← Autoridad de Certificación (ANF AC) cases
Bugzilla #1970567 Audit Finding

ANF AC: ETSI audit finding—CP&C missing explicit revocation circumstance for cryptographic obsolescence

RESOLVED FIXED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns an ETSI EN 319 401 audit finding for ANF AC’s Certification Policies and Practices (CP&C) documentation. During the review of the revocation policy, it was detected that the published CP&C version 3.9 (OID 1.3.6.1.4.1.18332.1.9.1.1) was missing an explicit clause requiring certificate revocation when the cryptography used no longer ensures the binding between the subject and its public key. ANF AC’s compliance team believed the requirement was already covered implicitly by other CP&C sections (including section 4.9.1 “Revocation Circumstances” and clause 5.7.3), but external auditors concluded that ETSI EN 319 401 requires the criterion to appear explicitly in the relevant revocation section. ANF AC published a corrected CP&C version 3.10 on 2025-02-20, explicitly adding the missing revocation circumstance to section 6.3.9. The incident report states there was no issuance or operational impact (total number of certificates: 0; documentation-only issue). The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:22 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.86 2 comments
Chronology
  1. ANF AC published CP&C version 3.9 without an explicit revocation clause for cryptographic obsolescence.
  2. External auditors detected the omission during the annual conformity assessment audit (ETSI EN 319 401).
  3. ANF AC published CP&C version 3.10 explicitly adding the missing revocation circumstance in section 6.3.9.
  4. The CA Program bug was updated to RESOLVED (FIXED).
Thread Activity
  1. Autoridad de Certificación (ANF AC) — Submitted an incident report describing ETSI audit finding #4 and the CP&C wording correction, stating the missing explicit revocation circumstance was added in version 3.10.
  2. CCADB representative — Posted a final call for comments/questions on the incident report, noting it would be closed around 2025-07-08.
Participants
Autoridad de Certificación (ANF AC) CCADB representative
External References
Similar Local Cases
#2047581 ASSIGNED Audit Finding Policy Document Issue Audit Document Remediation Tracking Opened 2026-06-15 Still Open · 86% similar
ANF AC: 2026 Audit Report Finding 3 out of 3
#2047580 ASSIGNED Audit Finding Policy Document Issue Audit Document Information Request Opened 2026-06-15 Still Open · 85% similar
ANF AC: 2026 Audit Report Finding 2 out of 3
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 69% similar
SwissSign: recommendation on publication process for CA related data
#1965804 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 69% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #1 – Improve clarity in CPS
#1970565 RESOLVED Audit Finding Self Reported Incident Opened 2025-06-05 · Closed 2025-07-08 · 69% similar
ANF AC: Finding #2 ETSI Audit - Information security policy not updated on the website
#1990254 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 68% similar
SwissSign: recommendation on risk assessment
#1965805 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 68% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #2 – Add test certificates in CPS
#1990272 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 67% similar
SwissSign: recommendation on backup testing

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action