Camerfirma: audit gap
This case concerns an audit coverage gap for Camerfirma’s CCADB audit updates. Camerfirma said it tried to update its audits in the Common CA Database (CCADB) to close the related case (00000435), but could not because there was a 25-day gap between the two most recent audit reports. Camerfirma explained that it covered the period until April 14, 2018 using WebTrust audits performed in 2017 for Standard Audit and for BR and EV SSL Audit, but did not cover the period from April 14, 2018 to May 8, 2018 for BR and EV SSL Audit under the ETSI EN 319 411 (eIDAS) scheme. Camerfirma stated that the gap occurred because major non-conformities were detected during the eIDAS audit and had to be solved before obtaining a favourable report and certification, and that those non-conformities were already solved before May 8, 2018 when the auditors issued the certificate of compliance. Mozilla staff helped Camerfirma identify that the 25-day gap was the reason it could not update the audits in CCADB. The bug was resolved as FIXED, and a later comment noted there is no way to remediate this issue short of distrusting all roots with missing audit coverage, while also stating the questions had been answered.
- WebTrust audits were performed for Standard Audit and for BR and EV SSL Audit (as referenced by Camerfirma).
- Camerfirma’s covered audit period ended for Standard Audit/BR/EV SSL under the prior WebTrust coverage (as referenced by Camerfirma).
- Auditors issued the certificate of compliance for the eIDAS/ETSI EN 319 411 BR and EV SSL audit after non-conformities were resolved (as referenced by Camerfirma).
- Camerfirma opened the bug after being unable to update audit information in CCADB due to the 25-day audit gap.
- AC Camerfirma, S.A. — Camerfirma reported it could not update audits in CCADB to close case 00000435 due to a 25-day gap between audit reports and described the eIDAS/ETSI EN 319 411 non-conformities that caused the gap.
- Community commenter — Ryan Sleevi asked whether Camerfirma anticipated issues, whether it took steps beforehand (e.g., parallel audits), and why management did not discuss such a process.
- AC Camerfirma, S.A. — Camerfirma answered that it did not anticipate issues, did not run parallel audits because it would be expensive, and did not discuss the process because it was not conscious of the possible impact.
- Fastly representative — W. Thayer stated there is no way to remediate the issue short of distrusting all roots with missing audit coverage, and resolved the bug after indicating the questions had been answered.