Dutch government struggles to deal with DigiNotar hack

Replacing SSL certificates will take time

The Dutch government is trying to minimize the effect of the DigiNotar hack on its IT infrastructure but warned it's a time-consuming process: Not all the SSL certificates can be replaced on the fly.

Piet Hein Donner, minister of the interior, said in a press conference on Tuesday that the government will work as quickly as possible to replace all the DigiNotar SSL certificates in use. However, if the certificates are withdrawn immediately it will be damaging, he warned.

"It particularly concerns the fully automated communication between computers," Donner said. If the certificates are withdrawn right now it would disturb or even block Machine-to-Machine (M2M) communication. That is why the Dutch government chose a "phased and controlled" migration to other certificates. While website certificates should be replaced by Saturday, he said, replacing those involved in M2M communication will take longer.

For the same reason, Microsoft agreed on Tuesday to postpone an automatic software update for the Netherlands that revokes the trust in all DigiNotar certificates for one week. Next week the software update will be rolled out in the Netherlands with an opt-out option. Companies who want to implement the software update this week have to do that themselves. According to Donner this ensures there is no significant disturbance in digital communications in the Netherlands.

On Sept. 2, the Dutch government announced in a night-time press conference, the first in Dutch IT history, that all DigiNotar certificates were to be banned and replaced. According to a report by the security firm Fox-IT published on Monday, 531 fraudulent certificates were issued after DigiNotar was hacked from an Iranian IP address in June. The firm also found proof that the "DigiNotar PKIoverheid CA" certificates the Dutch government uses were compromised. Fox-IT found no evidence that government certificates were misused.

Ronald Prins, CEO of Fox-IT, said on the Dutch television show "Nieuwsuur" on Monday that the real damage for Dutch citizens was limited, but that the implications could have been big. DigiNotar was used for DigiD, an identity management platform used by Dutch government agencies including the Tax and Customs Administration. Hackers could have monitored DigiD traffic and would even be able to manipulate tax filings if they wanted to.

The government replaced the DigiNotar DigiD certificates with PKIoverheid CA certificates from Getronics PinkRoccade, one of the seven (including DigiNotar) SSL certificate providers the government uses. Other problems occurred with the systems of the Rijksdienst voor het Wegverkeer (RDW), which handles vehicle registrations and inspections in the Netherlands. The RDW switched to VeriSign certificates but still has to use DigiNotar for M2M communication, spokesperson Sjoerd Weiland told the Dutch IDG news site Webwereld on Monday.

According to Weiland it is impossible to say when the switch from DigiNotar to another CA can be done. Every business connected to the RDW, including the police and insurance companies, has to switch to new certificates at the same time to prevent the total collapse of all M2M communication. Local governments could have the same problem as the RDW. Minister Donner said there are "some disturbances" in communications between the RDW and local governments.

Dutch financial transactions, Amsterdam's Schiphol airport and the national railways were not affected. "Although several sectors are meanwhile suffering from disruptions, major uncontrollable problems have not appeared to date," Minister Donner and Minister Ivo Opstelten of Public Safety and Justice stated in a letter to the lower house of Parliament. In total DigiNotar issued 57,956 certificates in different sectors in the Netherlands.

Because DigiNotar was hacked in June and the company knew about the hack shortly afterward but did not inform the Dutch government, the attorney general has begun an investigation to determine if DigiNotar can be held formally responsible for the ongoing crisis. Telecom watchdog OPTA is also investigating DigiNotar. That investigation is aimed at the way the certificates were issued.

Join the PC World newsletter!

Error: Please check your email address.

Tags intrusionsecuritygovernmentDigiNotar

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Loek Essers

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?