Certigna: Findings in 2024 ETSI Audit – Audit Incident Report
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: j.allemandou, Assigned: j.allemandou)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Attachments
(5 files)
Audit Incident Report
Findings reported in:
- LSTI Standard Audit Attestation (23-1713-Audit-Attestation-Letter-Standard-V1.0_Certigna_SS.pdf) from 2024-07-10
- LSTI TLS BR Audit Attestation (23-1713-Audit-Attestation-Letter-TLS-BR-V1.0_Certigna_SS.pdf) from 2024-07-10
- LSTI TLS EV Audit Attestation (23-1713-Audit-Attestation-Letter-TLS-EV-V1.0_Certigna_SS.pdf) from 2024-07-10
- LSTI Code Signing BR Audit Attestation (23-1713-Audit-Attestation-Letter_CSBR_V1.0_Certigna_SS.pdf) from 2024-07-10
- LSTI SMIME BR Audit Attestation (23-1713-Audit-Attestation-Letter-SMIME-BR-V1.0_Certigna_SS.pdf) from 2024-07-10.
All non-conformities were observed and closed during an audit carried out on June 28 and 29, 2024.
Finding #1
Deployment of new CA shall be improved. [ETSI EN 319 401 REQ-6.1-07]
Root Cause Analysis
At the time of the audit, the process for issuing new certificates linked to the new CA hierarchies had not been fully activated on the CERTIGNA website, as we wanted to display these products only after the audit had been completed and their conformity recognized.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Deployment of new certificates to demonstrate their delivery directly from CERTIGNA Website. | Mitigate | 2024-06-15 |
| Update of the “Audit Management Procedure” to include directives to activate in production all the services linked to the new CAs before the audit. | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #2
Training of RA operators shall be improved. [ETSI EN 319 401 REQ-7.2-03]
Root Cause Analysis
Guidelines for the use of new future features such as ACME were documented and presented to RA operators, but more detail needed to be provided. We were waiting for the conformity assessment of these functionalities before training the operators on these additional directives.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Update of the “RA’s Application processing procedure” with more directives on the practices related to the new functions and the impacts on their operations. | Prevent | 2024-06-15 |
| Training of RA operators on the changes made to the procedure and support on the implementation of the future functions. | Mitigate | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #4
Documentation of the OIDs in the terms and conditions shall be improved. [ETSI EN 319 411-1 OVR-7.1-02]
Root Cause Analysis
The presentation of OIDs applied to CA certificates and end-entity certificates in Terms and Conditions made more complex the recognition of OIDs.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Clarification of the presentation of OIDs in Terms and Conditions. | Mitigate | 2024-06-25 |
| Update of the “CP, CPS and T&C Management Policy” with guidelines to improve the presentation and the recognition of OIDs. | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #5
Planification of the periodic review of the information security policy shall be improved. [ETSI EN 319 401 REQ-6.3-07]
Root Cause Analysis
The revision of the document had been postponed pending compliance of the Information Security Management System of CERTIGNA with the new version of the ISO/IEC 27001/27002 standards.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| The Information Security Policy has been reviewed with the Top Management. | Mitigate | 2024-06-15 |
| Document Management Procedure has been reviewed and completed with guidelines to respect the frequency of revision. | Prevent | 2024-06-15 |
| New monitoring indicator defined on ISP review | Detect | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #8
Documentation on trusted role shall be improved. [ETSI EN 319 401 REQ-7.1.2-01]
Root Cause Analysis
The directives governing the assignment of trusted roles do not designate all the tools in which these roles must be declared (e.g. HR tool).
