PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #16 – EJBCA Configuration
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: EJBCA Configuration Not in Line with Documented Profile
- Relevant Policies:
- ETSI 411-1 (GEN-6.3.3-01)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #16 – EJBCA Configuration
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that certain certificate profiles implemented by KPN were not in line with the CP/CPS (Programme of Requirements PKIoverheid/CPS KPN B.V.). This was noted as a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: 6-Jun-2025
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing.
-
-
Relevant policies:
-
PKIoverheid Programme of Requirements (Certificate Policy) appendix: Certificate Profiles.
-
ETSI EN 319 411-1 GEN-6.3.3-01: The CA shall issue certificates securely to maintain their authenticity.
-
-
Source of incident disclosure: Audit finding by CAB.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates.
Timeline
-
6-Jun-2025: Profile change documented and partially implemented.
-
11-Jul-2025: Auditor identifies finding
-
17-Jul-2025: Created Corrective Action Plan
-
12-Aug-2025: Corrective Action Plan Approved by auditor
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: No integrated check on profile configuration changes.
-
Description: No integrated check on profile configuration changes across different applications (CA and CMS). A change which was initially processed in the CA software was scheduled to be changed in the CMS. In the meantime, the change in the CA software was reversed in another scheduled check. These checks therefore need to be integrated.
-
Timeline: N/A
-
Detection: Audit finding.
-
Interaction with other factors: No
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: N/A
-
What didn’t go well: N/A
-
Where we got lucky: No impact on issued actual issued certificates.
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Improve work instruction for profile changes. Include in the work instruction a check to ensure that CA application, CMS application and the profile document are aligned at all times. | Prevent | Root Cause #1 | N/A | 2025-10-11 | In progress |
| Check periodically the alignment of profile configurations in CA application, CMS application and the profile document. | Detect | Root Cause #1 | Periodic reporting for next (internal) audit | 2025-10-11 | In progress |
| Correct profile configuration. | Mitigate | Root Cause #1 | Certificate profiles aligned between CA and CMS | 2025-10-11 | Completed |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.
| Assignee | ||
Comment 3•11 months ago
|
||
A small update from our end:
- Action items #1 are currently still in progress but we've incurred a small delay. As seen with other action items the amount of work needed turned out to be more than initially foreseen.
- As indicated earlier action item #3 had been completed previously.
With that, the status is as follows:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Improve work instruction for profile changes. Include in the work instruction a check to ensure that CA application, CMS application and the profile document are aligned at all times. | Prevent | Root Cause #1 | N/A | 2025-10-25 | In progress |
| Check periodically the alignment of profile configurations in CA application, CMS application and the profile document. | Detect | Root Cause #1 | reporting for next (internal) audit | 2025-10-25 | In progress |
| Correct profile configuration. | Mitigate | Root Cause #1 | Certificate profiles aligned between CA and CMS | 2025-10-11 | Completed |
| Assignee | ||
Comment 4•10 months ago
|
||
Both action item #1 and #2 have been completed. With that, all open Action items have been completed. A closure request will be submitted by Logius in a few days, but in the meantime we're open to questions and/or comments that people might have. Thanks.
| Assignee | ||
Comment 5•10 months ago
|
||
Report Closure Summary
- Incident description: The CAB noted that certain certificate profiles implemented by KPN were not in line with the CP/CPS (Programme of Requirements PKIoverheid/CPS KPN B.V.). This was noted as a minor non-conformity.
- Incident Root Cause(s): No integrated check on profile configuration changes across different applications (CA and CMS). A change which was initially processed in the CA software was scheduled to be changed in the CMS. In the meantime, the change in the CA software was reversed in another scheduled check. These checks therefore need to be integrated.
- Remediation description: KPN has taken steps to ensure consistency in certificate profile configurations. This includes correction of the profile configuration to align the CA and CMS applications, update of the work instruction for certificate profile changes to include a verification step ensuring alignment between the CA application, CMS application, and the profile document and implementing a periodic check to monitor and report on profile alignment.
- Commitment summary: KPN commits to maintaining alignment between certificate profiles and system configurations. Periodic reviews and updated work instructions support consistency. Additionally, KPN will assess tooling options to further automate profile validation and reduce manual errors.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 6•10 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-11-19.
Updated•9 months ago
|
Description
•