Cryptoramic

PKIoverheid G4 migration

PKIoverheid G4 brings RSASSA-PSS. Can your systems validate it?

G4 introduces RSASSA-PSS certificate signatures. Cryptoramic discovers cryptographic algorithms and older PKIoverheid certificates, shows where they were found and flags affected certificates with a migration policy. Start early to investigate dependent systems and resolve incompatibilities before replacement.

Cryptoramic assessment dashboard · Illustrative data, not a G4 test result
Cryptoramic application dashboard showing discovered assets and findings from an illustrative assessment.
Actual application · Illustrative assessment data

RSA support alone does not establish G4 compatibility.

RSASSA-PSS replaces the older PKCS#1 v1.5 signature scheme. Both use RSA, but software must understand and verify the new signature format and its parameters. Check every component that validates certificates, including those accepting certificates from your customers and suppliers.

The validator can be the weak point

An older library, runtime or appliance may reject a PSS-signed certificate even when its RSA key size is supported. Trace validation through applications, middleware and TLS-terminating proxies; each can use a different cryptographic implementation.

New signatures, new trust chains

PSS support does not install the new roots or supply missing intermediates. Check chain building, trust stores and revocation checks separately from signature support.

The application must still accept it

Check the intended certificate profile and key usage. Changed issuer names, subject fields or policy identifiers can also affect application rules, even after cryptographic validation succeeds.

Find the certificates that need to move to G4.

Discover existing certificates across supported sources and use their locations to investigate where they are used. Cryptoramic’s included migration policy flags certificates identified as chaining to superseded PKIoverheid roots, including G3 and G1 Private. Combine these findings with observed connections and available software versions to focus compatibility testing.

From affected certificates to a migration plan
  • DiscoverFind existing certificates, their algorithms and locations.
  • FlagIdentify certificates affected by the G4 transition using policy findings.
  • PrioritizeReview dependent systems, software versions and service owners.
  • TestExercise G4 with the responsible teams and suppliers.
Cryptoramic

Prioritized changes and an agreed verification plan

Start discovery before renewal becomes urgent. Allow time for supplier responses, updates and compatibility tests.

Begin with a service that must keep working.

Bring one application or integration, the certificates it uses and the teams responsible for it. Agree which sources can be inspected and which questions need supplier evidence or a test environment.

Your own certificates

Where are they used, who owns the change, and which renewal or replacement process applies?

Certificates you accept

Which clients, services or signing workflows rely on certificates presented by another organization?

Guidance for your migration

Logius provides the G4 overview and preparation steps, current Dutch transition guidance and migration FAQ. Use these sources and your service provider’s instructions for the applicable certificate profiles and schedule.

For practical context, PKIpartners maintains a migration FAQ, an overview of PKIoverheid applications and a collection of government publications. Logius also publishes G4 trial-certificate tooling.

For compatibility checks, consult Logius guidance on software and TLS. Technical references for the FAQs include PKCS#1 signature schemes and security analysis, PSS signature processing, TLS 1.3 handshake signatures, OpenSSL release history.

Build on the evidence

The inventory you establish for G4 can also inform PQC planning and supplier conversations. Keep observed evidence, supplier statements and test results distinguishable as you plan further changes.

Frequently asked questions

How does Cryptoramic help us prepare for G4?

Cryptoramic finds older PKIoverheid certificates and records where they were found. Its migration policy flags certificates that need attention. Connection details and available software versions help you identify which applications to check. You can then focus testing on those systems, rather than starting with a manual search.

Does TLS 1.3 support mean we are ready for G4?

No. Your software may support TLS 1.3 but still reject a G4 certificate. Setting up a secure connection and checking its certificate are different tasks. Test whether your applications accept the actual G4 certificates and their issuing authorities. Some TLS 1.2 systems can also work with G4 if they support PSS.

What problems could we encounter when switching to G4?

Connections may fail, certificates may be rejected, or users and systems may be unable to sign in. The cause could be older software that cannot check PSS signatures, missing trusted certificates, or application rules that expect the old certificate details. Check the error logs with your software supplier to identify what needs changing.

How do we check whether our applications work with G4?

Use G4 test certificates in an environment that matches your live systems. Test a complete transaction, including any systems between the sender and receiver. If both sides use certificates to identify themselves, test both sides. Keep certificate checks enabled and record the results. Test certificates belong only in test environments; check the live certificates and service requirements before switching production.

Is RSASSA-PSS more secure than PKCS#1 v1.5?

Yes. RSASSA-PSS is designed to provide stronger protection against forged digital signatures than the older method. This does not mean your existing certificates are suddenly unsafe. Before moving to G4, check that your applications support the new signatures.

Could RSASSA-PSS slow down our applications?

PSS does a little more work than the older signature method; it is not designed to be faster. With the same RSA key size, expect similar signing speed, while checking signatures can be somewhat slower. This affects connection setup and document validation, not data transfer over an established TLS connection. For busy services, measure signature checks separately from any other changes made during the migration.

Is RSASSA-PSS already used elsewhere?

Yes. OpenSSL added support for PSS signatures in certificates in version 1.0.1 (March 2012). Version 1.1.1 (September 2018) added PSS for TLS handshakes, including TLS 1.2. TLS 1.3 requires PSS when RSA keys sign the handshake. These are historical milestones, not recommended versions to install. Use a maintained release and test the application with G4 certificates.

Does G4 protect us against quantum computers?

No. G4’s RSA signatures are not quantum-resistant. Moving to G4 and preparing for post-quantum cryptography are separate changes. The certificate inventory you build for G4 can also help you plan your later move to quantum-resistant algorithms.

When do we need to move to G4?

Before your current certificates expire, and by November 2028 at the latest for G3 and G1 Private certificates. A service provider may require an earlier move. Start finding affected certificates and testing now so there is time to resolve software problems before you need replacements.

Which service should we examine first?

Tell us about the application or integration, its owner and your migration question.

Discuss your G4 assessment

Product screenshot

Illustrative assessment data