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of all tools in which trusted roles must be declared, and update of the HR procedure with these tools. | Mitigate | 2024-06-15 |
| Awareness of person involved. | Prevent | 2024-06-15 |
| Periodic review of the HR procedure. | Detect | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #9
The supervision of the availability of new CAs need to be improved. [ETSI EN 319 401 REQ-7.9-04]
Root Cause Analysis
The new CAs recently generated had not been deployed in production and supervision of their availability has not yet been activated but this was planned when the new CAs were deployed and prior to their use.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Supervision of services related to new CAs has been deployed and controlled. | Mitigate | 2024-06-15 |
| The “Monitoring management procedure” has been updated with directives to manage the deployment of new CAs and ensure the monitoring of their availability. | Prevent | 2024-06-15 |
| Definition of an indicator to check the monitoring of new CA services | Detect | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #10
The Vulnerability Management Procedure shall be improved. [ETSI EN 319 401 REQ-7.9-10]
Root Cause Analysis
Although the vulnerability management process was found to be compliant, the procedure lacked details regarding the timeframes for processing vulnerabilities.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review and update of the vulnerability management procedure with all the requirements regarding vulnerability management. | Mitigate | 2024-06-15 |
| Periodic review of the vulnerability management procedure | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #11
Conditions of certificate acceptance and new Terms and conditions acceptance in the context of the use of ACME shall be improved in the Terms and Conditions. [ETSI EN 319 411-1 OVR-6.3.4-01]
Root Cause Analysis
The ACME service was implemented shortly before the audit was carried out and the description of acceptance procedures in Terms and Conditions was not explicit enough for ACME use. The availability of the ACME service to customers was planned after the audit, and not before September 2024.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the changes brought with the use of ACME to identify modifications to be made to the CP, CPS and Terms and Conditions. | Detect | 2024-06-15 |
| Review and update of the CP, CPS and Terms and conditions with commitments regarding the use of ACME protocol, such as the certificate acceptance, and Terms and Conditions acceptance. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #12
Obligations that the private key must be no longer in use when the issuing CA has been compromised shall be more precisely described within the CPS. [ETSI EN 319 411-1 OVR-6.3.5-01 j]
Root Cause Analysis
The following obligation was already present: no longer use a certificate and delete the associated key pair after the expiry or revocation of this certificate. But this obligation did not explicitly specify the case where the CA is compromised.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the obligations of the subscribers to ensure that no other obligations have been omitted. | Detect | 2024-06-15 |
| Review and update the obligations in the CP, CPS and Terms and Conditions, such as the obligation not to use the private key when the CA has been compromised. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #13
The scope of testing certificates in the CPS shall be more precisely described. [ETSI EN 319 411-1 OVR-6.9.2-01C]
Root Cause Analysis
An internal procedure describes the management of testing certificates in production and their limitation in the context of tests, but explicit commitment in this direction has not been specified in the CPS.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the requirements regarding testing certificates to ensure that no other obligations have been omitted. | Detect | 2024-06-15 |
| Review and update the CP and CPS with an explicit commitment that testing certificates cannot be used outside of the testing scope. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #18
OCSP certificates profiles implementation shall be improved. [ETSI EN 319 411-1 CSS-6.6.3-01B]
Root Cause Analysis
The procedures for storing and renewing OCSP certificates in the event of profile changes were not clearly defined.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Revision and update of the key management procedure with new guidelines for the storage and the renewal of OCSP certificates. | Prevent | 2024-06-15 |
| Generation on HSM of new OCSP certificates. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #20
The persistence of the Identity validation should be more precisely described within the CPS. [ETSI EN 319 411-1 REG-6.3.1-00D]
Root Cause Analysis
The admissibility period of the various identity documents was specified in the CP and CPS but not the period for which identity validation is valid. This information was available in Registration authority procedures and automatic checks are implemented.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the requirements regarding identity validation to ensure that no other information to describe have been omitted. | Prevent | 2024-06-15 |
| Review and update the CP and CPS with the description of the time frame within which a certificate can be issued once identity validation has been carried out. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #22
The RA procedure shall be improved regarding the “OrganizationName” field of legal entity certificates. [ETSI EN 319 411-1 GEN-6.6.1-02]
Root Cause Analysis
The directives related to the personalization of this field to integrate a DBA or tradename were not sufficiently detailed. Automated controls are implemented to pre-fill this field and check this field at the moment of validation.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Update of the RA Procedure with additional guidelines on authorized customization of the "OrganizationName" field, in addition to automated controls. | Mitigate | 2024-06-15 |
| Operator training on guidelines added to procedure. | prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #23
Documentation for new certificates regarding the signature algorithm description shall be improved. [ETSI EN 319 411-1 OVR-5.2-04]
Root Cause Analysis
On the CA currently used, the minimum signing algorithm is RSAwithSHA256. During the definition of new CA and end-entity certificate profiles, it was discussed to switch to RSAwithSHA384 minimum as for CA and this initial target had been recorded in the CP and CPS projects for new CA. After receiving requests from future customers for these new CAs, it was decided to stay on the current configuration, but this was not updated in CP and CPS projects.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the minimum signing algorithm defined in the new CP and CPS, in compliance with the current configuration. | prevent | 2024-06-15 |
| Review and update of CP and CPS of new CAs with the minimum tolerated signature algorithm (RSAwithSHA256). | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #24
Implementation of periodic password change shall be improved.
