The Dutch government has taken over operational management from DigiNotar.
govcert.nl
govcert.nl
"On 3 September, the Dutch government has taken over operational management of the DigiNotar systems that are used for certificates."
http://www.govcert.nl/binaries/live/govcert/hst%3Acontent/en...
It also kept all public services depending on Diginotar certificates operational, basically telling the public "well, you can't trust them, but feel free to use them anyway".
"EDIT: Oh, and there's a good reason why the DigiNotar PKIOverheid is now also rejected. The Government cert business was supposed to be on a seperate network, on computers (or data?) stored in a safe. However, there were links between the normal network and the secondary (government) network."
EDIT: Oh, and there's a good reason why the DigiNotar PKIOverheid is now also rejected. The Government cert business was supposed to be on a seperate network, on computers (or data?) stored in a safe. However, there were links between the normal network and the secondary (government) network.
Still not bad, for a government :-)
Two things impressed me the most about how transparently information has been handled: * the most relevant data and fact sheets have been made available in English; * there is a phone support line for public questions.
Not like they could really do any worse. Under previous management they literally allowed the one thing no CA must ever allow to happen.
If you read a bit deeper into their announcements you'll notice that this is not just 'the government taking over'. The breach post-mortem was handled by a private sector security company (Fox IT) and the SSL cert management was moved to another private sector firm (Getronics). Judging by the announcements this was overseen by the Ministry of Security and Justice, which has its own well-funded divisions of security specialists.
The Dutch government sees digital infrastructure as crucial and invests a lot of time and money into it. Components such as PKI government, etc are initiated by the government but then sourced to the private sector (a fairly common practice). This allows the government to revoke contracts or otherwise intervene if the contractor is in breach of something (bad management, bad governance, failure to comply with security standards, failing audits, etc). I'm guessing that this is also the legal basis for taking over operations from DigiNotar at such short notice.
Also, the Dutch government is a world-class player in the eavesdropping, interception, wiretapping and traffic monitoring game. That implies at least a basic in-house competency in network and crypto matters.
It looks like many other bad SSL certs were issued.