Firmaprofesional: 2020 Audit Report Finding 1 out of 4
This case concerns an audit finding from Firmaprofesional’s March 2020 eIDAS audit. The finding stated that the CA’s CPS could not be evidenced to include required information about how revocation status information is made available beyond the validity period of qualified certificates, including how it is provided in cases of CA key compromise or TSP termination. Firmaprofesional said it registered the non-conformity in its JIRA on 2020-04-14 and established an action plan, and it studied the ETSI obligations on 2020-04-16. The CA stated that it planned to issue a “lastCRL” containing revoked certificates regardless of whether they are expired, and that the CPS would be updated with the relevant revocation-status mechanisms. In the thread, Mozilla asked why the incident was not reported earlier and Firmaprofesional responded that the final audit report was not received until June due to COVID-19 workload, and that it had created a preventive Jira ticket earlier. Firmaprofesional later provided links to the updated CPS and described changes, including a procedure for generating the last CRL in cases of key compromise or termination of service. Mozilla indicated the audit finding had been addressed in the CPS and intended to close the bug around 17-Sep-2020, while also requesting an additional CPS statement about notifying root stores immediately upon discovery of key compromise or similar vulnerabilities.
- Firmaprofesional’s March 2020 eIDAS audit identified a CPS non-conformity related to revocation status information beyond certificate validity and in key-compromise/TSP-termination scenarios.
- Firmaprofesional registered the non-conformity in its JIRA and established an action plan.
- Firmaprofesional studied the ETSI obligations related to the finding.
- Firmaprofesional detailed the actions it planned to take, including issuing a lastCRL and updating the CPS.
- The bug was opened with the audit finding summary.
- Firmaprofesional published an updated CPS and described changes, including procedures for generating a last CRL.
- Mozilla stated the audit finding was addressed and planned closure, with an additional CPS notification requirement to add.
- Isigma representative — Opened the bug describing the annual audit finding and quoted the CPS revocation-status information gaps identified by auditors.
- Community commenter — Asked why an incident was not reported until 2020-06-30 and referenced Mozilla’s incident-reporting guidance.
- Autoridad de Certificacion Firmaprofesional — Explained that the final eIDAS audit report was received in June due to COVID-19 circumstances and said a preventive Jira ticket was created earlier.
- Community commenter — Pressed for clarification on why Mozilla and other root stores were not notified when the Jira ticket was created.
- Isigma representative — Responded that they waited for the final report because findings can be non-conformities or observations/improvement opportunities, and stated they would update the CPS this week.
- Isigma representative — Provided URLs to the updated Firmaprofesional CPS and listed changes, including a procedure for generating the last CRL in key-compromise or termination-of-service cases.
- Mozilla representative — Said the audit finding was addressed in the CPS and intended to close the bug around 17-Sep-2020, while requesting an additional CPS statement about notifying root stores immediately upon discovery of key compromise or similar vulnerabilities.