Swisscom: Missing Audits for Unconstrained Intermediate Certificates
This case concerns Swisscom failing to supply required audit information in the Common CA Database (CCADB) for several intermediate CA certificates. The issue was raised because the audit information was missing for the listed intermediates, which Swisscom was expected to provide under section 5.3 of the Mozilla root store policy. The reporter requested that Swisscom add the audit information to CCADB and provide an incident report as described in Mozilla’s misissuance response guidance. Swisscom acknowledged the request, stated it was awaiting an audit report (scheduled for mid-June 2018), and said the audit would cover specific issuing CAs, including some that were no longer active. Swisscom later uploaded a statement to the bug (referenced as an attachment) and asked that it be added to the root CA record. The reporter subsequently stated the audit report was deficient because it listed only one version of the Diamant CA and only one version of the Rubin CA 2, despite multiple versions existing, and requested that future audit statements include all certificates, listing duplicates separately. The bug is marked RESOLVED with resolution FIXED.
- Swisscom was reported as missing required audit information in CCADB for multiple intermediate CA certificates.
- Swisscom acknowledged the gap and said it was awaiting an audit report scheduled for mid-June 2018.
- Swisscom uploaded a statement intended to be added to the root CA record.
- The submitted audit report was challenged as deficient due to missing certificate versions.
- Fastly representative — Reported that Swisscom failed to supply CCADB audit information for specific intermediate CA certificates as required by section 5.3, and requested CCADB updates plus an incident report posted to the mozilla.dev.security.policy forum and added to the bug.
- Swisscom representative — Acknowledged the request, said Swisscom was awaiting an audit report for mid-June 2018, and listed the issuing CAs covered by the audit along with intermediates that were no longer active.
- Fastly representative — Asked that the audit report include all information required by section 3.1.4 and requested the full incident report, also questioning expiration/revocation timing for the non-active intermediates.
- Swisscom representative — Uploaded a statement (attachment) and asked that it be added to the root CA record.
- Fastly representative — Said the audit report was deficient because it listed only one version of the Diamant CA and only one version of Rubin CA 2, and requested future audit statements include all certificates including duplicates separately.