← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1832338
Technical Compliance
Firmaprofesional: 2023 - Ensure Timestamp service Logs Integrity
RESOLVED
FIXED
Autoridad de Certificacion Firmaprofesional
AI Summary
The case addresses a finding from an annual eIDAS/ETSI audit regarding the integrity of timestamp service logs at Firmaprofesional. The audit team identified that while access to the logs was restricted, it was deemed insufficient to guarantee their integrity. In response, Firmaprofesional decided to implement measures to seal the timestamp service logs with TSA. The issue was resolved promptly on May 9, 2023, and the case has since been marked as resolved.
Chronology
- Finding identified during annual eIDAS audit.
- Firmaprofesional analyzed the finding and decided to seal timestamp service logs.
- Firmaprofesional confirmed the issue was fixed.
Participants
Maria Jose Prieto
Ben Wilson
External References
Similar Local Cases
Firmaprofesional: 2022 - Title field
Firmaprofesional: 2022 - Define Device Obsolescence Process
Firmaprofesional: Non-BR-Compliant OCSP Responders
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
Sectigo: Late termination of privileged access to Certificate Systems
Entrust: CRLs and OCSP responses not issued as specified in the CPS