← D-TRUST cases
Bugzilla #2011430 Ca Documents Audit Delay

D-Trust: Delayed publication of audit attestation letters in the CCADB

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns D-Trust GmbH’s failure to upload required Audit Attestation Letter(s) (AALs) to the CCADB within the CCADB Policy deadline of 92 calendar days after the end date of the audit period. The audit period ended on 2025-10-07, the 92-day submission deadline expired on 2026-01-07, and the AALs were uploaded to the CCADB on 2026-01-19. The CCADB policy requirement for a delay greater than 92 days is that the CA Owner provide an explanatory letter signed by the Qualified Auditor, and the auditor TÜV NORD CERT GmbH distributed such an explanatory letter to root store providers on 2026-02-03. In the thread, CCADB/Chrome Root Program participants also raised questions about the policy-version references in the audit statements; D-Trust and its auditor discussed these points and later updated the Audit Attestation Letters to explicitly list all CP/CPS/TSPS document versions and validity periods applicable during the audit period. D-Trust reported process improvements, including an escalation path with deadline monitoring and a resolved CCADB S/MIME capability metadata discrepancy. The bug remains in ASSIGNED status with ongoing monitoring updates reported in later comments.

Model: gpt-5.4-nano Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 09:59 UTC Confidence: 0.86 22 comments
Chronology
  1. D-Trust’s audit period ended.
  2. The CCADB 92-day AAL submission deadline expired.
  3. D-Trust uploaded the Audit Attestation Letters to the CCADB.
  4. The auditor distributed an explanatory letter regarding the late AAL provision to root store providers.
  5. D-Trust provided revised Audit Attestation Letters explicitly listing all applicable CP/CPS/TSPS versions and validity periods for the audit period.
Thread Activity
  1. D-Trust — Opened a preliminary incident report stating D-Trust uploaded the required AALs on 2026-01-19 after the 92-day deadline expired on 2026-01-07, and cited CCADB Policy 5.2 requirements.
  2. CCADB representative — Noted that the audit reports had multiple versions and that, for delays beyond 92 days, D-Trust must provide an explanatory letter signed by the Qualified Auditor and improve internal processes.
  3. D-Trust — Acknowledged the comment.
  4. D-Trust — Stated D-Trust was in contact with its auditor to submit the Audit Attestation Letter(s).
  5. D-Trust — Provided a full incident report with the timeline and stated the explanatory letter would be distributed by TÜV NORD CERT GmbH on 2026-02-03.
  6. D-Trust — Posted the explanatory letter content and links to the AAL PDFs referenced in the letter.
  7. Google representative — Asked D-Trust to clarify discrepancies about policy-version references in the audit statements and how multiple in-force policy versions were handled.
  8. Bdr representative — Provided clarifications on why only latest approved policy versions were referenced in the attestation and confirmed the audit covered operational practices across the full audit period.
  9. Bdr representative — Updated action items, stating escalation path work and resolution of the CCADB S/MIME capability metadata discrepancy were completed.
  10. Apple representative — Requested that CCADB Policy 5.2 requirements be met, arguing that policy versions effective after the audit period should not be used to show compliance for that period.
  11. Bdr representative — Stated the Audit Attestation Letters were updated to explicitly list all CP/CPS/TSPS versions and validity periods applicable during the audit period and provided revised AAL links.
  12. Bdr representative — Reported weekly status: nothing new; D-Trust continues to monitor the ticket.
  13. Bdr representative — Reported weekly status: nothing new; requested the deadline for the next update be set for October 2, 2026.
Participants
D-Trust CCADB representative Google representative Bdr representative Apple representative HARICA Tuev-nord representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1967951 RESOLVED Ca Documents Opened 2025-05-22 · Closed 2025-07-01 · 67% similar
FNMT: Delayed Disclosure of Updated Policy Documents in the CCADB
#1969842 RESOLVED Ca Documents Incident Opened 2025-06-02 · Closed 2025-07-16 · 67% similar
ANF AC: Finding #1 ETSI Audit - Missing log retention period in Terms and Conditions v1.9
#2007238 RESOLVED Ca Documents Repository Issue Opened 2025-12-20 · Closed 2026-01-12 · 66% similar
Certigna: CRL URL Disclosure
#1716351 RESOLVED Ca Documents Audit Document Remediation Tracking Opened By Root Store Opened 2021-06-14 · Closed 2026-06-25 · 65% similar
HARICA: Audit Documents
#1965806 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 65% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #3 – Missing certSIGN OID on Terms and Conditions
#1945536 RESOLVED Ca Documents Audit Delay Opened 2025-02-03 · Closed 2025-06-02 · 64% similar
DigiCert: Outdated CPS for 13 Roots in CCADB
#2055444 ASSIGNED Ccadb Disclosure Issue Incident Self Reported Incident Audit Document Opened 2026-07-16 Still Open · 61% similar
Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters
#1597948 RESOLVED Ca Documents Opened 2019-11-20 · Closed 2024-06-30 · 61% similar
Sectigo: Missing Intermediate CA Certificate in Audit - D-TRUST CA 2-1 2015

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action