CA/Browser Forum
Home » All CA/Browser Forum Posts » 2022-11-08 Minutes of the Network Security Working Group

2022-11-08 Minutes of the Network Security Working Group

CA/Browser Forum NetSec Meeting Attendance: Adam Jones – Microsoft; Aaron Poulsen – Amazon Trust Services; Ben Wilson – Mozilla; Clint Wilson – Apple; Corey Rasmussen – OATI; David Kluge – Google; Joanna Fox – TrustCor; Marcelo Silva – Visa; Paul van Brouwershaven – Entrust; Pedro Fuentes – OISTE; Prachi Jain – Fastly; Rebecca Kelley – Apple; Ruben Annemans – GlobalSign; Tim Crawford – BDO; Tobias Josefowitz – Opera

Minutes

Read Antitrust Statement

Clint Wilson read the antitrust statement 2. Roll Call

No new members in attendance 3. Review Agenda

Waiting to approve minutes from previous meeting that was held at the F2F

New Meeting time and link https://cabf.webex.com/cabf/j.php?MTID=m0192d60c00c649d7c4c5d0dfceb74ef2

Risk Assessment/ Cloud Services review (David Kluge)

Continue Air Gapped CAs project (Ben Wilson) 5. Risk Assessment/ Cloud Services

The first round of the assessment is complete. Now in Revision 1 Last call it was decided to move into the drafting stage

The CCM (Cloud Security Alliance Risk Control Matrix) was brought to the attention of the group, and propose a mapping between the CCM and the NSR’s, with additional mapping for the threats that have been identified. Next points to be addressed are to either write requirements or just reference the CCM. Aaron Poulsen commented that this is beneficial, as some are unfamiliar with the cloud control matrix (CCM). They do have a cross-walk with other programs, and feels there should be control requirements that are familiar.

8.Air-Gapped Systems document.

Reviewed slides that were presented at the F2F – Review definitions (Glossary Working Group) – Replace zones – Miscellaneous items b. Look at the possible reorganization of the section “Trusted Roles” – Possibly move into Section 5 (RFC 3647 section) – Section 5.2.1 could possibly work c. Clint suggested an exercise of comparing what has been written and compare it against published version. – Trusted roles may have to be a separate project d. Reviewed Sections 5 and 2

Latest releases
Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.13 - Ballot SMC015v2 - Mar 28, 2026

This ballot introduces requirements that a CA or RA must follow to rely upon a Mobile Drivers License (mDL) to provide evidence for the authentication of individual identity. It allows the use of mDL that conform to ISO/IEC 18013-5 and which may be verified by the CA or RA in conformance with ISO/IEC 18013-7. The CA or RA shall only accept mDL from an Issuing Authority that is legally authorized by the relevant government or jurisdiction to issue driving licenses. The draft also aligns the subsections of 3.2.4.2 (Validation of individual identity) to correspond more closely with those in 3.2.4.1 (Attribute collection of individual identity). It also includes minor editorial corrections. SMC015v2 was updated to remove an additional reference to the superceded ETSI EN 319 403. This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Ben Wilson (Mozilla) and Scott Rea (eMudhra).

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).