← Autoridad de Certificación (ANF AC) cases
Bugzilla #1970559 Ca Certificate Compliance

ANF AC: Finding #3 ETSI audit — improve CPS documentation for revocation requests delayed >24h

RESOLVED FIXED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ANF AC opened this CA Program bug to address a non-conformity found during an ETSI EN 319 411-1 audit. The issue was that ANF AC’s CPS stated that if a revocation request could not be confirmed within 24 hours, actions and reasons would be recorded, but the explanation was insufficient because it did not specify what concrete actions ANF AC would take in that scenario. The non-conformity was raised under requirement [REV-6.2.4-03BA], and the incident disclosure source was described as an external auditor during the annual conformity assessment audit. ANF AC stated that the impact was documentation-only: no certificates were affected, issuance was not stopped, and immediate revocation channels remained functional at all times. ANF AC reported that it corrected the documentation by explicitly describing the internal escalation process, immediate notification to the Security Officer, and corrective actions for such scenarios. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:21 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.50 2 comments
Chronology
  1. Non-conformity identified during the period covered by the ETSI audit findings.
  2. Non-conformity end date recorded for the documentation gap.
  3. ANF AC filed the incident report bug to document and remediate the CPS documentation deficiency.
  4. Bug status updated to RESOLVED/FIXED.
Thread Activity
  1. Autoridad de Certificación (ANF AC) — Pablo Díaz posted a full incident report explaining that the CPS revocation exception procedure lacked concrete escalation steps when confirmation could not be completed within 24 hours, and described the corrective documentation updates.
  2. CCADB representative — CCADB sent a final call for comments or questions, noting the incident report would be closed around 2025-07-08.
Participants
Autoridad de Certificación (ANF AC) CCADB representative
External References
Similar Local Cases
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 68% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#1976860 RESOLVED Ca Certificate Compliance Opened 2025-07-11 · Closed 2025-08-21 · 68% similar
Telekom Security: Failure to file a bug for two findings from the 2024 Audit
#2019995 RESOLVED Ca Certificate Compliance Opened 2026-02-27 · Closed 2026-04-08 · 68% similar
Sectigo: Package patching gap within Certificate Systems
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 68% similar
Financijska agencija (Fina): Mis-issued certificates
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 67% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#1957962 RESOLVED Ca Certificate Compliance Opened 2025-04-02 · Closed 2025-07-16 · 67% similar
Telekom Security: QCStatement with http link to PDS
#1970968 RESOLVED Ca Certificate Compliance Opened 2025-06-06 · Closed 2025-07-08 · 67% similar
Microsoft PKI Services: Incorrect Revocation Reason Code
#2013805 RESOLVED Ca Certificate Compliance Opened 2026-02-02 · Closed 2026-05-01 · 67% similar
iTrusChina: Finding in Routine WebTrust Audit - Domain validation records without the TLS BR version

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action