← certSIGN cases
Bugzilla #1965805 Ca Documents Audit Finding

certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #2 – Add test certificates in CPS

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents certSIGN’s response to a finding from a 2025 ETSI audit (Audit Incident Report #2). The auditors requested a sample of test certificates for signing/sealing that were issued in the Production environment, but certSIGN stated it did not use signing/sealing test certificates in Production and instead used test certificates only on Demo/Test platforms. certSIGN also stated that to issue a sample of test certificates in Production, operators had to use the normal registration process, and that the limited-to-testing usage was not written in the CPS. The auditors asked certSIGN to include test certificate descriptions in the CPS with a clear differentiator between normal and test certificates. certSIGN updated its CPS documents with test certificates information and published the updated CPS versions, and it also released an internal procedure for issuing test certificates. certSIGN reported that the mitigation actions were completed and requested closure; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:24 UTC Confidence: 0.86 10 comments
Chronology
  1. ETSI audit auditors requested a sample of signing/sealing test certificates issued in the Production environment.
  2. The non-compliance period identified by the audit finding ended (as stated in the incident report).
  3. certSIGN published updated CPS documents including test certificates information and released an internal procedure for issuing test certificates.
  4. certSIGN submitted a closure report stating mitigation actions were completed and requested closure.
Thread Activity
  1. certSIGN — Opened the incident report describing the audit finding about adding test certificate descriptions in the CPS and noting that test certificates were not used in Production.
  2. HARICA — Asked for clarification of what “Production” meant and questioned the usefulness of the “Lessons Learned” wording.
  3. certSIGN — Clarified that “Production” refers to the environment used for issuing public certificates and explained the intent behind the CPS updates.
  4. certSIGN — Noted updates made to the bug’s subject/title, source of disclosure, timeline, related incidents, and action items per a referenced Chrome root program request.
  5. HARICA — Followed up by asking whether the “test” certificates were indistinguishable from regular subscriber certificates and challenged the conditional ETSI interpretation.
  6. certSIGN — Explained that in Demo/Test environments all certificates are test certificates, and in Production certSIGN issued regular subscriber certificates with short validity for testing; stated the auditors recommended using test certificates in Production.
  7. certSIGN — Reported that the CPS documents were updated with test certificates information, provided publication links, and stated the internal procedure was released; mitigation actions were marked Completed.
  8. certSIGN — Proposed closing the report, stating all actions were completed.
  9. CCADB representative — Issued a final call for comments and indicated the incident report would be closed approximately 2025-06-11.
Participants
certSIGN HARICA CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1963546 RESOLVED Ca Documents Audit Finding Opened 2025-04-30 · Closed 2025-05-19 · 100% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report
#1965804 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 100% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #1 – Improve clarity in CPS
#1833667 RESOLVED Audit Document Audit Finding Opened 2023-05-17 · Closed 2023-11-19 · 90% similar
certSIGN: Findings in 2023 ETSI Audit for certSIGN ROOT CA G2 - Audit Incident Report
#1965806 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 90% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #3 – Missing certSIGN OID on Terms and Conditions
#1897134 RESOLVED Audit Finding Opened 2024-05-16 · Closed 2024-09-06 · 89% similar
certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report
#1990274 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 80% similar
SwissSign: recommendation on synchronization of staging and production environments
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 80% similar
SwissSign: recommendation on publication process for CA related data
#1990254 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 79% similar
SwissSign: recommendation on risk assessment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action