Closed Bug 1907833 Opened 2 years ago Closed 2 years ago

Certigna: Findings in 2024 ETSI Audit – Audit Incident Report

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: j.allemandou, Assigned: j.allemandou)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Attachments

(5 files)

Audit Incident Report

Findings reported in:

  • LSTI Standard Audit Attestation (23-1713-Audit-Attestation-Letter-Standard-V1.0_Certigna_SS.pdf) from 2024-07-10
  • LSTI TLS BR Audit Attestation (23-1713-Audit-Attestation-Letter-TLS-BR-V1.0_Certigna_SS.pdf) from 2024-07-10
  • LSTI TLS EV Audit Attestation (23-1713-Audit-Attestation-Letter-TLS-EV-V1.0_Certigna_SS.pdf) from 2024-07-10
  • LSTI Code Signing BR Audit Attestation (23-1713-Audit-Attestation-Letter_CSBR_V1.0_Certigna_SS.pdf) from 2024-07-10
  • LSTI SMIME BR Audit Attestation (23-1713-Audit-Attestation-Letter-SMIME-BR-V1.0_Certigna_SS.pdf) from 2024-07-10.

All non-conformities were observed and closed during an audit carried out on June 28 and 29, 2024.

Finding #1

Deployment of new CA shall be improved. [ETSI EN 319 401 REQ-6.1-07]

Root Cause Analysis

At the time of the audit, the process for issuing new certificates linked to the new CA hierarchies had not been fully activated on the CERTIGNA website, as we wanted to display these products only after the audit had been completed and their conformity recognized.

Action Items

Action Item Kind Due Date
Deployment of new certificates to demonstrate their delivery directly from CERTIGNA Website. Mitigate 2024-06-15
Update of the “Audit Management Procedure” to include directives to activate in production all the services linked to the new CAs before the audit. Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #2

Training of RA operators shall be improved. [ETSI EN 319 401 REQ-7.2-03]

Root Cause Analysis

Guidelines for the use of new future features such as ACME were documented and presented to RA operators, but more detail needed to be provided. We were waiting for the conformity assessment of these functionalities before training the operators on these additional directives.

Action Items

Action Item Kind Due Date
Update of the “RA’s Application processing procedure” with more directives on the practices related to the new functions and the impacts on their operations. Prevent 2024-06-15
Training of RA operators on the changes made to the procedure and support on the implementation of the future functions. Mitigate 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #4

Documentation of the OIDs in the terms and conditions shall be improved. [ETSI EN 319 411-1 OVR-7.1-02]

Root Cause Analysis

The presentation of OIDs applied to CA certificates and end-entity certificates in Terms and Conditions made more complex the recognition of OIDs.

Action Items

Action Item Kind Due Date
Clarification of the presentation of OIDs in Terms and Conditions. Mitigate 2024-06-25
Update of the “CP, CPS and T&C Management Policy” with guidelines to improve the presentation and the recognition of OIDs. Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #5

Planification of the periodic review of the information security policy shall be improved. [ETSI EN 319 401 REQ-6.3-07]

Root Cause Analysis

The revision of the document had been postponed pending compliance of the Information Security Management System of CERTIGNA with the new version of the ISO/IEC 27001/27002 standards.

Action Items

Action Item Kind Due Date
The Information Security Policy has been reviewed with the Top Management. Mitigate 2024-06-15
Document Management Procedure has been reviewed and completed with guidelines to respect the frequency of revision. Prevent 2024-06-15
New monitoring indicator defined on ISP review Detect 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #8

Documentation on trusted role shall be improved. [ETSI EN 319 401 REQ-7.1.2-01]

Root Cause Analysis

The directives governing the assignment of trusted roles do not designate all the tools in which these roles must be declared (e.g. HR tool).

Action Items

Action Item Kind Due Date
Review of all tools in which trusted roles must be declared, and update of the HR procedure with these tools. Mitigate 2024-06-15
Awareness of person involved. Prevent 2024-06-15
Periodic review of the HR procedure. Detect 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #9

The supervision of the availability of new CAs need to be improved. [ETSI EN 319 401 REQ-7.9-04]

Root Cause Analysis

The new CAs recently generated had not been deployed in production and supervision of their availability has not yet been activated but this was planned when the new CAs were deployed and prior to their use.

