certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #5 – Conflicting info in CPS
This case concerns a finding in certSIGN’s CPS for its “certSIGN Web CA for DV SSL Certificates” (version 1.8). The ETSI auditors identified conflicting information in chapter 3.2.2.1 Identity: the CPS text referenced domain validation methods, while chapter 3.2.2.4.2 stated that the method of domain validation was not used. certSIGN reported that the issue was a typo error missed during verification, and stated that there was no impact because no certificates were affected (total number of certificates: 0). certSIGN’s remediation included correcting the CPS typo, retraining verifiers, and adding an extra verification step via internal audit. In the thread, certSIGN provided a closure report stating the typo was corrected, verification was improved, and that the disclosed action items were completed, requesting closure. CCADB incident-reporting then issued a final call for comments and indicated the report would be closed on approximately 2025-06-11 if no further questions were raised.
- ETSI auditors identified a conflicting-information finding in certSIGN’s DV CPS (version 1.8) and marked it as an audit finding.
- certSIGN published CPS version 1.9 with an effective date of 30-Apr-2025 to address the finding.
- certSIGN submitted a closure report stating the typo was corrected and action items were completed, requesting closure.
- CCADB indicated the incident report would be closed on approximately this date if no further comments were received.
- certSIGN — Submitted the full incident report finding #5 describing conflicting CPS content in chapter 3.2.2.1 vs 3.2.2.4.2, stating there was no impact and attributing it to a typo missed by verification.
- certSIGN — Updated the bug’s title and incident-reporting fields per a request referencing Bug 1965807 (including adding a timeline item for 15-Jan-2025 publication of annual updates).
- CCADB representative — Noted the report had gone stale and requested an update or a closure report, also referencing other related bugs.
- certSIGN — Provided a closure report stating the CPS typo was corrected, the root cause was typo/bad verification, remediation included retraining and internal audit verification, and that action items were completed with a request for closure.
- CCADB representative — Issued a final call for comments and stated the report would be closed on approximately 2025-06-11.