← SwissSign AG cases
Bugzilla #1990269 Incident

SwissSign: recommendation on document release dual control

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign opened this CA Program bug to report an audit finding. The audit report contained a recommendation to improve dual control for any public document release in the markdown process, referencing ETSI EN 319 401 and REQ-6.1-01. SwissSign stated that certificate issuance was not impacted because the issue was an audit recommendation rather than a non-compliance event. SwissSign explained that dual control for TSP document management and publication was previously implemented via a manual, email-based process, and that it was transitioning to Git and Markdown-based management. As remediation, SwissSign implemented a technically enforced dual-control mechanism in its internal Git-based TSP document publishing workflow, requiring independent approvals and using automated workflow controls and pipelines. SwissSign reported that the action item was completed and reviewed by auditors, and the bug was resolved as FIXED. The thread also notes a final call for community comments before closure.

Model: gpt-5.4-nano Generated: 2026-06-13 20:48 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.86 6 comments
Chronology
  1. SwissSign’s audit report was published with a recommendation to improve dual control for public document releases in the markdown process.
  2. SwissSign completed implementation of technically enforced dual control in its Git-based TSP document publishing workflow and had it reviewed by auditors.
Thread Activity
  1. SwissSign AG — Opened a preliminary incident report stating the audit recommended improving dual control for public document release in the markdown process and cited ETSI EN 319 401 / REQ-6.1-01.
  2. SwissSign AG — Provided a full incident report, noting the recommendation was not a certificate-issuance impact and describing the move from manual email-based dual control to GitLab-based automated approval workflows.
  3. SwissSign AG — Noted they were monitoring the Bugzilla for community feedback.
  4. SwissSign AG — Noted they were monitoring the Bugzilla for community feedback.
  5. SwissSign AG — Reported completion of the action item, stating auditors reviewed the implementation of technically enforced dual control in the Git-based workflow and that all action items were done.
  6. CCADB representative — Issued a final call for comments or questions before the incident report would be closed on approximately 2026-05-07.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990285 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-07 · 81% similar
SwissSign: recommendation on log review process
#1990266 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 80% similar
SwissSign: recommendation on BIA/BCP test coverage
#1990271 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 79% similar
SwissSign: recommendation on firewall review
#1990263 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 78% similar
SwissSign: recommendation on BIA/BCP review
#1995252 RESOLVED Incident Opened 2025-10-20 · Closed 2025-12-11 · 74% similar
SwissSign: Attribute Change process did not revoke single-domain certificates
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 67% similar
SwissSign: recommendation on publication process for CA related data
#1965807 RESOLVED Incident Opened 2025-05-12 · Closed 2025-06-04 · 67% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #4 – Expired cert with bad order of attributes
#1990274 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 66% similar
SwissSign: recommendation on synchronization of staging and production environments

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action