Guidance for your migration
Logius provides the G4 overview and preparation steps, current Dutch transition guidance and migration FAQ. Use these sources and your service provider’s instructions for the applicable certificate profiles and schedule.
For practical context, PKIpartners maintains a migration FAQ, an overview of PKIoverheid applications and a collection of government publications. Logius also publishes G4 trial-certificate tooling.
For compatibility checks, consult Logius guidance on software and TLS. Technical references for the FAQs include PKCS#1 signature schemes and security analysis, PSS signature processing, TLS 1.3 handshake signatures, OpenSSL release history.
Build on the evidence
The inventory you establish for G4 can also inform PQC planning and supplier conversations. Keep observed evidence, supplier statements and test results distinguishable as you plan further changes.
Frequently asked questions
How does Cryptoramic help us prepare for G4?
Cryptoramic finds older PKIoverheid certificates and records where they were found. Its migration policy flags certificates that need attention. Connection details and available software versions help you identify which applications to check. You can then focus testing on those systems, rather than starting with a manual search.
Does TLS 1.3 support mean we are ready for G4?
No. Your software may support TLS 1.3 but still reject a G4 certificate. Setting up a secure connection and checking its certificate are different tasks. Test whether your applications accept the actual G4 certificates and their issuing authorities. Some TLS 1.2 systems can also work with G4 if they support PSS.
What problems could we encounter when switching to G4?
Connections may fail, certificates may be rejected, or users and systems may be unable to sign in. The cause could be older software that cannot check PSS signatures, missing trusted certificates, or application rules that expect the old certificate details. Check the error logs with your software supplier to identify what needs changing.
How do we check whether our applications work with G4?
Use G4 test certificates in an environment that matches your live systems. Test a complete transaction, including any systems between the sender and receiver. If both sides use certificates to identify themselves, test both sides. Keep certificate checks enabled and record the results. Test certificates belong only in test environments; check the live certificates and service requirements before switching production.
Is RSASSA-PSS more secure than PKCS#1 v1.5?
Yes. RSASSA-PSS is designed to provide stronger protection against forged digital signatures than the older method. This does not mean your existing certificates are suddenly unsafe. Before moving to G4, check that your applications support the new signatures.
Could RSASSA-PSS slow down our applications?
PSS does a little more work than the older signature method; it is not designed to be faster. With the same RSA key size, expect similar signing speed, while checking signatures can be somewhat slower. This affects connection setup and document validation, not data transfer over an established TLS connection. For busy services, measure signature checks separately from any other changes made during the migration.
Is RSASSA-PSS already used elsewhere?
Yes. OpenSSL added support for PSS signatures in certificates in version 1.0.1 (March 2012). Version 1.1.1 (September 2018) added PSS for TLS handshakes, including TLS 1.2. TLS 1.3 requires PSS when RSA keys sign the handshake. These are historical milestones, not recommended versions to install. Use a maintained release and test the application with G4 certificates.
Does G4 protect us against quantum computers?
No. G4’s RSA signatures are not quantum-resistant. Moving to G4 and preparing for post-quantum cryptography are separate changes. The certificate inventory you build for G4 can also help you plan your later move to quantum-resistant algorithms.
When do we need to move to G4?
Before your current certificates expire, and by November 2028 at the latest for G3 and G1 Private certificates. A service provider may require an earlier move. Start finding affected certificates and testing now so there is time to resolve software problems before you need replacements.
