Closed Bug 1983276 Opened 1 year ago Closed 9 months ago

PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #16 – EJBCA Configuration

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pkioverheid, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: EJBCA Configuration Not in Line with Documented Profile
  • Relevant Policies:
    • ETSI 411-1 (GEN-6.3.3-01)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → pkioverheid
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Full Incident Report - ETSI Finding #16 – EJBCA Configuration

Summary

  • CA Owner CCADB unique ID: A000068

  • Incident description: The CAB noted that certain certificate profiles implemented by KPN were not in line with the CP/CPS (Programme of Requirements PKIoverheid/CPS KPN B.V.). This was noted as a minor non-conformity.

  • Timeline summary:

    • Non-compliance start date: 6-Jun-2025

    • Non-compliance identified date: 11-Jul-2025

    • Non-compliance end date: Ongoing.

  • Relevant policies:

    • PKIoverheid Programme of Requirements (Certificate Policy) appendix: Certificate Profiles.

    • ETSI EN 319 411-1 GEN-6.3.3-01: The CA shall issue certificates securely to maintain their authenticity.

  • Source of incident disclosure: Audit finding by CAB.

Impact

  • Total number of certificates: N/A

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: N/A

  • Incident heuristic: N/A

  • Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)

  • Analysis: N/A

  • Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU emailProtection were no longer included in publicly trusted certificates.

Timeline

  • 6-Jun-2025: Profile change documented and partially implemented.

  • 11-Jul-2025: Auditor identifies finding

  • 17-Jul-2025: Created Corrective Action Plan

  • 12-Aug-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

Contributing Factor 1: No integrated check on profile configuration changes.

  • Description: No integrated check on profile configuration changes across different applications (CA and CMS). A change which was initially processed in the CA software was scheduled to be changed in the CMS. In the meantime, the change in the CA software was reversed in another scheduled check. These checks therefore need to be integrated.

  • Timeline: N/A

  • Detection: Audit finding.

  • Interaction with other factors: No

  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A

  • What didn’t go well: N/A

  • Where we got lucky: No impact on issued actual issued certificates.

  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Improve work instruction for profile changes. Include in the work instruction a check to ensure that CA application, CMS application and the profile document are aligned at all times. Prevent Root Cause #1 N/A 2025-10-11 In progress
Check periodically the alignment of profile configurations in CA application, CMS application and the profile document. Detect Root Cause #1 Periodic reporting for next (internal) audit 2025-10-11 In progress
Correct profile configuration. Mitigate Root Cause #1 Certificate profiles aligned between CA and CMS 2025-10-11 Completed

Appendix

N/A

PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.

A small update from our end:

  • Action items #1&#2 are currently still in progress but we've incurred a small delay. As seen with other action items the amount of work needed turned out to be more than initially foreseen.
  • As indicated earlier action item #3 had been completed previously.

With that, the status is as follows:

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Improve work instruction for profile changes. Include in the work instruction a check to ensure that CA application, CMS application and the profile document are aligned at all times. Prevent Root Cause #1 N/A 2025-10-25 In progress
Check periodically the alignment of profile configurations in CA application, CMS application and the profile document. Detect Root Cause #1 reporting for next (internal) audit 2025-10-25 In progress
Correct profile configuration. Mitigate Root Cause #1 Certificate profiles aligned between CA and CMS 2025-10-11 Completed

Both action item #1 and #2 have been completed. With that, all open Action items have been completed. A closure request will be submitted by Logius in a few days, but in the meantime we're open to questions and/or comments that people might have. Thanks.

Report Closure Summary

  • Incident description: The CAB noted that certain certificate profiles implemented by KPN were not in line with the CP/CPS (Programme of Requirements PKIoverheid/CPS KPN B.V.). This was noted as a minor non-conformity.
  • Incident Root Cause(s): No integrated check on profile configuration changes across different applications (CA and CMS). A change which was initially processed in the CA software was scheduled to be changed in the CMS. In the meantime, the change in the CA software was reversed in another scheduled check. These checks therefore need to be integrated.
  • Remediation description: KPN has taken steps to ensure consistency in certificate profile configurations. This includes correction of the profile configuration to align the CA and CMS applications, update of the work instruction for certificate profile changes to include a verification step ensuring alignment between the CA application, CMS application, and the profile document and implementing a periodic check to monitor and report on profile alignment.
  • Commitment summary: KPN commits to maintaining alignment between certificate profiles and system configurations. Periodic reviews and updated work instructions support consistency. Additionally, KPN will assess tooling options to further automate profile validation and reduce manual errors.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2025-11-19.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2025-11-19] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 9 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2025-11-19] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.