← SwissSign AG cases
Bugzilla #1990275 Ca Documents Audit Finding

SwissSign: recommendation on publication process for CA related data

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is based on an ETSI audit report for SwissSign that included a recommendation to improve SwissSign’s publication process for CA-related data in its public repository, such as PKI chains and relevant certificates (including issuing CAs). The audit recommendation was the trigger for the incident report, and SwissSign stated that certificate issuance was not impacted because the issue was not related to issuance. SwissSign also reported that during the audit an error was detected in its certificate repository: all required PEM files were correct, but one DER file was wrong. SwissSign reviewed and corrected the repository inconsistency and improved internal processes, including additional verification steps and evaluation of automation options to reduce recurrence risk. SwissSign reported that the action items associated with the audit recommendation were completed and that it would continue monitoring the Bugzilla for community feedback. The CCADB incident report was subject to a final call for comments before closure, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:48 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 6 comments
Chronology
  1. SwissSign opened a CA Program bug with a preliminary incident report describing an ETSI audit recommendation to improve publication of CA-related data.
  2. SwissSign posted a full incident report with details of the audit recommendation and the repository inconsistency found during the audit.
  3. SwissSign indicated it was monitoring the Bugzilla for community feedback.
  4. SwissSign reported completion of the audit recommendation action items after auditor review and provided a report closure summary.
  5. The incident report was scheduled to close after a final call for comments.
Thread Activity
  1. SwissSign AG — Opened a preliminary incident report stating the ETSI audit recommended improving SwissSign’s publication process for CA-related data in its public repository.
  2. SwissSign AG — Posted the full incident report, including that an audit detected a repository inconsistency (one wrong DER file while required PEM files were correct) and that certificate issuance was not halted.
  3. SwissSign AG — Noted that SwissSign was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — Again stated that SwissSign was monitoring the Bugzilla for community feedback.
  5. SwissSign AG — Reported completion of the action item to check for automation possibilities, reviewed by auditors, and described remediation including corrected repository inconsistency and improved verification/automation evaluation.
  6. CCADB representative — Issued a final call for comments or questions and stated the incident report would be closed approximately 2026-05-04.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990254 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on risk assessment
#1990272 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on backup testing
#1990274 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on synchronization of staging and production environments
#1990276 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-07 · 100% similar
SwissSign: recommendation on evaluation of cloud service providers
#1990277 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 83% similar
SwissSign: recommendation on CA-specific risk assessment
#1990281 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 82% similar
SwissSign: recommendation on self-assessment tool
#1990284 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-04 · 82% similar
SwissSign: recommendation on review of key pair generation implementation
#1965804 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 80% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #1 – Improve clarity in CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action