ANF AC: ETSI audit finding—CP&C missing explicit revocation circumstance for cryptographic obsolescence
This case concerns an ETSI EN 319 401 audit finding for ANF AC’s Certification Policies and Practices (CP&C) documentation. During the review of the revocation policy, it was detected that the published CP&C version 3.9 (OID 1.3.6.1.4.1.18332.1.9.1.1) was missing an explicit clause requiring certificate revocation when the cryptography used no longer ensures the binding between the subject and its public key. ANF AC’s compliance team believed the requirement was already covered implicitly by other CP&C sections (including section 4.9.1 “Revocation Circumstances” and clause 5.7.3), but external auditors concluded that ETSI EN 319 401 requires the criterion to appear explicitly in the relevant revocation section. ANF AC published a corrected CP&C version 3.10 on 2025-02-20, explicitly adding the missing revocation circumstance to section 6.3.9. The incident report states there was no issuance or operational impact (total number of certificates: 0; documentation-only issue). The bug was resolved as FIXED.
- ANF AC published CP&C version 3.9 without an explicit revocation clause for cryptographic obsolescence.
- External auditors detected the omission during the annual conformity assessment audit (ETSI EN 319 401).
- ANF AC published CP&C version 3.10 explicitly adding the missing revocation circumstance in section 6.3.9.
- The CA Program bug was updated to RESOLVED (FIXED).
- Autoridad de Certificación (ANF AC) — Submitted an incident report describing ETSI audit finding #4 and the CP&C wording correction, stating the missing explicit revocation circumstance was added in version 3.10.
- CCADB representative — Posted a final call for comments/questions on the incident report, noting it would be closed around 2025-07-08.