Telia: Findings in 2024 Audit
This case is Telia CA’s audit incident report for its 2024 annual ETSI audit. The report describes three audit findings: (1) missing or insufficient operation security test documentation and software acceptance process for Cygate secure mail and related RA software change management documentation; (2) backup/key escrow documentation lacking explicit information about the number of duplicated private key copies required; and (3) OCSP responder monitoring capability not covering requests for non-issued certificates due to a monitoring solution transition not being fully migrated. Telia states that it remedied all findings and that the audit attestation was verified by auditors before issuance. In response to questions from the Chrome Root Program, Telia clarified that no major non-conformities were detected, provided additional detail via updated audit reports uploaded to the CCADB, and corrected incorrect ETSI standard version numbers in the reports. Telia also provided a closure summary asserting that all disclosed action items were completed and requested closure. The bug is marked RESOLVED with resolution FIXED.
- Telia filed its 2024 annual ETSI audit incident report describing three findings and associated action items.
- Telia uploaded updated audit reports to the CCADB to address questions and remedy issues identified in the CCADB review.
- Telia provided an incident report closure summary stating remediation and completion of all action items.
- Teliacompany representative — Filed an audit incident report for Telia CA’s 2024 annual ETSI audit, listing three findings, root causes, and action items with due dates.
- Google representative — Asked questions about the meaning of “All major non-conformities have been closed,” Telia’s evaluation against Chrome Root Program policy, and rationale for using superseded ETSI standard versions, and requested more specificity in finding/action item descriptions.
- Teliacompany representative — Responded that Telia would provide full answers by 17 Dec 16:00 EET due to auditor involvement.
- Teliacompany representative — Provided responses to the questions, stated no major non-conformities were detected, and said updated audit reports were uploaded to the CCADB; also said incorrect ETSI standard version numbers were remedied in newly updated reports.
- Mozilla representative — Requested a brief closing summary confirming incident/root cause/remediation, any commitments, and that all action items were completed.
- Teliacompany representative — Submitted a closure summary for all three findings, describing remediation and stating all action items were completed and requesting closure.
- Mozilla representative — Indicated no further questions and intent to close the bug on 20-Dec-2024.