← Autoridad de Certificación (ANF AC) cases
Bugzilla #1837386 Ca Security Vulnerability

ANF AC: 2023 Audit Report Finding (contingency plan testing timeframes)

RESOLVED FIXED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports a finding from ANF AC’s eIDAS/ETSI audit carried out in March–April 2023. The audit team found that, although disaster contingency plan testing was analyzed for the main CPD and the replacement CPD, the annual testing evidence did not consider the time frames for the availability of disaster CPD personnel needed to access the ANF AC rack during holidays or outside business hours. ANF AC explained that annual simulation of the contingency plan requires activating an alternative (passive) CPD and that physical access involves ANF AC trusted role personnel and CPD personnel, with customer service coordinating access details. ANF AC stated that the audit period was close to national holidays, leading auditors to check operational officer availability during non-working hours; ANF AC verified the operational officer is available 24 hours a day but not in person at the CPD during non-working hours, which could add travel time not contemplated by the continuity plan. In response, ANF AC registered the issue in its ticketing system on 2023-05-04 and updated the contingency procedure on 2023-05-16 for scenarios requiring use of the DR site as primary CPD. Mozilla asked whether any action items remained, and ANF AC indicated the bug could be closed, after which Mozilla closed it on 2023-10-11.

Model: gpt-5.4-nano Generated: 2026-06-13 15:21 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.86 4 comments
Chronology
  1. eIDAS/ETSI audit identified a finding about contingency plan testing not covering disaster CPD personnel availability timeframes during non-working hours.
  2. ANF AC registered the audit finding in its ticketing system.
  3. ANF AC updated the contingency procedure for scenarios requiring the DR site as primary CPD.
  4. Mozilla closed the bug after confirming no further action items were needed.
Thread Activity
  1. Autoridad de Certificación (ANF AC) — ANF AC described the audit finding and the contingency procedure update, explaining why non-working-hours availability and travel time were not covered by the tested timeframes.
  2. Mozilla representative — Mozilla asked whether any action items remained and whether the bug could be closed.
  3. Autoridad de Certificación (ANF AC) — ANF AC said the bug could be closed unless further clarification was needed.
  4. Mozilla representative — Mozilla stated it would close the bug on Wed 11-Oct-2023.
Participants
Autoridad de Certificación (ANF AC) Mozilla representative
External References
Similar Local Cases
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 48% similar
DigiCert: OCSP not responding issue
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 47% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 47% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 47% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 45% similar
DigiCert: OCSP responder returning invalid responses
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 45% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1773556 RESOLVED Ca Security Vulnerability Opened 2022-06-09 · Closed 2023-02-22 · 45% similar
Google Trust Services: Incorrect OCSP responses for certain certificates
#1622505 RESOLVED Ca Security Vulnerability Opened 2020-03-14 · Closed 2023-02-22 · 45% similar
GlobalSign: OCSP Status HTTP 530

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action