Action Items

Action Item Kind Due Date
Supervision of services related to new CAs has been deployed and controlled. Mitigate 2024-06-15
The “Monitoring management procedure” has been updated with directives to manage the deployment of new CAs and ensure the monitoring of their availability. Prevent 2024-06-15
Definition of an indicator to check the monitoring of new CA services Detect 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #10

The Vulnerability Management Procedure shall be improved. [ETSI EN 319 401 REQ-7.9-10]

Root Cause Analysis

Although the vulnerability management process was found to be compliant, the procedure lacked details regarding the timeframes for processing vulnerabilities.

Action Items

Action Item Kind Due Date
Review and update of the vulnerability management procedure with all the requirements regarding vulnerability management. Mitigate 2024-06-15
Periodic review of the vulnerability management procedure Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #11

Conditions of certificate acceptance and new Terms and conditions acceptance in the context of the use of ACME shall be improved in the Terms and Conditions. [ETSI EN 319 411-1 OVR-6.3.4-01]

Root Cause Analysis

The ACME service was implemented shortly before the audit was carried out and the description of acceptance procedures in Terms and Conditions was not explicit enough for ACME use. The availability of the ACME service to customers was planned after the audit, and not before September 2024.

Action Items

Action Item Kind Due Date
Review of the changes brought with the use of ACME to identify modifications to be made to the CP, CPS and Terms and Conditions. Detect 2024-06-15
Review and update of the CP, CPS and Terms and conditions with commitments regarding the use of ACME protocol, such as the certificate acceptance, and Terms and Conditions acceptance. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #12

Obligations that the private key must be no longer in use when the issuing CA has been compromised shall be more precisely described within the CPS. [ETSI EN 319 411-1 OVR-6.3.5-01 j]

Root Cause Analysis

The following obligation was already present: no longer use a certificate and delete the associated key pair after the expiry or revocation of this certificate. But this obligation did not explicitly specify the case where the CA is compromised.

Action Items

Action Item Kind Due Date
Review of the obligations of the subscribers to ensure that no other obligations have been omitted. Detect 2024-06-15
Review and update the obligations in the CP, CPS and Terms and Conditions, such as the obligation not to use the private key when the CA has been compromised. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #13

The scope of testing certificates in the CPS shall be more precisely described. [ETSI EN 319 411-1 OVR-6.9.2-01C]

Root Cause Analysis

An internal procedure describes the management of testing certificates in production and their limitation in the context of tests, but explicit commitment in this direction has not been specified in the CPS.

Action Items

Action Item Kind Due Date
Review of the requirements regarding testing certificates to ensure that no other obligations have been omitted. Detect 2024-06-15
Review and update the CP and CPS with an explicit commitment that testing certificates cannot be used outside of the testing scope. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #18

OCSP certificates profiles implementation shall be improved. [ETSI EN 319 411-1 CSS-6.6.3-01B]

Root Cause Analysis

The procedures for storing and renewing OCSP certificates in the event of profile changes were not clearly defined.

Action Items

Action Item Kind Due Date
Revision and update of the key management procedure with new guidelines for the storage and the renewal of OCSP certificates. Prevent 2024-06-15
Generation on HSM of new OCSP certificates. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #20

The persistence of the Identity validation should be more precisely described within the CPS. [ETSI EN 319 411-1 REG-6.3.1-00D]

Root Cause Analysis

The admissibility period of the various identity documents was specified in the CP and CPS but not the period for which identity validation is valid. This information was available in Registration authority procedures and automatic checks are implemented.

Action Items

Action Item Kind Due Date
Review of the requirements regarding identity validation to ensure that no other information to describe have been omitted. Prevent 2024-06-15
Review and update the CP and CPS with the description of the time frame within which a certificate can be issued once identity validation has been carried out. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #22

The RA procedure shall be improved regarding the “OrganizationName” field of legal entity certificates. [ETSI EN 319 411-1 GEN-6.6.1-02]

Root Cause Analysis

The directives related to the personalization of this field to integrate a DBA or tradename were not sufficiently detailed. Automated controls are implemented to pre-fill this field and check this field at the moment of validation.

