← Certigna cases
Bugzilla #2041368 Self Reported Incident

Certigna: Finding #1 ETSI Audit – Missing system configuration information in the CP/CPS

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certigna reported an ETSI audit finding that its CP/CPS did not specify the maximum interval between two checks of system configuration, even though this information existed in its “configuration management procedure.” The non-compliance was identified by an auditor on 2026-02-27 and was treated as an incident disclosed through ETSI audit materials. Certigna stated that there was no impact on certificates and that issuance was not stopped because no certificates were affected. As remediation, Certigna raised awareness among its compliance team and revised and updated the CP/CPS to explicitly specify the maximum interval between system configuration checks in line with its configuration management procedure. Certigna submitted a report closure summary requesting closure after completing the disclosed action items. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:24 UTC Confidence: 0.86 8 comments
Chronology
  1. Certigna’s last CP/CPS version did not explicitly include the maximum interval between two system configuration checks.
  2. An ETSI auditor identified that the CP/CPS omitted the maximum interval between system configuration checks.
  3. Certigna revised and updated the CP/CPS to specify the maximum interval between system configuration checks.
  4. The auditor validated the resolution of the deviation.
  5. Certigna posted a preliminary incident report describing the CP/CPS omission.
  6. Certigna posted the full incident report findings and a report closure summary requesting closure.
  7. The incident report was scheduled to be closed and the bug reached RESOLVED/FIXED.
Thread Activity
  1. Dhimyotis representative — Posted a preliminary incident report stating the CP/CPS lacked the maximum interval between system configuration checks required by ETSI EN 319 401, with the information instead in the configuration management procedure.
  2. Dhimyotis representative — Posted the full incident report with timeline, stating no certificate impact and that remediation included awareness-raising and CP/CPS revisions to explicitly specify the required maximum interval.
  3. Dhimyotis representative — Submitted a report closure summary stating all disclosed action items were completed and requested closure.
  4. CCADB representative — Issued a final call for comments and noted the closure would occur approximately 2026-06-02.
  5. Community commenter — Questioned why the ticket was not posted by the expected CCADB guideline date and referenced the CCADB incident-report posting timing guidance.
  6. Dhimyotis representative — Acknowledged the timing issue and stated a new incident report was created to address it, linking to bug 2043140.
  7. HARICA — Commented that a CA might wait a few days after submitting a final incident report to allow community review before publishing a closure summary.
  8. Dhimyotis representative — Agreed and said future incident reports will wait longer before publishing closure summaries.
Participants
Dhimyotis representative CCADB representative Community commenter HARICA
Related Bugzilla IDs Mentioned
Similar Local Cases
#1973032 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 100% similar
Certigna: Finding #2 ETSI Audit - Risks regarding the certification of device not described
#1973034 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 100% similar
Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved
#2043140 RESOLVED Self Reported Incident Opened 2026-05-28 · Closed 2026-06-16 · 100% similar
Certigna: Delay in reporting an audit finding
#1667744 RESOLVED Self Reported Incident Opened 2020-09-28 · Closed 2023-02-22 · 87% similar
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
#1973027 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 83% similar
Certigna: Finding #1 ETSI Audit – French translation missing from S/MIME CP/CPS
#2002402 RESOLVED Self Reported Incident Opened 2025-11-25 · Closed 2026-01-13 · 79% similar
GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 78% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 77% similar
IdenTrust: Root OCSP Signer certificate mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action