← Autoridad de Certificación (ANF AC) cases
Bugzilla #1974325 Incident Self Reported Incident

ANF AC: Test Certificates Non-Compliance

RESOLVED FIXED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns ANF AC’s test website TLS certificates for the “Test Website - Valid” and “Test Website - Revoked” URLs expiring on 2025-06-17, which violated Section 2.2 of the Baseline Requirements requiring the CA to host test web pages with valid, revoked, and expired TLS certificates at all times. The issue was initially disclosed via a third-party report, and ANF AC then published a Preliminary Incident Report and a Full Incident Report in the bug. ANF AC stated that the certificates were replaced with non-expired certificates and that monitoring was restored with alerts. In the Full Incident Report, ANF AC attributed the non-compliance to test domain monitoring checks being omitted during an infrastructure migration and to renewal of test certificates being historically tied to the audit calendar, which led to renewal being skipped. ANF AC also listed completed corrective actions, including creating a centralized certificate inventory with expiration dates, defining test website management as a recurring compliance task independent of the audit schedule, and adding a post-migration validation checklist. The report closure summary states that all action items were completed and requests closure, with a final call for comments before closure on approximately 2025-07-16.

Model: gpt-5.4-nano Generated: 2026-06-13 15:22 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.50 9 comments
Chronology
  1. ANF AC’s test website TLS certificates for the Valid and Revoked test URLs expired.
  2. ANF AC’s test website certificate non-compliance was reported via a third-party report.
  3. ANF AC replaced the expired test website certificates and re-added the test domains into monitoring.
  4. ANF AC reported completion of action items and requested incident report closure.
Thread Activity
  1. Community commenter — Opened a preliminary incident report stating that the Valid and Revoked test website certificates had expired and referenced the Baseline Requirements Section 2.2 expectations.
  2. Autoridad de Certificación (ANF AC) — Updated that both certificates were updated and that ANF AC was working on the full incident report.
  3. CCADB representative — Noted that the CA Owner response was inconsistent with CCADB.org expectations for incident report timing and content.
  4. Autoridad de Certificación (ANF AC) — Published the Full Incident Report describing the incident, impact, timeline, and root cause analysis.
  5. Autoridad de Certificación (ANF AC) — Reported completion of creating a centralized list of ANF AC certificates and their expiration dates.
  6. Autoridad de Certificación (ANF AC) — Reported completion of defining test website management as a recurring compliance task independent of the audit schedule and adding a control in GRC software.
  7. Autoridad de Certificación (ANF AC) — Reported completion of adding a post-migration validation checklist for monitoring system changes.
  8. Autoridad de Certificación (ANF AC) — Provided a report closure summary stating certificates were renewed, monitoring restored, corrective actions completed, and requested closure.
  9. CCADB representative — Issued a final call for comments or questions before the report would be closed on approximately 2025-07-16.
Participants
Derekrgreene representative Autoridad de Certificación (ANF AC) CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1973236 RESOLVED Incident Policy Document Issue Self Reported Incident Opened 2025-06-20 · Closed 2025-07-09 · 95% similar
ANF AC: Delayed Disclosure of Updated Policy Documents in CCADB
#1970565 RESOLVED Audit Finding Self Reported Incident Opened 2025-06-05 · Closed 2025-07-08 · 87% similar
ANF AC: Finding #2 ETSI Audit - Information security policy not updated on the website
#2050383 ASSIGNED Self Reported Incident Repository Issue Problem Reporting Failure Opened 2026-06-25 Still Open · 86% similar
ANF AC: Incident Report - OCSP "unknown" response for CT precertificate
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 79% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2025913 RESOLVED Self Reported Incident Incident Opened 2026-03-24 · Closed 2026-05-18 · 79% similar
IdenTrust: Full Incident Report for Bug 2014609 was not published within 14 days of discovering the issue
#2013400 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-04-17 · 79% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 78% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 77% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action