Dutch government struggles with DigiNotar hack
Replacing SSL certificates will take time
IDG News Service - The Dutch government is trying to minimize the effect of the DigiNotar hack on its IT infrastructure but warned it's a time-consuming process: Not all the SSL certificates can be replaced on the fly.
Piet Hein Donner, minister of the interior, said in a press conference on Tuesday that the government will work as quickly as possible to replace all the DigiNotar SSL certificates in use. However, if the certificates are withdrawn immediately it will be damaging, he warned.
"It particularly concerns the fully automated communication between computers," Donner said. If the certificates are withdrawn right now it would disturb or even block Machine-to-Machine (M2M) communication. That is why the Dutch government chose a "phased and controlled" migration to other certificates. While website certificates should be replaced by Saturday, he said, replacing those involved in M2M communication will take longer.
For the same reason, Microsoft agreed on Tuesday to postpone an automatic software update for the Netherlands that revokes the trust in all DigiNotar certificates for one week. Next week the software update will be rolled out in the Netherlands with an opt-out option. Companies who want to implement the software update this week have to do that themselves. According to Donner this ensures there is no significant disturbance in digital communications in the Netherlands.
On Sept. 2, the Dutch government announced in a night-time press conference, the first in Dutch IT history, that all DigiNotar certificates were to be banned and replaced. According to a report by the security firm Fox-IT published on Monday, 531 fraudulent certificates were issued after DigiNotar was hacked from an Iranian IP address in June. The firm also found proof that the "DigiNotar PKIoverheid CA" certificates the Dutch government uses were compromised. Fox-IT found no evidence that government certificates were misused.
Ronald Prins, CEO of Fox-IT, said on the Dutch television show "Nieuwsuur" on Monday that the real damage for Dutch citizens was limited, but that the implications could have been big. DigiNotar was used for DigiD, an identity management platform used by Dutch government agencies including the Tax and Customs Administration. Hackers could have monitored DigiD traffic and would even be able to manipulate tax filings if they wanted to.
The government replaced the DigiNotar DigiD certificates with PKIoverheid CA certificates from Getronics PinkRoccade, one of the seven (including DigiNotar) SSL certificate providers the government uses. Other problems occurred with the systems of the Rijksdienst voor het Wegverkeer (RDW), which handles vehicle registrations and inspections in the Netherlands. The RDW switched to VeriSign certificates but still has to use DigiNotar for M2M communication, spokesperson Sjoerd Weiland told the Dutch IDG news site Webwereld on Monday.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Federal IT Innovation Caught in a Catch-22 Fed resources shoring up old infrastructure, holding back new technologies.
- Five Ways that Identity Federation is Improving Online Security for Government Agencies Cloud computing, social networking and mobile devices are improving efficiency and collaboration in the public sector. But anytime, anywhere accessibility also increases the...
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Government/Industries White Papers | Webcasts