certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report
This case documents findings from a 2024 ETSI audit for certSIGN, reported via LSTI TLS BR and LSTI TLS EV audit attestations dated 2024-05-08. The auditors considered the findings to be minor non-conformities, and the report described multiple issues, including an obsolete RFC number in the CPS and an incomplete risk analysis, as well as missing information assets. certSIGN stated that the CPS was corrected, including publishing CPS version 1.27 from 29.03.2024, and that the risk analysis and information asset inventory were improved and updated. In response to Mozilla and a request from Google’s Chris Clements for more detailed root-cause analysis, certSIGN provided additional explanation and noted that detailed audit reports are not public and are available on a need-to-know basis via the referenced CCADB case. Mozilla indicated it would close the bug unless further questions were raised, and certSIGN reiterated that there were no additional remediation items and that the audit findings were resolved. Mozilla later stated it would close the case on or about 6-Sept-2024 unless notice otherwise. The bug is marked RESOLVED with resolution FIXED.
- LSTI TLS BR and LSTI TLS EV audit attestations were issued reporting minor non-conformities from the 2024 ETSI audit.
- certSIGN opened the CA Program bug with the audit incident report and described issues #4–#6 and remediation status.
- Mozilla indicated it intended to close the case unless questions were raised.
- certSIGN provided expanded root-cause and remediation details and referenced the related CCADB audit case.
- Mozilla set a closing timeframe for the bug.
- certSIGN — Submitted the 2024 ETSI audit incident report, describing issues #4–#6 (obsolete RFC in CPS, incomplete risk analysis, and missing information assets) and stating remediation plans and that each issue was marked Done.
- certSIGN — Stated there were no additional remediation items and that the audit findings were resolved unless further questions.
- Mozilla representative — Indicated intent to close the bug on or about 26-July-2024 unless questions or issues were raised.
- Google representative — Requested an update with more detailed root cause analysis and asked whether the audit reports were intended to be attached.
- Mozilla representative — Held off closing and removed the need-info request.
- certSIGN — Explained where audit links are located in CCADB case 00001838, stated detailed audit reports are not public, and provided expanded root-cause and remediation details for issues #4 and #5 (continuing the report text).
- certSIGN — Reiterated there were no additional remediation items and that the audit findings were resolved unless further questions.
- certSIGN — Again stated there were no additional remediation items and that the audit findings were resolved unless further questions.
- Mozilla representative — Stated it would close the bug on or about 6-Sept-2024 unless notice otherwise.