certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report
This case documents certSIGN’s 2025 ETSI audit findings disclosed to Mozilla as an “Audit Incident Report.” certSIGN stated that it received Audit Attestation letters and that the auditors considered the findings to be minor non-conformities. The thread lists multiple findings, including CPS clarity issues (policy identifier acronyms), certificate issuance/testing process concerns, a missing OID listing in published terms and conditions, a test certificate subject attribute order issue, and a conflicting/typo identity statement in a DV CPS. certSIGN proposed corrective actions and due dates for each finding, and it said it would submit separate tickets for each finding using the recommended template. certSIGN opened separate Bugzilla tickets for audit findings #1 through #5 and proposed closing the preliminary audit report. Mozilla (b**********n@mozilla.com) indicated the report could be closed because five other incident reports had been opened that replace it. The bug is marked RESOLVED with resolution FIXED.
- certSIGN filed a preliminary “Audit Incident Report” describing minor non-conformities from its 2025 ETSI audit attestation letters.
- certSIGN opened separate Bugzilla tickets for each of the five audit findings and proposed closing the preliminary report.
- Mozilla confirmed the preliminary report could be closed because replacement incident reports were opened.
- certSIGN — certSIGN described five minor audit findings, their root causes, and action items with due dates, and provided the audit attestation sources.
- Community commenter — Asked whether separate bugs should be opened for each finding due to different root causes and discussion needs.
- Google representative — Explained that CCADB Policy previously referenced “Audit Incident Report” and that CCADB incident reporting guidance was updated to remove that concept, preferring distinct reports per issue using current templates.
- certSIGN — Confirmed certSIGN would submit separate tickets for each finding using the recommended template.
- certSIGN — Reported that separate Bugzilla tickets were opened for audit findings #1–#5 and proposed closing the preliminary audit report.
- certSIGN — Proposed closing the incident if there were no further requirements.
- Mozilla representative — Agreed it could be closed because five other incident reports had been opened that replace this one.