Action Items

Action Item Kind Due Date
Update of the RA Procedure with additional guidelines on authorized customization of the "OrganizationName" field, in addition to automated controls. Mitigate 2024-06-15
Operator training on guidelines added to procedure. prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #23

Documentation for new certificates regarding the signature algorithm description shall be improved. [ETSI EN 319 411-1 OVR-5.2-04]

Root Cause Analysis

On the CA currently used, the minimum signing algorithm is RSAwithSHA256. During the definition of new CA and end-entity certificate profiles, it was discussed to switch to RSAwithSHA384 minimum as for CA and this initial target had been recorded in the CP and CPS projects for new CA. After receiving requests from future customers for these new CAs, it was decided to stay on the current configuration, but this was not updated in CP and CPS projects.

Action Items

Action Item Kind Due Date
Review of the minimum signing algorithm defined in the new CP and CPS, in compliance with the current configuration. prevent 2024-06-15
Review and update of CP and CPS of new CAs with the minimum tolerated signature algorithm (RSAwithSHA256). Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #24

Implementation of periodic password change shall be improved.

Root Cause Analysis

The password policy implemented for some functional user workstations was constrained by various standard and tools.

Action Items

Action Item Kind Due Date
Review of the password policy applied to CA systems and user workstations, with applicable requirements. detect 2024-06-15
Review and update of the password policy for the workstations concerned by configuring the password change to more than 2 years. Mitigate 2024-06-15
Review and update of the Access Control Policy to highlight this directive for all CA systems and workstations. Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Assignee: nobody → j.allemandou
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Hi Certigna,

Thank you for providing this audit incident report. A few questions:

Question #1: Did you intend to attach the audit reports here?

Question #2: Can you improve the level of detail surrounding these findings and the root cause of each? For example, it’s unclear what “Implementation of periodic password change shall be improved.” is intending to communicate. Similarly, “The password policy implemented for some functional user workstations was constrained by various standard and tools.” does not offer actionable detail to help readers understand what specifically was of concern from the auditor’s perspective.

In almost all cases, the “Root Cause Analysis" content in this report is a brief description of what was found to be non-conformant.

From CCADB.org: “The Root Cause Analysis section must contain a detailed analysis of the conditions which combined to give rise to the issue. It is unusual for an incident to have a single root cause; often there must be a confluence of several issues such as a software bug, insufficient checks, and a malformed request. Make sure that all contributing causes are identified and described, including noting when they first arose and how they avoided detection until they were discovered or identified."

In your next update, please minimally make sure the Root Cause Analysis is updated to better consider the above criteria.

Hi,
Below you will find the updated ticket with details and attestations in attachment.

Finding #1

Deployment of new CA shall be improved. [ETSI EN 319 401 REQ-6.1-07]

Root Cause Analysis

At the time of the audit, the process for issuing new certificates linked to the new CA hierarchies had not been fully activated on the CERTIGNA website, as we wanted to display these products only after the audit had been completed and their conformity recognized. The audit preparation process, and particularly the procedure governing our audits, did not clearly determine to what level any new CA generated should be deployed in production for observation, without it yet being certified and accessible to the public.

Action Items

Action Item Kind Due Date
Deployment of new certificates to demonstrate their delivery directly from CERTIGNA Website. Mitigate 2024-06-15
Update of the “Audit Management Procedure” to include directives to activate in production all the services linked to the new CAs before the audit. Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #2

Training of RA operators shall be improved. [ETSI EN 319 401 REQ-7.2-03]

Root Cause Analysis

Guidelines for the use of new future features such as ACME were documented and presented to RA operators, but more details on the process were not specified. This was a planning error for the detailed training, because we were waiting for the conformity assessment of these functionalities to consider any changes requested by the auditors, before training the operators in detail on these future functionalities.

Action Items

Action Item Kind Due Date
Update of the “RA’s Application processing procedure” with more directives on the practices related to the new functions and the impacts on their operations. Prevent 2024-06-15
Training of RA operators on the changes made to the procedure and support on the implementation of the future functions. Mitigate 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #4

Documentation of the OIDs in the terms and conditions shall be improved. [ETSI EN 319 411-1 OVR-7.1-02]

Root Cause Analysis

The presentation of OIDs applied to CA certificates and end-entity certificates in Terms and Conditions made more complex the recognition of OIDs. The OID declaration guidelines did not specify any format or presentation criteria.

