← Certigna cases
Bugzilla #1973034 Technical Compliance

Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved

RESOLVED FIXED Certigna
AI Summary

Certigna identified a non-compliance issue regarding the protection of event logs, which were configured to be retained for only seven years. This was found during an ETSI audit, where it was noted that logs linked to short-lived certificates were subject to the same retention policy. The issue was resolved by updating the logging procedures and raising team awareness about the new guidelines. No impact on certificates was reported, and all action items have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Confidence: 0.90
Chronology
  1. Protection of log repositories set to a maximum of 7 years.
  2. Non-compliance identified by auditor.
  3. Validation of deviation resolution by auditor.
Participants
Josselin Allemandou R. Delval
External References
Similar Local Cases
#2028195 RESOLVED Technical Compliance Opened 2026-03-31 · Closed 2026-04-11 · 40% similar
GoDaddy: inconsistent CP/CPS disclosure
#1983270 RESOLVED Technical Compliance Opened 2025-08-15 · Closed 2026-01-13 · 40% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
#1428891 RESOLVED Technical Compliance Opened 2018-01-08 · Closed 2023-02-22 · 40% similar
Entrust: Non-BR-Compliant OCSP Responder
#1732745 RESOLVED Technical Compliance Opened 2021-09-27 · Closed 2023-02-22 · 40% similar
Certainly: Root CRL validity period exceeds maximum by one second
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 40% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1746945 RESOLVED Technical Compliance Opened 2021-12-20 · Closed 2023-02-22 · 40% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1772633 RESOLVED Technical Compliance Opened 2022-06-03 · Closed 2023-02-22 · 39% similar
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines
#2008027 RESOLVED Technical Compliance Opened 2025-12-30 · Closed 2026-02-09 · 39% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #6 – Access Control Management

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action