EDIT: Oh, and there's a good reason why the DigiNotar PKIOverheid is now also rejected. The Government cert business was supposed to be on a seperate network, on computers (or data?) stored in a safe. However, there were links between the normal network and the secondary (government) network.
It also kept all public services depending on Diginotar certificates operational, basically telling the public "well, you can't trust them, but feel free to use them anyway".
"EDIT: Oh, and there's a good reason why the DigiNotar PKIOverheid is now also rejected. The Government cert business was supposed to be on a seperate network, on computers (or data?) stored in a safe. However, there were links between the normal network and the secondary (government) network."
Still not bad, for a government :-)
Two things impressed me the most about how transparently information has been handled: * the most relevant data and fact sheets have been made available in English; * there is a phone support line for public questions.