SwissSign: Audit Letter Validation failures on intermediate certificates
This case was filed regarding SwissSign AG’s intermediate certificates after Mozilla’s Audit Letter Validation (ALV) reported failures. The reporter noted that SwissSign had responded to Action 5 of Mozilla’s January 2020 CA Communication survey stating it had no audit issues with its intermediate certificates identified by CCADB, but ALV indicated that the CA needed to investigate and resolve the listed problems. The ALV results included an Audit Letter Validation failure for the certificate “SwissSign Personal Platinum CA 2014 - G22,” identified by its SHA-256 fingerprint. The bug was then closed with the explanation that the certificate was already listed in the audit statement, and that SwissSign only needed to ensure the next annual audit statement followed the formatting guidelines for SHA-256 fingerprints. The bug’s resolution is WORKSFORME and it is marked RESOLVED.
- Bug filed by a Mozilla CA Program participant regarding ALV-reported validation failures for SwissSign AG intermediate certificates.
- Bug closed after confirming the certificate was listed in the audit statement and noting formatting requirements for the next annual audit statement.
- Assigned CA contact confirmed closure and cleared the needinfo flag.
- Community commenter — Filed the bug stating ALV reported Audit Letter Validation failures for SwissSign intermediate certificates that the CA said had no audit issues in its January 2020 survey response.
- Community commenter — Closed the bug, stating the certificate is listed in the audit statement and the CA should ensure the next annual audit statement follows the CCADB formatting guidelines for SHA-256 fingerprints.
- SwissSign AG — Commented that the bug was closed by Kathleen and that the needinfo flag was cleared.