← SwissSign AG cases
Bugzilla #1990284 Audit Finding Self Reported Incident

SwissSign: recommendation on review of key pair generation implementation

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents an audit recommendation affecting SwissSign’s key pair generation compliance process. The incident report states that an ETSI audit included a recommendation to improve SwissSign’s regular review of its implementation against NIST SP 800-89 for key pair generation. SwissSign reported that certificate issuance was not halted because the audit recommendation was not treated as a non-compliance event, and SwissSign already checks public keys according to TLS BR 6.1.6 before issuing certificates. The reported root cause was that a formally defined and recurring monitoring process for tracking updates to NIST SP 800-89 had not been explicitly documented in SwissSign’s compliance framework. As remediation, SwissSign implemented a defined and documented monitoring process to track changes to NIST SP 800-89 and to regularly reassess internal key pair generation controls against the specification. The bug was resolved as FIXED, with action items marked done and a final call for comments before closure.

Model: gpt-5.4-nano Generated: 2026-06-13 20:47 UTC Revised: 2026-06-16 18:24 UTC Confidence: 0.84 6 comments
Chronology
  1. An audit report containing a recommendation on improving SwissSign’s regular review of key pair generation against NIST SP 800-89 was published.
  2. SwissSign completed the action item to set up monitoring for NIST SP 800-89 changes and reported remediation completion.
Thread Activity
  1. SwissSign AG — Opened a preliminary incident report stating the audit recommendation concerned improving SwissSign’s regular review of its key pair generation implementation against NIST SP 800-89.
  2. SwissSign AG — Submitted a full incident report describing the audit recommendation, noting issuance was not halted, and identifying the lack of a formally documented recurring monitoring process for NIST SP 800-89 updates.
  3. SwissSign AG — Noted that SwissSign was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — Noted again that SwissSign was monitoring the Bugzilla for community feedback.
  5. SwissSign AG — Reported completion of the action item to set up monitoring of NIST SP 800-89 changes and provided a report closure summary stating all action items were completed.
  6. CCADB representative — Issued a final call for comments or questions and stated the incident report would be closed on approximately 2026-05-04.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990277 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 100% similar
SwissSign: recommendation on CA-specific risk assessment
#1990282 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-11 · 100% similar
SwissSign: recommendation on linting software updates
#1990281 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 92% similar
SwissSign: recommendation on self-assessment tool
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 88% similar
SwissSign: OCSP outage
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 87% similar
SwissSign: Certificate Profile error for S/MIME MV
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 82% similar
SwissSign: recommendation on publication process for CA related data
#1990276 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-07 · 81% similar
SwissSign: recommendation on evaluation of cloud service providers
#1473971 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-07-06 · Closed 2023-02-22 · 81% similar
SwissSign: Domain validated certificate but with stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action