← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1612929 CCADB Compliance

Firmaprofesional: 2019 audit Finding #2 - 6.4 Facility, management, and operational controls

RESOLVED FIXED Autoridad de Certificacion Firmaprofesional
AI Summary

The case addresses an audit finding related to Firmaprofesional's management and operational controls. The audit revealed that auditors lacked sufficient access to review logs, which was a non-conformity noted prior to the eIDAS audit in March 2019. Firmaprofesional has since taken steps to rectify this by creating an auditor role with read-only access to logs in their CA software, EJBCA. They are also implementing a centralized log management system using Elastic Stack to enhance security and compliance. The issue has been resolved, and the CA continues to issue certificates without impact from this finding.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Confidence: 0.95
Chronology
  1. Non Conformity registered in JIRA and action plan established.
  2. Issue presented to steering committee; project initiated for centralized log management.
  3. Auditor role created in EJBCA.
  4. Audit role delivered to personnel.
  5. Remediation confirmed complete.
Participants
chemalogo@isigma.es ryan.sleevi@gmail.com wthayer@fastly.com
External References
Similar Local Cases
#1588213 RESOLVED CCADB Compliance Opened 2019-10-11 · Closed 2024-06-30 · 55% similar
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports
#1455053 RESOLVED CCADB Compliance Opened 2018-04-18 · Closed 2022-11-14 · 55% similar
Add some Firmaprofesional SubCAs to OneCRL
#1771724 RESOLVED CCADB Compliance Opened 2022-05-30 · Closed 2023-02-22 · 49% similar
Firmaprofesional: 2022 - CPS without correct explanation about difference between OCSP and CRL
#1717795 RESOLVED CCADB Compliance Opened 2021-06-23 · Closed 2023-02-22 · 49% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#2025536 RESOLVED CCADB Compliance Opened 2026-03-23 · Closed 2026-04-15 · 48% similar
Firmaprofesional: Delayed initial incident reporting for Bug 2016475 (72-hour preliminary and 14-day full report timing)
#1838864 RESOLVED CCADB Compliance Opened 2023-06-16 · Closed 2023-07-14 · 48% similar
Firmaprofesional: Failure to Respond to April 2023 Survey
#1610000 RESOLVED CCADB Compliance Opened 2020-01-17 · Closed 2023-02-22 · 48% similar
SSL.com: Intermediate certificate not listed in audit reports
#1652827 RESOLVED CCADB Compliance Opened 2020-07-14 · Closed 2024-06-30 · 48% similar
Microsoft PKI Services: Incomplete Logical Access Review Audit Evidence

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action