DigiCert: WTCA / WTBR Audit 2019 - Matters to be resolved
This case tracks matters identified in DigiCert’s WebTrust (WTCA/WTBR) Audit 2019 that were not already covered by existing Bugzilla bugs. DigiCert provided updated WTCA and WTBR audit information and asked that this bug be used to capture incident-report style items for matters that did not already have corresponding bugs. DigiCert responded with management resolutions for multiple audit “matters,” including implementing automated log auditing and real-time review with monthly tickets to document log review, instituting quarterly system access reviews to include application level access, and addressing vulnerability report archival traceability concerns. For one ICA-related item (#5), DigiCert later stated that the interpretation behind issuing it was wrong and revoked the ICA, providing a crt.sh link and a revocation date of 2020-03-26. Ryan Sleevi and Brenda Bernal discussed clarifications on the audit resolutions, and Kathleen A. Wilson confirmed the ICA revocation and that it was indicated in the CCADB as Ready to Add to OneCRL. Kathleen then closed the bug as fixed, stating that the other items had been sufficiently addressed as well.
- WebTrust audit closed (engagement period ended).
- DigiCert initiated this bug to document and resolve audit matters not already covered by other Bugzilla bugs.
- DigiCert provided management responses and resolutions for multiple audit matters, including log review, system access, and vulnerability report archival.
- DigiCert revoked the ICA associated with audit item #5.
- DigiCert reported the revocation details and link for the revoked ICA.
- Mozilla-side confirmation that the certificate was revoked and CCADB status updated; bug closed as fixed.
- Community commenter — Requested that this bug be used to provide incident-report information for audit matters not already having corresponding Bugzilla bugs.
- DigiCert — Provided management responses and resolutions for multiple WebTrust audit matters, noting which items were closed and which remained pending.
- Community commenter — Asked for clarification on how DigiCert’s stated resolutions related to the audit emphasis items, including offline logs, system access, and vulnerability report archival.
- DigiCert — Answered Ryan’s questions with additional details for offline logs, system access, vulnerability report archival, and clientAuth certificate issues, and provided updates for other numbered items.
- DigiCert — Stated that the interpretation behind issuing item #5 was wrong and that the ICA was revoked.
- DigiCert — Confirmed revocation of the ICA for item #5, provided a crt.sh link, and gave the revocation date as 2020-03-26.
- Mozilla representative — Confirmed the cert was revoked and indicated in the CCADB as Ready to Add to OneCRL, and closed the bug as fixed.