← certSIGN cases
Bugzilla #1965805
Audit Related
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #2 – Add test certificates in CPS
RESOLVED
FIXED
certSIGN
AI Summary
The certSIGN CA was found to have issued test certificates in a manner that did not comply with the normal registration process during a 2025 ETSI audit. The auditors identified that test certificates were used only in Demo/Test environments and not in Production, leading to a lack of clear differentiation in the Certification Practice Statement (CPS). certSIGN has since updated their CPS to include descriptions of test certificates and their intended usage, addressing the auditors' concerns. No actual certificates were impacted by this finding.
Chronology
- Non-compliance identified during audit
- Non-compliance ended after CPS update
- Closure report submitted
Participants
Gabriel PETCU
Dimitris Zacharopoulos
External References
Similar Local Cases
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #3 – Missing certSIGN OID on Terms and Conditions
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #1 – Improve clarity in CPS
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #5 – Conflicting info in CPS
certSIGN: Findings in 2023 ETSI Audit for certSIGN ROOT CA G2 - Audit Incident Report
certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report
Preliminary Audit Statements - certSIGN
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #3 – Asset Management