Closed Bug 2051283 Opened 2 months ago Closed 22 days ago

ANF AC : Delayed Reporting of 2026 Audit Findings

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pablo, Assigned: pablo)

Details

(Whiteboard: [ca-compliance] [disclosure-failure])

Preliminary Incident Report

Summary

Incident description: ANF AC identified that the audit findings from the 2026 ETSI audit were not reported within the timeframes defined by the CCADB Incident Reporting Guidelines.
The delayed reporting resulted from an incorrect assessment of the reportability of the audit findings. The findings themselves are being addressed in their respective incident reports.

Relevant policies: CCADB Incident Reporting Guidelines v3.2
Source of incident disclosure: A comment from the Chrome Root Program in the following Bugzilla incident:
https://bugzilla.mozilla.org/show_bug.cgi?id=2047579#c4

Assignee: nobody → pablo
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]

Full Incident Report

Summary

Incident description:
ANF AC did not report the audit findings within the reporting timelines defined by the CCADB Incident Reporting Guidelines.

Timeline summary

  • Non-compliance start date: 2026-02-20
  • Non-compliance identified date: 2026-06-29
  • Non-compliance end date: 2026-06-15
    Relevant policies:
  • CCADB Incident Reporting Guidelines v3.2
    Source of incident disclosure:
    Comment from the Chrome Root Program in Bug https://bugzilla.mozilla.org/show_bug.cgi?id=2047579#c4

Impact

No impact identified on certificates.

Timeline

Fecha Evento
2026-02-20 ANF AC became aware of the first audit finding identified during the ETSI audit.
2026-03-30 ANF AC became aware of the remaining audit findings identified during the ETSI audit.
2026-06-15 ANF AC received the Audit Attestation Letter (AATL) and published it in CCADB. Based on the understanding at that time that audit findings should be reported once the AATL was publicly available, ANF AC created the three corresponding Bugzilla incident reports (Bugs 2047579, 2047580 and 2047581).
2026-06-29 Chrome Root Program noted that the audit findings should have been reported within the CCADB Incident Reporting Guidelines timelines.
2026-06-29 ANF AC acknowledged the delayed reporting and initiated a separate incident report for this issue.
2026-06-29 Incident reporting procedure updated to clarify the reporting timeline for audit findings.

|

Root Cause Analysis

Root Cause #1

The reportability assessment was based on an incorrect interpretation of the CCADB Incident Reporting Guidelines. ANF AC understood that audit findings requiring public disclosure should be associated with a published Audit Letter in CCADB and therefore postponed the incident reporting until the Audit Letter became publicly available.
This interpretation was influenced by the fact that the audit findings were documentary in nature and did not affect certificate issuance, validation, revocation.
This interpretation was incorrect. The incident should have been reported when ANF AC became aware of the audit findings, independently of the publication status of the Audit Letter.

Contributing Factor #1

ANF AC did not identify a recent public incident report from another CA addressing the same interpretation of the CCADB Incident Reporting Guidelines. As a result, the opportunity to correct the interpretation before publishing the audit finding incident reports was missed.

Detection

The issue was identified following a comment from the Chrome Root Program referencing the applicable public precedent.

Interaction with other factors

None.


Lessons Learned

What went well

The underlying audit findings were corrected promptly.

What didn't go well

Documentary audit findings with no operational impact were incorrectly assessed as reportable only after publication of the AATL, resulting in delayed incident reporting.
The process used to determine whether an incident was reportable did not systematically incorporate relevant public precedents or Root Program guidance.

Where we got lucky

The delay concerned reporting obligations only. No certificates or subscribers were affected.


Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Update the incident assessment procedure to explicitly state that reportability of audit findings shall be assessed independently of the publication status of the Audit Attestation Letter. Prevent Root Cause #1 The incident assessment procedure explicitly defines the reporting trigger for audit findings and requires documenting the reportability assessment. 2026-07-03 Complete
Implement an automated weekly Bugzilla monitoring process using the Bugzilla REST API to identify new or updated CA Certificate Compliance bugs and generate concise summaries of changes. Prevent Root Cause #1 A weekly summary of relevant Bugzilla updates is automatically generated and reviewed as part of the incident assessment process. 2026-07-31 Planned
Raising awareness among the Compliance team regarding the reporting timelines for audit findings and the updates made to our incident reporting procedures. Prevent Root Cause #1, Contributing Factor #1 The updated incident reporting criteria and procedures have been communicated to all members of the Compliance team. 2026-07-03 Complete

As a follow-up to Comment 1, implementation of the Action Item 2 is currently in progress and remains on schedule, due date (2026-07-31).

This report has gone stale. As a reminder, CA Owners may request the “Next update” Whiteboard field be set by a Root Store Operator to align with a specific date related to an open Action Item.

If a "Next update" date has not been requested, updates are expected weekly.

Flags: needinfo?(pablo)

Action Item 2 has been completed.

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Implement an automated weekly Bugzilla monitoring process using the Bugzilla REST API to identify new or updated CA Certificate Compliance bugs and generate concise summaries of changes. Prevent Root Cause #1 A weekly summary of relevant Bugzilla updates is automatically generated and reviewed as part of the incident assessment process. 2026-07-31 Complete

The automated monitoring process has been implemented. New and updated CA Certificate Compliance bugs are gathered through the Bugzilla API, and a weekly summary is generated for our review.

All Action Items associated with this incident have now been completed.

Report Closure Summary

  • Incident description: We did not report three findings from the 2026 ETSI audit within the timelines defined by the CCADB Incident Reporting Guidelines. The findings were reported on 2026-06-15, after publication of the corresponding Audit Attestation Letter. The delayed reporting did not affect certificates or subscribers.

  • Incident Root Cause(s): We incorrectly understood that documentary audit findings requiring public disclosure should be reported after the corresponding Audit Attestation Letter became publicly available. In addition, we did not identify a recent public incident report from another CA that addressed the same interpretation as ours.

  • Remediation description: We updated our incident assessment procedure to state explicitly that the reportability and reporting timelines of audit findings must be assessed inmediately and independently of the publication status of the Audit Attestation Letter. The updated criteria was communicated to the Compliance team. We also implemented an automated weekly Bugzilla monitoring process to identify relevant incidents.

  • Commitment summary:
    N/A. No ongoing commitments remain beyond the completed Action Items.

All Action Items disclosed in this report have been completed as described, and we request its closure.

Flags: needinfo?(pablo) → needinfo?(incident-reporting)

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-08-07.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] → [close on 2026-08-07] [ca-compliance] [disclosure-failure]
Status: ASSIGNED → RESOLVED
Closed: 22 days ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-08-07] [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure]
You need to log in before you can comment on or make changes to this bug.