CA/Browser Forum
Home » All CA/Browser Forum Posts » Ballot 203 – Formation of Network Security Working Group

Ballot 203 – Formation of Network Security Working Group

Results on Ballot 203 – Formation of Network Security Working Group

The voting period for Ballot 203 has ended. The ballot has passed. Here are the results.

Voting by CAs – 19 votes total including abstentions

  • 17 Yes votes: Buypass, CFCA, Comodo, DigiCert, Disig, Entrust, GDCA, GoDaddy, HARICA, Izenpe, SHECA, SSC, SwissSign, Symantec, TrustCor, Trustwave, TurkTrust

  • 0 No votes:

  • 2 Abstain: Actalis, OATI

100% of voting CAs voted in favor

Voting by browsers – 3 votes total including abstentions

  • 2 Yes votes: Microsoft, Mozilla

  • 0 No votes:

  • 1 Abstain: Google

100% of voting browsers voted in favor

Under Bylaw 2.2(g), a ballot result will be considered valid only when more than half of the number of currently active Members has participated. Votes to abstain are counted in determining a quorum. Half of currently active Members as of the start of voting is 9, so quorum was 10 votes – quorum was met.

Bylaw 2.2(f) requires a yes vote by two-thirds of CA votes and 50%-plus-one browser votes for approval. Votes to abstain are not counted for this purpose. This requirement was met for both CAs and browsers.

At least one CA Member and one browser Member must vote in favor of a ballot for the ballot to be adopted. This requirement was met

The ballot passes.

Because this ballot did not propose Final Guidelines or Final Maintenance Guidelines, I do not believe the result implicates our IPR Agreement, and so I will NOT be sending out a Notice of Review Period for this Ballot. If anyone disagrees, please let me know.

Ballot 203: Formation of Network Security Working Group (v2)

Purpose of Ballot: To form a Network Security Working Group to re-evaluate the CAB Forum’s Network Security Guidelines.

The following motion has been proposed by Gervase Markham of Mozilla and endorsed by Jeremy Rowley of DigiCert and Moudrick Dadashov of SSC:

Motion begins

In accordance with Section 5.3 of the CA/B Forum Bylaws, the chartering of a new Working Group requires a ballot. This ballot charters the Network Security Working Group.

The CAB Forum’s Network Security Guidelines were adopted in August 2012 but have not been updated since. Significant doubts have been raised as to their fitness for purpose in 2017. Therefore, the Working Group’s charter will be as follows:

Scope

  1. Consider options for revising, replacing or scrapping the Network Security Guidelines.

Deliverables

  1. A report with one or more proposals for the future of the Network Security Guidelines.

  2. For proposals involving replacement, details of the availability and applicability of the proposed alternative, and what modifications if any would be needed to it in order to make it suitable for use.

  3. For proposals involving revision, details of the revisions that are deemed necessary and how the document will be kept current in the future.

  4. For proposals involving scrapping, an explanation of why this is preferable to either of the other two options.

  5. If there are multiple proposals, optionally a recommendation as to which one to pursue and an associated timeline.

  6. A form of ballot or ballots to implement any recommendations.

Expiry

The Working Group shall expire once the deliverables have been completed, or on 2018-06-19, whichever happens first.

The expiry date given above shall be automatically postponed by 1 year on 2018-05-19 (“postponement date”) and each anniversary of the postponement date thereafter unless three or more members separately or jointly request on the Public Mail List, within one month prior to a particular postponement date, that expiry of this Working Group not be postponed in that instance.

Motion ends

Ballot 203: Formation of Network Security Working Group (v2)

Purpose of Ballot: To form a Network Security Working Group to re-evaluate the CAB Forum’s Network Security Guidelines.

The following motion has been proposed by Gervase Markham of Mozilla and endorsed by Jeremy Rowley of DigiCert and Moudrick Dadashov of SSC:

Motion begins

In accordance with Section 5.3 of the CA/B Forum Bylaws, the chartering of a new Working Group requires a ballot. This ballot charters the Network Security Working Group.

The CAB Forum’s Network Security Guidelines were adopted in August 2012 but have not been updated since. Significant doubts have been raised as to their fitness for purpose in 2017. Therefore, the Working Group’s charter will be as follows:

Scope

  1. Consider options for revising, replacing or scrapping the Network Security Guidelines.

Deliverables

  1. A report with one or more proposals for the future of the Network Security Guidelines.

  2. For proposals involving replacement, details of the availability and applicability of the proposed alternative, and what modifications if any would be needed to it in order to make it suitable for use.

  3. For proposals involving revision, details of the revisions that are deemed necessary and how the document will be kept current in the future.

  4. For proposals involving scrapping, an explanation of why this is preferable to either of the other two options.

  5. If there are multiple proposals, optionally a recommendation as to which one to pursue and an associated timeline.

  6. A form of ballot or ballots to implement any recommendations.

Expiry

The Working Group shall expire once the deliverables have been completed, or on 2018-06-19, whichever happens first.

The expiry date given above shall be automatically postponed by 1 year on 2018-05-19 (“postponement date”) and each anniversary of the postponement date thereafter unless three or more members separately or jointly request on the Public Mail List, within one month prior to a particular postponement date, that expiry of this Working Group not be postponed in that instance.

Motion ends

The procedure for approval of this ballot is as follows:

BALLOT 203

Start time (22:00 UTC)End time (22:00 UTC)
Discussion (7 to 14 days)5th June12th June
Vote for approval (7 days)12th June19th June

Votes must be cast by posting an on-list reply to this thread on the Public list. A vote in favor of the motion must indicate a clear ‘yes’ in the response. A vote against must indicate a clear ‘no’ in the response. A vote to abstain must indicate a clear ‘abstain’ in the response. Unclear responses will not be counted. The latest vote received from any representative of a voting member before the close of the voting period will be counted. Voting members are listed here:

In order for the motion to be adopted, two thirds or more of the votes cast by members in the CA category and greater than 50% of the votes cast by members in the browser category must be in favor. Quorum is shown on CA/Browser Forum wiki. Under Bylaw 2.2(g), at least the required quorum number must participate in the ballot for the ballot to be valid, either by voting in favor, voting against, or abstaining.

Latest releases
Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.7 - Ballot SMC09 - Nov 25, 2024

This ballot includes updates for the following: • Require pre-linting of leaf end entity Certificates starting September 15, 2025 • Require WebTrust for Network Security for audits starting after April 1, 2025 • Clarify that multiple certificatePolicy OIDs are allowed in end entity certificates • Clarify use of organizationIdentifer references • Update of Appendix A.2 Natural Person Identifiers This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Clint Wilson (Apple) and Martijn Katerbarg (Sectigo).

Network and Certificate System Security Requirements
v2.0 - Ballot NS-003 - Jun 26, 2024

Ballot NS-003: Restructure the NCSSRs in https://github.com/cabforum/netsec/pull/35

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).