ANF AC: Finding #3 ETSI audit — improve CPS documentation for revocation requests delayed >24h
ANF AC opened this CA Program bug to address a non-conformity found during an ETSI EN 319 411-1 audit. The issue was that ANF AC’s CPS stated that if a revocation request could not be confirmed within 24 hours, actions and reasons would be recorded, but the explanation was insufficient because it did not specify what concrete actions ANF AC would take in that scenario. The non-conformity was raised under requirement [REV-6.2.4-03BA], and the incident disclosure source was described as an external auditor during the annual conformity assessment audit. ANF AC stated that the impact was documentation-only: no certificates were affected, issuance was not stopped, and immediate revocation channels remained functional at all times. ANF AC reported that it corrected the documentation by explicitly describing the internal escalation process, immediate notification to the Security Officer, and corrective actions for such scenarios. The bug is marked RESOLVED with resolution FIXED.
- Non-conformity identified during the period covered by the ETSI audit findings.
- Non-conformity end date recorded for the documentation gap.
- ANF AC filed the incident report bug to document and remediate the CPS documentation deficiency.
- Bug status updated to RESOLVED/FIXED.
- Autoridad de Certificación (ANF AC) — Pablo Díaz posted a full incident report explaining that the CPS revocation exception procedure lacked concrete escalation steps when confirmation could not be completed within 24 hours, and described the corrective documentation updates.
- CCADB representative — CCADB sent a final call for comments or questions, noting the incident report would be closed around 2025-07-08.