SwissSign: recommendation on publication process for CA related data
This case is based on an ETSI audit report for SwissSign that included a recommendation to improve SwissSign’s publication process for CA-related data in its public repository, such as PKI chains and relevant certificates (including issuing CAs). The audit recommendation was the trigger for the incident report, and SwissSign stated that certificate issuance was not impacted because the issue was not related to issuance. SwissSign also reported that during the audit an error was detected in its certificate repository: all required PEM files were correct, but one DER file was wrong. SwissSign reviewed and corrected the repository inconsistency and improved internal processes, including additional verification steps and evaluation of automation options to reduce recurrence risk. SwissSign reported that the action items associated with the audit recommendation were completed and that it would continue monitoring the Bugzilla for community feedback. The CCADB incident report was subject to a final call for comments before closure, and the bug is marked RESOLVED with resolution FIXED.
- SwissSign opened a CA Program bug with a preliminary incident report describing an ETSI audit recommendation to improve publication of CA-related data.
- SwissSign posted a full incident report with details of the audit recommendation and the repository inconsistency found during the audit.
- SwissSign indicated it was monitoring the Bugzilla for community feedback.
- SwissSign reported completion of the audit recommendation action items after auditor review and provided a report closure summary.
- The incident report was scheduled to close after a final call for comments.
- SwissSign AG — Opened a preliminary incident report stating the ETSI audit recommended improving SwissSign’s publication process for CA-related data in its public repository.
- SwissSign AG — Posted the full incident report, including that an audit detected a repository inconsistency (one wrong DER file while required PEM files were correct) and that certificate issuance was not halted.
- SwissSign AG — Noted that SwissSign was monitoring the Bugzilla for community feedback.
- SwissSign AG — Again stated that SwissSign was monitoring the Bugzilla for community feedback.
- SwissSign AG — Reported completion of the action item to check for automation possibilities, reviewed by auditors, and described remediation including corrected repository inconsistency and improved verification/automation evaluation.
- CCADB representative — Issued a final call for comments or questions and stated the incident report would be closed approximately 2026-05-04.