← Certigna cases
Bugzilla #1907833
Audit Finding
Certigna: Findings in 2024 ETSI Audit – Audit Incident Report
RESOLVED
FIXED
Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves Certigna's findings from a 2024 ETSI audit, which identified several areas for improvement. The audit revealed non-conformities related to the deployment of new CA hierarchies, training of RA operators, documentation of OIDs, periodic review of the information security policy, and documentation on trusted roles. Certigna has since implemented corrective actions for each finding, and all issues were closed by the auditor in June 2024. The current status of the case is resolved, with all actions operational as confirmed by Certigna.
Chronology
- Completion of the ETSI audit with findings reported.
Thread Activity
- Dhimyotis representative — Audit incident report findings were detailed, including action items for improvement.
- Google representative — Questions raised regarding the level of detail in the findings and root cause analysis.
- Dhimyotis representative — Attachments of audit attestation letters were provided.
- Dhimyotis representative — Confirmed that all actions have been implemented and findings are closed.
- Mozilla representative — Indicated intention to close the bug unless additional items are addressed.
Participants
Dhimyotis representative
Google representative
Mozilla representative
External References
Similar Local Cases
Dhimyotis / Certigna: Intermediate CAs missing audits
certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report
certSIGN: Findings in 2023 ETSI Audit for certSIGN ROOT CA G2 - Audit Incident Report
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report
Telia: Findings in 2024 Audit
SSL.com: Findings in 2023 audit
Audit info for SECOM
Network Solutions: Audit Reports