Root Cause Analysis
The password policy implemented for some functional user workstations was constrained by various standard and tools.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the password policy applied to CA systems and user workstations, with applicable requirements. | detect | 2024-06-15 |
| Review and update of the password policy for the workstations concerned by configuring the password change to more than 2 years. | Mitigate | 2024-06-15 |
| Review and update of the Access Control Policy to highlight this directive for all CA systems and workstations. | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Updated•2 years ago
|
Comment 1•2 years ago
|
||
Hi Certigna,
Thank you for providing this audit incident report. A few questions:
Question #1: Did you intend to attach the audit reports here?
Question #2: Can you improve the level of detail surrounding these findings and the root cause of each? For example, it’s unclear what “Implementation of periodic password change shall be improved.” is intending to communicate. Similarly, “The password policy implemented for some functional user workstations was constrained by various standard and tools.” does not offer actionable detail to help readers understand what specifically was of concern from the auditor’s perspective.
In almost all cases, the “Root Cause Analysis" content in this report is a brief description of what was found to be non-conformant.
From CCADB.org: “The Root Cause Analysis section must contain a detailed analysis of the conditions which combined to give rise to the issue. It is unusual for an incident to have a single root cause; often there must be a confluence of several issues such as a software bug, insufficient checks, and a malformed request. Make sure that all contributing causes are identified and described, including noting when they first arose and how they avoided detection until they were discovered or identified."
In your next update, please minimally make sure the Root Cause Analysis is updated to better consider the above criteria.
| Assignee | ||
Comment 2•2 years ago
|
||
| Assignee | ||
Comment 3•2 years ago
|
||
| Assignee | ||
Comment 4•2 years ago
|
||
| Assignee | ||
Comment 5•2 years ago
|
||
| Assignee | ||
Comment 6•2 years ago
|
||
| Assignee | ||
Comment 7•2 years ago
|
||
Hi,
Below you will find the updated ticket with details and attestations in attachment.
Finding #1
Deployment of new CA shall be improved. [ETSI EN 319 401 REQ-6.1-07]
Root Cause Analysis
At the time of the audit, the process for issuing new certificates linked to the new CA hierarchies had not been fully activated on the CERTIGNA website, as we wanted to display these products only after the audit had been completed and their conformity recognized. The audit preparation process, and particularly the procedure governing our audits, did not clearly determine to what level any new CA generated should be deployed in production for observation, without it yet being certified and accessible to the public.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Deployment of new certificates to demonstrate their delivery directly from CERTIGNA Website. | Mitigate | 2024-06-15 |
| Update of the “Audit Management Procedure” to include directives to activate in production all the services linked to the new CAs before the audit. | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #2
Training of RA operators shall be improved. [ETSI EN 319 401 REQ-7.2-03]
Root Cause Analysis
Guidelines for the use of new future features such as ACME were documented and presented to RA operators, but more details on the process were not specified. This was a planning error for the detailed training, because we were waiting for the conformity assessment of these functionalities to consider any changes requested by the auditors, before training the operators in detail on these future functionalities.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Update of the “RA’s Application processing procedure” with more directives on the practices related to the new functions and the impacts on their operations. | Prevent | 2024-06-15 |
| Training of RA operators on the changes made to the procedure and support on the implementation of the future functions. | Mitigate | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #4
Documentation of the OIDs in the terms and conditions shall be improved. [ETSI EN 319 411-1 OVR-7.1-02]
Root Cause Analysis
The presentation of OIDs applied to CA certificates and end-entity certificates in Terms and Conditions made more complex the recognition of OIDs. The OID declaration guidelines did not specify any format or presentation criteria.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Clarification of the presentation of OIDs in Terms and Conditions. | Mitigate | 2024-06-25 |
| Update of the “CP, CPS and T&C Management Policy” with guidelines to improve the presentation and the recognition of OIDs. | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #5
Planification of the periodic review of the information security policy shall be improved. [ETSI EN 319 401 REQ-6.3-07]
Root Cause Analysis
