SwissSign: recommendation on firewall review
This case documents an ETSI audit recommendation for SwissSign to further improve its firewall review process, specifically to identify unused firewall rules. The incident disclosure source was the audit report, and SwissSign stated that the recommendation was not tied to a certificate misissuance or a period of non-compliance. SwissSign explained that its networking infrastructure is built using “infrastructure as code,” where firewall rules are generated and pushed via automation, with no manual firewall-rule management, making it non-trivial to find unused rules. SwissSign investigated whether it could automatically extract firewall rule usage data, including how rule counters behave during automated full uploads and how to account for rarely executed processes. SwissSign reported that the action item to investigate automatic extraction of firewall rule usage was completed and reviewed by its auditors, and that the firewall review process was enhanced to better assess rule usage without impacting operational or emergency processes. The bug was resolved as FIXED, and SwissSign stated it would continue monitoring the Bugzilla for community feedback.
- SwissSign opened a CA Program incident report bug based on an ETSI audit recommendation to improve firewall rule review.
- SwissSign provided a full incident report describing the audit recommendation and planned remediation actions.
- An ETSI audit report containing the firewall-rule review recommendation was published.
- SwissSign reported completion of the investigation and auditor review, and closed out the incident report.
- The Bugzilla case was resolved (FIXED).
- SwissSign AG — SwissSign submitted a preliminary incident report stating the audit report recommended further improvement of its firewall review.
- SwissSign AG — SwissSign posted a full incident report describing the infrastructure-as-code setup, the non-triviality of finding unused rules, and an action item to investigate automatic extraction of firewall rule usage.
- SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign reported the action item was completed, reviewed by auditors, and that the firewall review process was enhanced; it also stated all action items were completed.
- CCADB representative — CCADB requested a final call for comments and noted the incident report would be closed around 2026-05-04.