← SwissSign AG cases
Bugzilla #1374381 Policy Compliance

SwissSign: BRs require full annual audits

RESOLVED FIXED SwissSign AG
AI Summary

The case addresses SwissSign AG's compliance with Mozilla's Baseline Requirements (BRs) for annual audits. SwissSign submitted an audit statement that raised concerns regarding its adequacy, particularly regarding the terminology used and the scope of the audit. Issues included the use of 'point-in-time' audits, which do not meet the BRs' requirement for full annual audits. After discussions, SwissSign provided updated audit statements, but complications arose regarding the coverage of all included roots. The case was ultimately resolved with the acceptance of the updated audits, although concerns about continuity and compliance with Mozilla's policies were highlighted.

Model: gpt-4o-mini Generated: 2026-06-13 15:01 UTC Confidence: 0.90
Chronology
  1. Initial audit statement submitted by SwissSign.
  2. SwissSign responds to concerns about audit terminology.
  3. New audit reports submitted for review.
  4. Bug reopened due to concerns about audit compliance.
Participants
Kathleen Wilson Reinhard Dietrich Cornelia Enke Ryan Sleevi Wayne Thayer Gervase Markham
Similar Local Cases
#1391066 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 72% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1586125 RESOLVED Policy Compliance Opened 2019-10-03 · Closed 2024-06-30 · 64% similar
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 63% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1575530 RESOLVED Policy Compliance Opened 2019-08-21 · Closed 2023-02-22 · 62% similar
Camerfirma: Govern d'Andorra audits
#1391054 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 61% similar
Izenpe: Non-BR-Compliant Certificate Issuance
#1397830 RESOLVED Policy Compliance Opened 2017-09-07 · Closed 2023-02-22 · 60% similar
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
#1315018 RESOLVED Policy Compliance Opened 2016-11-03 · Closed 2022-11-14 · 59% similar
SHA-1 issuance by GlobalSign root
#1230797 RESOLVED Policy Compliance Opened 2015-12-06 · Closed 2022-11-14 · 58% similar
Distrust ISRG Subordinate Certificate and Remove It Until the CA is Compliant with Mozilla Policies

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action