Action Items

Action Item Kind Due Date
Clarification of the presentation of OIDs in Terms and Conditions. Mitigate 2024-06-25
Update of the “CP, CPS and T&C Management Policy” with guidelines to improve the presentation and the recognition of OIDs. Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #5

Planification of the periodic review of the information security policy shall be improved. [ETSI EN 319 401 REQ-6.3-07]

Root Cause Analysis

The revision of the document had been postponed pending compliance of the Information Security Management System of CERTIGNA with the new version of the ISO/IEC 27001/27002 standards. The guidelines and indicators for monitoring and possibly postponing the revision of security policies were not sufficiently clear for these documents, which are reviewed annually.

Action Items

Action Item Kind Due Date
The Information Security Policy has been reviewed with the Top Management. Mitigate 2024-06-15
Document Management Procedure has been reviewed and completed with guidelines to respect the frequency of revision. Prevent 2024-06-15
New monitoring indicator defined on ISP review Detect 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #8

Documentation on trusted role shall be improved. [ETSI EN 319 401 REQ-7.1.2-01]

Root Cause Analysis

The directives governing the assignment of trusted roles do not designate all the tools in which these roles must be declared (e.g. HR tool). The people in charge of the HR procedure had not updated the procedure, specifying the new tool used to record these roles.

Action Items

Action Item Kind Due Date
Review of all tools in which trusted roles must be declared, and update of the HR procedure with these tools. Mitigate 2024-06-15
Awareness of person involved Prevent 2024-06-15
Periodic review of the HR procedure. Detect 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #9

The supervision of the availability of new CAs need to be improved. [ETSI EN 319 401 REQ-7.9-04]

Root Cause Analysis

The new CAs recently generated had not been deployed in production and supervision of their availability has not yet been activated but this was planned when the new CAs were deployed and prior to their use. The directives and indicators governing the supervision of a new service did not clearly determine under which stage of the project the supervision of the availability of the service should be activated.

Action Items

Action Item Kind Due Date
Supervision of services related to new CAs has been deployed and controlled. Mitigate 2024-06-15
The “Monitoring management procedure” has been updated with directives to manage the deployment of new CAs and ensure the monitoring of their availability. Prevent 2024-06-15
Definition of an indicator to check the monitoring of new CA services Detect 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #10

The Vulnerability Management Procedure shall be improved. [ETSI EN 319 401 REQ-7.9-10]

Root Cause Analysis

Although the vulnerability management process was found to be compliant, the procedure lacked details regarding the timeframes for processing vulnerabilities. For vulnerability management, the requirements may differ from one applicable standard to another, and the team in charge of this procedure had provided guidelines but with a moderate level of description to meet all the requirements.

Action Items

Action Item Kind Due Date
Periodic review of the vulnerability management procedure Prevent 2024-06-15
Review and update of the vulnerability management procedure Mitigate 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #11

Conditions of certificate acceptance and new Terms and conditions acceptance in the context of the use of ACME shall be improved in the Terms and Conditions. [ETSI EN 319 411-1 OVR-6.3.4-01]

Root Cause Analysis

The ACME service was implemented shortly before the audit was carried out and the description of acceptance procedures in Terms and Conditions was not explicit enough for ACME use. The error is related to the fact that these evolutions were not planned before the audit was carried out. The availability of the ACME service to customers was planned after the audit, and not before September 2024.

Action Items

Action Item Kind Due Date
Review of the changes brought with the use of ACME to identify modifications to be made to the CP, CPS and Terms and Conditions. Detect 2024-06-15
Review and update of the CP, CPS and Terms and conditions with commitments regarding the use of ACME protocol, such as the certificate acceptance, and Terms and Conditions acceptance. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #12

Obligations that the private key must be no longer in use when the issuing CA has been compromised shall be more precisely described within the CPS. [ETSI EN 319 411-1 OVR-6.3.5-01 j]

Root Cause Analysis

The following obligation was already present: no longer use a certificate and delete the associated key pair after the expiry or revocation of this certificate. But this obligation did not explicitly specify the case where the CA is compromised. This was an error in the description of this obligation which was covered but not sufficiently detailed.

Action Items

Action Item Kind Due Date
Review of the obligations of the subscribers to ensure that no other obligations have been omitted. Detect 2024-06-15
Review and update the obligations in the CP, CPS and Terms and Conditions, such as the obligation not to use the private key when the CA has been compromised. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #13

The scope of testing certificates in the CPS shall be more precisely described. [ETSI EN 319 411-1 OVR-6.9.2-01C]

Root Cause Analysis

An internal procedure describes the management of testing certificates in production and their limitation in the context of tests, but explicit commitment in this direction has not been specified in the CPS. This was an error in the description of this commitment which was not sufficiently detailed in CPS.

