Approved by auditor.
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: Absence of a proper LCM plan/upgrade path
-
Description: The deployment of the CA application was postponed because there was no clear plan in place to manage its upgrade, because the onboarding process for software did not include proper assignment of responsibility.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: N/A
-
What didn’t go well: N/A
-
Where we got lucky: The previous version of the CA software didn’t contain any known security issues.
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Integration of the CA software manufacturer’s release plan of the CA software in the LCM process. | Mitigate | Root Cause #1 | implemented release plan | 2025-10-11 | In progress |
| Add check to update LCM in go-live checklist for new services/applications. | Prevent | Root Cause #1 | Delivered checklist and discussed with operations (report back) | 2025-10-11 | In progress |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.
| Assignee | ||
Comment 3•11 months ago
|
||
A status update from our end:
- For action item #1 we unfortunately have incurred a small delay due to the fact that this turned out to be more complex than initially envisioned.
- Action item #2 has been completed (as indicated in https://bugzilla.mozilla.org/show_bug.cgi?id=1983268 and https://bugzilla.mozilla.org/show_bug.cgi?id=1983270).
The status of the action item is then as follows:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Integration of the CA software manufacturer’s release plan of the CA software in the LCM process. | Mitigate | Root Cause #1 | implemented release plan | 2025-10-25 | in progress |
| Add check to update LCM in go-live checklist for new services/applications. | Prevent | Root Cause #1 | Delivered checklist and discussed with operations (report back) | 2025-10-11 | Completed |
| Assignee | ||
Comment 4•10 months ago
|
||
Unfortunately 100% completion of action item #1 wasn't managed before the due date. KPN has indicated that they're almost done and now estimates that action item #1 will now be completed by November 4, 2025 at the latest.
| Assignee | ||
Comment 5•9 months ago
|
||
KPN has finished action item #1. WIth that, all action items are complete and with that we'll be posting a Closure summary shortly.
| Assignee | ||
Comment 6•9 months ago
|
||
Report Closure Summary
- Incident description: The CAB noted that the CA/VA software used by KPN was out-of-support by the supplier at the time of the audit. This was observed as a minor non-conformity.
- Incident Root Cause(s): The deployment of the CA application was postponed because there was no clear plan in place to manage its upgrade, because the onboarding process for software did not include proper assignment of responsibility.
- remediation description: KPN has updated the go-live checklist for new software/applications to include LCM checks and has also integrated the release plan provided by the supplier of the CA software in her own LCM/deployment process
- Commitment summary: KPN commits to periodically evaluating and updating the lifecycle management (LCM) process and the go-live checklist, ensuring that all future hardware and software is updated and supported in a timely manner, and that responsibilities are clearly assigned.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 7•9 months ago
|
||
Since this is an S/MIME CA, the S/MIME Baseline Requirements incorporate the NCSSRs, which require timely remediation of unsupported software. Could you confirm whether the NCSSRs were impacted by this bug and why they weren’t listed under ‘Relevant Policies’?
| Assignee | ||
Comment 8•9 months ago
|
||
Hi Dustin, thanks for your reply. The NCSSRs were in scope for this audit (specifically version 2.0.3). The audit criteria under "relevant policies" bullet in this bug were directly taken from the audit report (statement of non-conformity). As to why the CAB didn't include the NCSSRs for this specific finding, we're not exactly sure, so KPN has asked the CAB (BSI) for clarification. This might take a few days. Thanks.
| Assignee | ||
Comment 9•9 months ago
|
||
Hi Dustin,
We have gotten a response from BSI (the CAB) regarding the applicability of NetSec in general with regards to this audit finding and together with KPN have made an assessment about the applicability of specific NCCSR requirements. Our questions to BSI and their answer are posted below verbatim accompanied by our our assessment below that.
1. Should NCSSRs be explicitly mentioned in the report for this type of finding?
The audit was conducted as an assertion-based audit, where KPN confirmed compliance with the applicable requirements outlined in the Statement of Applicability and the Overview of Applicability. These requirements include ETSI standards, NCSSRs, and the PKIoverheid Programme of Requirements, among others. For reporting purposes, each non-conformity is referenced against the requirement that most directly addresses the issue. In this case, ETSI EN 319 401 REQ-7.7-01 fully covers the observed condition (unsupported software). Referencing ETSI ensures clarity and consistency in the report, while all applicable criteria were evaluated during the audit.
2. Do you consider this non-conformity a breach of NCSSRs, or is reporting under ETSI sufficient?
The non-conformity also falls under NCSSR obligations (e.g., timely remediation of unsupported components) and PKIOverheid requirements. The audit team reviewed all applicable frameworks as part of the full-scope audit required by, for example, Mozilla Root Store Policy and Microsoft Trusted Root Certificate Program requirements. For reporting purposes, the finding was mapped to ETSI EN 319 401 because it most directly addresses the issue. This does not diminish the relevance of other frameworks, which remain part of the audit scope. In general, a TSP should ensure that any corrective action plan addresses compliance across all obligations.
As to the specific NCCSR criteria applicable to this finding, we’ve concluded that " 4.2 – Vulnerability Management Lifecycle" is applicable in this case. We’ll update this bug accordingly.
| Assignee | ||
Comment 10•8 months ago
|
||
As indicated in our previous post we hereby restate our incident report, now fully reflecting the applicable audit criteria including the NCSSRs. We’ve also updated the end date for the non-compliance based on the status of the action items (all completed) and updated the table to reflect this.
Full Incident Report - ETSI Finding #15 – Outdated Software
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that the CA/VA software used by KPN was out-of-support by the supplier at the time of the audit. This was observed as a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: Jul-2024
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: 26-Nov-2025.
-
-
Relevant policies:
- ETSI 319 401 REQ-7.7-01: The TSP shall use trustworthy systems and products that are protected against modification and ensure the technical security and reliability of the processes supported by them.
- Network and Certificate System Security Requirements section 4.2 – Vulnerability Management Lifecycle: The CA MUST document and follow a vulnerability correction process that includes: 1. identification; 2. review; 3. response; and 4. remediation.
-
Source of incident disclosure: Audit finding by CAB.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates. -
Incident heuristic: N/A
Timeline
-
Jan-2024: A proper LCM plan/upgrade preparation plan was not created for the CA application.
-
Jul-2024: End of support for the then used version of the CA application.
-
11-Jul-2025: Auditor identifies finding.
-
17-Jul-2025: Created Corrective Action Plan.
-
12-Aug-2025: Corrective Action Plan Approved by auditor.
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: Absence of a proper LCM plan/upgrade path
-
Description: The deployment of the CA application was postponed because there was no clear plan in place to manage its upgrade, because the onboarding process for software did not include proper assignment of responsibility.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: N/A
-
What didn’t go well: N/A
-
Where we got lucky: The previous version of the CA software didn’t contain any known security issues.
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Integration of the CA software manufacturer’s release plan of the CA software in the LCM process. | Mitigate | Root Cause #1 | implemented release plan | 2025-10-11 | Completed |
| Add check to update LCM in go-live checklist for new services/applications. | Prevent | Root Cause #1 | Delivered checklist and discussed with operations (report back) | 2025-10-11 | Completed |
Appendix
N/A
| Assignee | ||
Comment 11•8 months ago
|
||
Since the original closure statement was already posted in comment #6 and the discussion about the applicability of the NCSSRs doesn't impact that, we would like to request closure of this bug unless the community or a root store has any questions or concerns. Thanks!
Comment 12•8 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-12-24.
Updated•8 months ago
|
Description
•