← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1717790 Ca Certificate Compliance Incident Self Reported Incident

Firmaprofesional: 2021 Audit Report Finding 1 out of 3

RESOLVED FIXED Autoridad de Certificacion Firmaprofesional
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents a finding identified in Firmaprofesional’s annual eIDAS audit carried out in March 2021 (29th). The finding states that the existence of a user exercising a trusted role (System Administrator) was evidenced without proof of the formal assignment and acceptance of that role. Firmaprofesional said the issue was registered in its JIRA on 2021-04-08 and that an action plan was established after studying the ETSI obligations. As remediation, Firmaprofesional modified the process “PR101-Human Resources” on 2021-04-08 to require each manager to validate the correct assignment and acceptance of the role before it becomes effective and permissions/credentials are delivered. Firmaprofesional stated that the new process was validated by its Human Resources Director on 2021-04-28 and that new personnel incorporations already follow the requirement. The bug was resolved as FIXED, and Mozilla participant guidance in the thread focused on the incident reporting expectations and the need for more substantive incident reporting, including how the process allowed the issue to be missed until the auditor detected it. Firmaprofesional responded that the Security Officer is the only person who can grant such a role and described procedural changes intended to prevent recurrence by improving communication between departments (HR and the technical/security side).

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.86 6 comments
Chronology
  1. Firmaprofesional’s annual eIDAS audit identified a finding about missing evidence of formal assignment and acceptance for a trusted System Administrator role.
  2. Firmaprofesional registered the finding in JIRA and established an action plan, then modified its PR101-Human Resources process to require validation of role assignment and acceptance.
  3. Firmaprofesional validated the updated HR process with its Human Resources Director.
  4. The CA Program bug was created to report the audit finding (resolved later as FIXED).
Thread Activity
  1. Autoridad de Certificacion Firmaprofesional — Submitted the incident report describing the eIDAS audit finding and Firmaprofesional’s remediation steps, including the PR101-Human Resources process change and validation date.
  2. Community commenter — Commented that this was the third consecutive year of audit findings and asked for more substance, including why it was not reported timely and what the full issue was.
  3. Autoridad de Certificacion Firmaprofesional — Responded to the request for more substance, stating the Security Officer is the only person who can grant the role and describing how notification timing and evidence were handled.
  4. Community commenter — Further emphasized that future suspected incidents should be disclosed transparently and asked how the process went wrong to allow the issue to be missed until the auditor detected it.
  5. Autoridad de Certificacion Firmaprofesional — Provided additional explanation of how logs/records are managed and described a redesigned procedure to improve communication between HR and the security/technical side to prevent recurrence.
  6. Mozilla representative — Stated there were no further suggestions and that the bug would be scheduled to close on or about 13-Aug-2021.
Participants
Autoridad de Certificacion Firmaprofesional Community commenter Mozilla representative
Similar Local Cases
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 92% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1769240 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-13 · Closed 2023-02-22 · 86% similar
Firmaprofesional: 2022 - SSL certificates issued with wrong Organization ID number
#1771722 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-30 · Closed 2023-02-22 · 85% similar
Firmaprofesional: 2022 - Title field
#1771715 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-30 · Closed 2023-02-22 · 83% similar
Firmaprofesional: 2022 - StateorProvince field
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 76% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1368171 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-26 · Closed 2024-06-30 · 75% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1771724 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2022-05-30 · Closed 2023-02-22 · 75% similar
Firmaprofesional: 2022 - CPS without correct explanation about difference between OCSP and CRL
#1398240 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 74% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action