Action Items

Action Item Kind Due Date
Review of the requirements regarding testing certificates to ensure that no other obligations have been omitted. Detect 2024-06-15
Review and update the CP and CPS with an explicit commitment that testing certificates cannot be used outside of the testing scope. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #18

OCSP certificates profiles implementation shall be improved. [ETSI EN 319 411-1 CSS-6.6.3-01B]

Root Cause Analysis

The procedures for storing and renewing OCSP certificates in the event of profile changes were not clearly defined with the team in charge of Key Management.

Action Items

Action Item Kind Due Date
Revision and update of the key management procedure with new guidelines for the storage and the renewal of OCSP certificates. Prevent 2024-06-15
Generation on HSM of new OCSP certificates. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #20

The persistence of the Identity validation should be more precisely described within the
CPS. [ETSI EN 319 411-1 REG-6.3.1-00D]

Root Cause Analysis

The admissibility period of the various identity documents was specified in the CP and CPS but not the period for which identity validation is valid. This information was available in Registration authority procedures and automatic checks are implemented. This was an error in the review of this obligation which was covered but not sufficiently detailed in CPS.

Action Items

Action Item Kind Due Date
Review of the requirements regarding identity validation to ensure that no other information to describe have been omitted. Prevent 2024-06-15
Review and update the CP and CPS with the description of the time frame within which a certificate can be issued once identity validation has been carried out. Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #22

The RA procedure shall be improved regarding the “OrganizationName” field of legal entity certificates. [ETSI EN 319 411-1 GEN-6.6.1-02]

Root Cause Analysis

The directives related to the personalization of this field to integrate a DBA or tradename were not sufficiently detailed particularly linked to the fact that automated controls are implemented to pre-fill this field and check this field at the moment of validation.

Action Items

Action Item Kind Due Date
Update of the RA Procedure with additional guidelines on authorized customization of the "OrganizationName" field, in addition to automated controls. Mitigate 2024-06-15
Operator training on guidelines added to procedure. prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

Finding #23

Documentation for new certificates regarding the signature algorithm description shall be improved. [ETSI EN 319 411-1 OVR-5.2-04]

Root Cause Analysis

On the CA currently used, the minimum signing algorithm is RSAwithSHA256. During the definition of new CA and end-entity certificate profiles, it was discussed to switch to RSAwithSHA384 minimum as for CA and this initial target had been recorded in the CP and CPS projects for new CA. After receiving requests from future customers for these new CAs, it was decided to stay on the current configuration, but this was not updated in CP and CPS projects.

Action Items

Action Item Kind Due Date
Review of the minimum signing algorithm defined in the new CP and CPS, in compliance with the current configuration. prevent 2024-06-15
Review and update of CP and CPS of new CAs with the minimum tolerated signature algorithm (RSAwithSHA256). Mitigate 2024-06-25

Status of actions: Done.
Status of finding: Closed.

Finding #24

Implementation of periodic password change shall be improved.

Root Cause Analysis

The password policy implemented for some functional user workstations was constrained by various standard (e.g. group policies and standard policies) and tools (e.g. MDM, IAM solutions). This is a misconfiguration of the password expiration of some functional user workstations configured in the IAM in alignment with the standard guidelines of our group and not internal policies of our entity.

Action Items

Action Item Kind Due Date
Review of the password policy applied to CA systems and user workstations, with applicable requirements. detect 2024-06-15
Review and update of the password policy for the workstations concerned by configuring the password change to more than 2 years. Mitigate 2024-06-15
Review and update of the Access Control Policy to highlight this directive for all CA systems and workstations. Prevent 2024-06-15

Status of actions: Done.
Status of finding: Closed.

What other action items exist? If none, then please request that I close this bug with a "Need Info" / "Request information from triage owner".

Flags: needinfo?(j.allemandou)

Hello Ben,
All actions have been implemented and are operational. All findings are closed since June by the auditor. The ticket can be closed.
Thanks,
Josselin

Flags: needinfo?(j.allemandou) → needinfo?(bwilson)

I will close this tomorrow, Wed. 28-Aug-2024, unless there are additional items to address.

Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Flags: needinfo?(bwilson)
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: