SwissSign: recommendation on document release dual control
SwissSign opened this CA Program bug to report an audit finding. The audit report contained a recommendation to improve dual control for any public document release in the markdown process, referencing ETSI EN 319 401 and REQ-6.1-01. SwissSign stated that certificate issuance was not impacted because the issue was an audit recommendation rather than a non-compliance event. SwissSign explained that dual control for TSP document management and publication was previously implemented via a manual, email-based process, and that it was transitioning to Git and Markdown-based management. As remediation, SwissSign implemented a technically enforced dual-control mechanism in its internal Git-based TSP document publishing workflow, requiring independent approvals and using automated workflow controls and pipelines. SwissSign reported that the action item was completed and reviewed by auditors, and the bug was resolved as FIXED. The thread also notes a final call for community comments before closure.
- SwissSign’s audit report was published with a recommendation to improve dual control for public document releases in the markdown process.
- SwissSign completed implementation of technically enforced dual control in its Git-based TSP document publishing workflow and had it reviewed by auditors.
- SwissSign AG — Opened a preliminary incident report stating the audit recommended improving dual control for public document release in the markdown process and cited ETSI EN 319 401 / REQ-6.1-01.
- SwissSign AG — Provided a full incident report, noting the recommendation was not a certificate-issuance impact and describing the move from manual email-based dual control to GitLab-based automated approval workflows.
- SwissSign AG — Noted they were monitoring the Bugzilla for community feedback.
- SwissSign AG — Noted they were monitoring the Bugzilla for community feedback.
- SwissSign AG — Reported completion of the action item, stating auditors reviewed the implementation of technically enforced dual control in the Git-based workflow and that all action items were done.
- CCADB representative — Issued a final call for comments or questions before the incident report would be closed on approximately 2026-05-07.