SwissSign: Missed deadline of publication of 6 CPs and 1 CP/CPS
SwissSign reported that, ahead of its yearly audit in September, it realized its CPs for DV, OV, EV, LCP, NCP, and NCPextended were older than 365 days, and that its SwissSign Platinum CP/CPS (legacy root) was also last published on 2021-06-14. The CA stated that it reviewed its public documents (TSPS, CPS, CPR, and CP) on 2022-08-15 and started a TSP document process using a “6 eye principle” to update the CPs and finalize the Platinum CP/CPS. SwissSign published the updated documents on 2022-08-15 and also published the incident report the same day. The CA said no certificates were affected by this incident. SwissSign attributed the issue to missing alarms after a change from one CP/CPS per root to a TSPS document set, which prevented static CPs from being reviewed since 2021-06-14. For remediation, it reported adding next publish dates to an internal management overview page, setting alarms in a group calendar, and creating a bi-monthly internal audit to check for “elapsing” TSP documents; it also discussed adding CCADB reflection checks to the internal audit and noted CCADB workflow issues that delayed showing correct dates until a root store operator review. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it would be closed on 2022-12-07 unless further discussion was needed.
- SwissSign last published its CPs (including the SwissSign Platinum CP/CPS) on this date.
- SwissSign reviewed its public policy documents, updated them, and published the updated CPs/CP-CPS and the incident report.
- Mozilla indicated the CCADB workflow was pending root store operator review and that the bug would be closed on 2022-12-07 unless further discussion was needed.
- SwissSign AG — SwissSign explained it discovered its CPs/CP-CPS were older than 365 days, provided a timestamped remediation timeline, stated no certificates were affected, and described root cause and planned improvements (alarms, internal audit, and publish-date tracking).
- Google representative — Chris Clements asked about the cadence of the bi-monthly internal audit and whether it includes checking that updated policy documents are reflected in CCADB.
- SwissSign AG — Mike Guenther clarified the audit occurs every second month and said the internal audit would be updated to include CCADB reflection checks using the newer CCADB workflow approach.
- Google representative — Chris Clements referenced the relevant CCADB workflow as the “Add/Update Root Request.”
- SwissSign AG — Mike Guenther said the internal audit was already conducted and CCADB updates were in process but delayed due to a CCADB workflow issue needing CCADB team support.
- SwissSign AG — Mike Guenther reported the CCADB workflow was pending review by a root store operator and requested closure if no further questions remained.
- Mozilla representative — Mozilla stated it would close the bug on Wed 7-Dec-2022 unless further discussion was needed.