The revision of the document had been postponed pending compliance of the Information Security Management System of CERTIGNA with the new version of the ISO/IEC 27001/27002 standards. The guidelines and indicators for monitoring and possibly postponing the revision of security policies were not sufficiently clear for these documents, which are reviewed annually.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| The Information Security Policy has been reviewed with the Top Management. | Mitigate | 2024-06-15 |
| Document Management Procedure has been reviewed and completed with guidelines to respect the frequency of revision. | Prevent | 2024-06-15 |
| New monitoring indicator defined on ISP review | Detect | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #8
Documentation on trusted role shall be improved. [ETSI EN 319 401 REQ-7.1.2-01]
Root Cause Analysis
The directives governing the assignment of trusted roles do not designate all the tools in which these roles must be declared (e.g. HR tool). The people in charge of the HR procedure had not updated the procedure, specifying the new tool used to record these roles.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of all tools in which trusted roles must be declared, and update of the HR procedure with these tools. | Mitigate | 2024-06-15 |
| Awareness of person involved | Prevent | 2024-06-15 |
| Periodic review of the HR procedure. | Detect | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #9
The supervision of the availability of new CAs need to be improved. [ETSI EN 319 401 REQ-7.9-04]
Root Cause Analysis
The new CAs recently generated had not been deployed in production and supervision of their availability has not yet been activated but this was planned when the new CAs were deployed and prior to their use. The directives and indicators governing the supervision of a new service did not clearly determine under which stage of the project the supervision of the availability of the service should be activated.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Supervision of services related to new CAs has been deployed and controlled. | Mitigate | 2024-06-15 |
| The “Monitoring management procedure” has been updated with directives to manage the deployment of new CAs and ensure the monitoring of their availability. | Prevent | 2024-06-15 |
| Definition of an indicator to check the monitoring of new CA services | Detect | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #10
The Vulnerability Management Procedure shall be improved. [ETSI EN 319 401 REQ-7.9-10]
Root Cause Analysis
Although the vulnerability management process was found to be compliant, the procedure lacked details regarding the timeframes for processing vulnerabilities. For vulnerability management, the requirements may differ from one applicable standard to another, and the team in charge of this procedure had provided guidelines but with a moderate level of description to meet all the requirements.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Periodic review of the vulnerability management procedure | Prevent | 2024-06-15 |
| Review and update of the vulnerability management procedure | Mitigate | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #11
Conditions of certificate acceptance and new Terms and conditions acceptance in the context of the use of ACME shall be improved in the Terms and Conditions. [ETSI EN 319 411-1 OVR-6.3.4-01]
Root Cause Analysis
The ACME service was implemented shortly before the audit was carried out and the description of acceptance procedures in Terms and Conditions was not explicit enough for ACME use. The error is related to the fact that these evolutions were not planned before the audit was carried out. The availability of the ACME service to customers was planned after the audit, and not before September 2024.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the changes brought with the use of ACME to identify modifications to be made to the CP, CPS and Terms and Conditions. | Detect | 2024-06-15 |
| Review and update of the CP, CPS and Terms and conditions with commitments regarding the use of ACME protocol, such as the certificate acceptance, and Terms and Conditions acceptance. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #12
Obligations that the private key must be no longer in use when the issuing CA has been compromised shall be more precisely described within the CPS. [ETSI EN 319 411-1 OVR-6.3.5-01 j]
Root Cause Analysis
The following obligation was already present: no longer use a certificate and delete the associated key pair after the expiry or revocation of this certificate. But this obligation did not explicitly specify the case where the CA is compromised. This was an error in the description of this obligation which was covered but not sufficiently detailed.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the obligations of the subscribers to ensure that no other obligations have been omitted. | Detect | 2024-06-15 |
| Review and update the obligations in the CP, CPS and Terms and Conditions, such as the obligation not to use the private key when the CA has been compromised. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #13
The scope of testing certificates in the CPS shall be more precisely described. [ETSI EN 319 411-1 OVR-6.9.2-01C]
Root Cause Analysis
