← Buypass cases
Bugzilla #1875440
Audit Related
Buypass: Findings in 2023 audit
RESOLVED
FIXED
Buypass
AI Summary
Buypass underwent a 2023 audit which revealed two main findings. The first finding highlighted ineffective physical security reviews due to an accidental deletion of internal control in the scheduling program, leading to a lack of periodic review. The second finding involved improper implementation of certificate profile changes regarding Subject Attribute Encoding, which was self-reported. Action items have been established to prevent future occurrences, including improvements to the change process and the inclusion of verification steps.
Chronology
- Audit findings reported
- Action item to include digicert/pkilint in the certificate issuance process due
- Request to close the bug made
Participants
mads.henriksveen@buypass.no
daknob@daknob.net
bwilson@mozilla.com
External References
Similar Local Cases
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #1 - Compliance auditing on support processes
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #2 - Supply chain policy
Audit infor for Buypass
SSL.com: Findings in 2023 audit
Microsoft PKI Services: Overdue Audit Reports 2021
SwissSign Audit info
Audit Info for SSL.com
FNMT: Documents