← SwissSign AG cases
Bugzilla #1990271 Incident

SwissSign: recommendation on firewall review

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents an ETSI audit recommendation for SwissSign to further improve its firewall review process, specifically to identify unused firewall rules. The incident disclosure source was the audit report, and SwissSign stated that the recommendation was not tied to a certificate misissuance or a period of non-compliance. SwissSign explained that its networking infrastructure is built using “infrastructure as code,” where firewall rules are generated and pushed via automation, with no manual firewall-rule management, making it non-trivial to find unused rules. SwissSign investigated whether it could automatically extract firewall rule usage data, including how rule counters behave during automated full uploads and how to account for rarely executed processes. SwissSign reported that the action item to investigate automatic extraction of firewall rule usage was completed and reviewed by its auditors, and that the firewall review process was enhanced to better assess rule usage without impacting operational or emergency processes. The bug was resolved as FIXED, and SwissSign stated it would continue monitoring the Bugzilla for community feedback.

Model: gpt-5.4-nano Generated: 2026-06-13 20:48 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.84 6 comments
Chronology
  1. SwissSign opened a CA Program incident report bug based on an ETSI audit recommendation to improve firewall rule review.
  2. SwissSign provided a full incident report describing the audit recommendation and planned remediation actions.
  3. An ETSI audit report containing the firewall-rule review recommendation was published.
  4. SwissSign reported completion of the investigation and auditor review, and closed out the incident report.
  5. The Bugzilla case was resolved (FIXED).
Thread Activity
  1. SwissSign AG — SwissSign submitted a preliminary incident report stating the audit report recommended further improvement of its firewall review.
  2. SwissSign AG — SwissSign posted a full incident report describing the infrastructure-as-code setup, the non-triviality of finding unused rules, and an action item to investigate automatic extraction of firewall rule usage.
  3. SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
  5. SwissSign AG — SwissSign reported the action item was completed, reviewed by auditors, and that the firewall review process was enhanced; it also stated all action items were completed.
  6. CCADB representative — CCADB requested a final call for comments and noted the incident report would be closed around 2026-05-04.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990285 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-07 · 98% similar
SwissSign: recommendation on log review process
#1990263 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 97% similar
SwissSign: recommendation on BIA/BCP review
#1990266 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 95% similar
SwissSign: recommendation on BIA/BCP test coverage
#1995252 RESOLVED Incident Opened 2025-10-20 · Closed 2025-12-11 · 94% similar
SwissSign: Attribute Change process did not revoke single-domain certificates
#1990269 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-07 · 79% similar
SwissSign: recommendation on document release dual control
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 73% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1983270 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-13 · 69% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 68% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action