certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #2 – Add test certificates in CPS
This case documents certSIGN’s response to a finding from a 2025 ETSI audit (Audit Incident Report #2). The auditors requested a sample of test certificates for signing/sealing that were issued in the Production environment, but certSIGN stated it did not use signing/sealing test certificates in Production and instead used test certificates only on Demo/Test platforms. certSIGN also stated that to issue a sample of test certificates in Production, operators had to use the normal registration process, and that the limited-to-testing usage was not written in the CPS. The auditors asked certSIGN to include test certificate descriptions in the CPS with a clear differentiator between normal and test certificates. certSIGN updated its CPS documents with test certificates information and published the updated CPS versions, and it also released an internal procedure for issuing test certificates. certSIGN reported that the mitigation actions were completed and requested closure; the bug is marked RESOLVED with resolution FIXED.
- ETSI audit auditors requested a sample of signing/sealing test certificates issued in the Production environment.
- The non-compliance period identified by the audit finding ended (as stated in the incident report).
- certSIGN published updated CPS documents including test certificates information and released an internal procedure for issuing test certificates.
- certSIGN submitted a closure report stating mitigation actions were completed and requested closure.
- certSIGN — Opened the incident report describing the audit finding about adding test certificate descriptions in the CPS and noting that test certificates were not used in Production.
- HARICA — Asked for clarification of what “Production” meant and questioned the usefulness of the “Lessons Learned” wording.
- certSIGN — Clarified that “Production” refers to the environment used for issuing public certificates and explained the intent behind the CPS updates.
- certSIGN — Noted updates made to the bug’s subject/title, source of disclosure, timeline, related incidents, and action items per a referenced Chrome root program request.
- HARICA — Followed up by asking whether the “test” certificates were indistinguishable from regular subscriber certificates and challenged the conditional ETSI interpretation.
- certSIGN — Explained that in Demo/Test environments all certificates are test certificates, and in Production certSIGN issued regular subscriber certificates with short validity for testing; stated the auditors recommended using test certificates in Production.
- certSIGN — Reported that the CPS documents were updated with test certificates information, provided publication links, and stated the internal procedure was released; mitigation actions were marked Completed.
- certSIGN — Proposed closing the report, stating all actions were completed.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed approximately 2025-06-11.