← SwissSign AG cases
Bugzilla #1990285 Incident

SwissSign: recommendation on log review process

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign opened this CA Program bug as an incident disclosure based on an ETSI audit report. The audit report contained a recommendation to improve SwissSign’s review process of its logs and to align log review and retention processes with anticipated eIDAS regulatory requirements. SwissSign stated that certificate issuance was not halted because issuance was not impacted. SwissSign reported that existing archival retention periods (up to 11 years) did not proactively address potential eIDAS requirements mandating retention periods of up to 30 years. As remediation, SwissSign defined and implemented updated retention policies extending applicable log and information archival periods to 30 years for information governed by eIDAS, and had the updates reviewed by its auditors. The bug thread indicates the action item was completed and the report was closed, with SwissSign continuing to monitor the Bugzilla for community feedback.

Model: gpt-5.4-nano Generated: 2026-06-13 20:47 UTC Revised: 2026-06-16 18:24 UTC Confidence: 0.86 6 comments
Chronology
  1. An ETSI audit report containing a recommendation on SwissSign’s log review and retention processes was published.
  2. SwissSign completed the action item to define and implement 30-year retention for eIDAS-governed information and had it reviewed by auditors.
Thread Activity
  1. SwissSign AG — SwissSign submitted a preliminary incident report stating the audit report recommended improving its log review process.
  2. SwissSign AG — SwissSign provided a full incident report describing the audit recommendation, noting no issuance halt, and listing an action item to implement 30-year eIDAS-related retention.
  3. SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
  5. SwissSign AG — SwissSign reported completion of the 30-year retention action item, including auditor review, and stated the incident report was closed with continued monitoring.
  6. CCADB representative — CCADB posted a final call for comments and indicated the incident report would be closed around 2026-05-07.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990263 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on BIA/BCP review
#1990266 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on BIA/BCP test coverage
#1990271 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-04 · 98% similar
SwissSign: recommendation on firewall review
#1995252 RESOLVED Incident Opened 2025-10-20 · Closed 2025-12-11 · 94% similar
SwissSign: Attribute Change process did not revoke single-domain certificates
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 85% similar
SwissSign: Certificate Profile error for S/MIME MV
#1990269 RESOLVED Incident Opened 2025-09-23 · Closed 2026-05-07 · 81% similar
SwissSign: recommendation on document release dual control
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 75% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 70% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action