Telia: Findings in Audit 2023
This case documents findings from Telia Company’s Audit 2023. The audit incident report lists multiple non-conformities against ETSI EN 319 401 and ETSI EN 319 411-1 requirements, including issues related to cryptographic controls for subject key pair generation, physical and environmental security (data center visitor identity document checks), certificate acceptance terms/conditions and GDPR-related information in the application process, and activation data handling for S/MIME certificates. Telia CA provided root cause analysis details and defined action items to address the findings. Telia CA stated that preventive corrections were deployed with evidence and confirmed by the auditor, and that all findings had been addressed. In the thread, Telia CA also noted ongoing monitoring and requested closure after no further questions were raised. Mozilla indicated it would close the bug on Wed 27-March-2024 unless additional questions were needed. The bug is marked RESOLVED with resolution FIXED.
- Telia CA took immediate actions to ensure required visitor clearance practices were adhered to by data center security personnel as part of Audit 2023 finding remediation.
- Telia CA deployed preventive cryptographic validation corrections with evidence for the subject key pair generation finding.
- Telia CA filed the Audit Incident Report documenting multiple Audit 2023 findings and associated action items.
- Telia CA requested closure after stating all findings had been addressed and actions completed.
- Teliacompany representative — Opened the bug with an “Audit Incident Report” describing four audit findings, root causes, and action items for remediation.
- DigiCert — Noted that the item in Finding #4 was under active discussion in the CA/Browser Forum S/MIME Certificate Work Group and linked to a GitHub issue.
- Teliacompany representative — Acknowledged the CA/Browser Forum work and stated Telia CA would follow progress while continuing to follow the incident.
- Teliacompany representative — Provided a monthly update stating all findings had been addressed and that Telia CA would continue monitoring.
- Teliacompany representative — Provided another monthly update stating all actions/tasks were completed and requested the incident be closed due to no further comments or questions.
- Mozilla representative — Indicated Mozilla would close the bug on Wed 27-March-2024 unless additional questions needed answering.