An internal procedure describes the management of testing certificates in production and their limitation in the context of tests, but explicit commitment in this direction has not been specified in the CPS. This was an error in the description of this commitment which was not sufficiently detailed in CPS.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the requirements regarding testing certificates to ensure that no other obligations have been omitted. | Detect | 2024-06-15 |
| Review and update the CP and CPS with an explicit commitment that testing certificates cannot be used outside of the testing scope. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #18
OCSP certificates profiles implementation shall be improved. [ETSI EN 319 411-1 CSS-6.6.3-01B]
Root Cause Analysis
The procedures for storing and renewing OCSP certificates in the event of profile changes were not clearly defined with the team in charge of Key Management.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Revision and update of the key management procedure with new guidelines for the storage and the renewal of OCSP certificates. | Prevent | 2024-06-15 |
| Generation on HSM of new OCSP certificates. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #20
The persistence of the Identity validation should be more precisely described within the
CPS. [ETSI EN 319 411-1 REG-6.3.1-00D]
Root Cause Analysis
The admissibility period of the various identity documents was specified in the CP and CPS but not the period for which identity validation is valid. This information was available in Registration authority procedures and automatic checks are implemented. This was an error in the review of this obligation which was covered but not sufficiently detailed in CPS.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the requirements regarding identity validation to ensure that no other information to describe have been omitted. | Prevent | 2024-06-15 |
| Review and update the CP and CPS with the description of the time frame within which a certificate can be issued once identity validation has been carried out. | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #22
The RA procedure shall be improved regarding the “OrganizationName” field of legal entity certificates. [ETSI EN 319 411-1 GEN-6.6.1-02]
Root Cause Analysis
The directives related to the personalization of this field to integrate a DBA or tradename were not sufficiently detailed particularly linked to the fact that automated controls are implemented to pre-fill this field and check this field at the moment of validation.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Update of the RA Procedure with additional guidelines on authorized customization of the "OrganizationName" field, in addition to automated controls. | Mitigate | 2024-06-15 |
| Operator training on guidelines added to procedure. | prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Finding #23
Documentation for new certificates regarding the signature algorithm description shall be improved. [ETSI EN 319 411-1 OVR-5.2-04]
Root Cause Analysis
On the CA currently used, the minimum signing algorithm is RSAwithSHA256. During the definition of new CA and end-entity certificate profiles, it was discussed to switch to RSAwithSHA384 minimum as for CA and this initial target had been recorded in the CP and CPS projects for new CA. After receiving requests from future customers for these new CAs, it was decided to stay on the current configuration, but this was not updated in CP and CPS projects.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the minimum signing algorithm defined in the new CP and CPS, in compliance with the current configuration. | prevent | 2024-06-15 |
| Review and update of CP and CPS of new CAs with the minimum tolerated signature algorithm (RSAwithSHA256). | Mitigate | 2024-06-25 |
Status of actions: Done.
Status of finding: Closed.
Finding #24
Implementation of periodic password change shall be improved.
Root Cause Analysis
The password policy implemented for some functional user workstations was constrained by various standard (e.g. group policies and standard policies) and tools (e.g. MDM, IAM solutions). This is a misconfiguration of the password expiration of some functional user workstations configured in the IAM in alignment with the standard guidelines of our group and not internal policies of our entity.
Action Items
| Action Item | Kind | Due Date |
|---|---|---|
| Review of the password policy applied to CA systems and user workstations, with applicable requirements. | detect | 2024-06-15 |
| Review and update of the password policy for the workstations concerned by configuring the password change to more than 2 years. | Mitigate | 2024-06-15 |
| Review and update of the Access Control Policy to highlight this directive for all CA systems and workstations. | Prevent | 2024-06-15 |
Status of actions: Done.
Status of finding: Closed.
Comment 8•2 years ago
|
||
What other action items exist? If none, then please request that I close this bug with a "Need Info" / "Request information from triage owner".
| Assignee | ||
Comment 9•2 years ago
|
||
Hello Ben,
All actions have been implemented and are operational. All findings are closed since June by the auditor. The ticket can be closed.
Thanks,
Josselin
Comment 10•2 years ago
|
||
I will close this tomorrow, Wed. 28-Aug-2024, unless there are additional items to address.
Updated•2 years ago
|
Description
•