2023-04-27 Minutes of the Server Certificate Working Group
Server Certificate Working Group Meeting April 27, 2023
Attendees:
Aaron Gable – (Let’s Encrypt), Adam Jones – (Microsoft), Adrian Mueller – (SwissSign), Bruce Morton – (Entrust), Chad Ehlers – (IdenTrust), Chris Clements – (Google), Clint Wilson – (Apple), Daryn Wright – (GoDaddy), Dimitris Zacharopoulos – (HARICA), Doug Beattie – (GlobalSign), Dustin Hollenback – (Microsoft), Ellie Lu – (TrustAsia Technologies, Inc.), Fumi Yoneda – (Japan Registry Services), Hogeun Yoo – (NAVER Cloud), Inigo Barreira – (Sectigo), Jamie Mackey – (US Federal PKI Management Authority), Janet Hines – (VikingCloud), Joanna Fox – (TrustCor Systems), Jos Purvis – (Fastly), Karina Sirota – (Microsoft), Marco Schambach – (IdenTrust), Martijn Katerbarg – (Sectigo), Nargis Mannan – (VikingCloud), Nate Smith – (GoDaddy), Pedro Fuentes – (OISTE Foundation), Peter Miskovic – (Disig), Rebecca Kelley – (Apple), Ryan Dickson – (Google), Sissel Hoel – (Buypass AS), Sooyoung Eo – (NAVER Cloud), Stephen Davidson – (DigiCert), Tadahiko Ito – (SECOM Trust Systems), Thomas Zermeno – (SSL.com), Tim Hollebeek – (DigiCert), Tobias Josefowitz – (Opera Software AS), Tsung-Min Kuo – (Chunghwa Telecom), Wendy Brown – (US Federal PKI Management Authority), Yoshiro Yoneya – (Japan Registry Services).
Server Certificate Working Group Agenda – 27 April 2023
Roll Call and Begin Recording (* not needed)
Read Antitrust Statement (* not needed)
Review Agenda
Minutes:
16 March: published
30 March: not ready yet
13 April: circulated within management list on 13/4
Certificate consumers moratorium
Update, if needed – Ben was not available to deliver update
Does this mean that any application for consumers will not be discussed?
Once requirements are updated, new applicants will need to re-apply.
BRs format as per SC62 ballot
Potential issues and solutions
Ryan Dickson – increased number of tables in BRs 15 fold to improve readability, but this makes some parts like section 7, in paged pdf difficult to read
Solution is make pageless markdown the default view and offer a pageless pdf as option for download
Example is page 90
Other concern, margins decreased making doc harder to read.
Pagebreaks could be added to make it readable, however this will introduce a manual edit requirement to every ballot.
On each version creation, the manual portion is redlining, everything else is automated
The group agreed that this is a readability issue and will try out several solutions.
Issues to discuss:
GitHub issues
- Continue with the review of the open issues
- Several have been closed or combined into a ballot Ryan is putting forward.
- Ballot Status – see list below
- Any Other Business
- Next call: 11 May
- Adjourn
CURRENT STATUS OF BALLOTS
- Passed
- None
- Failed
- None
- Voting Period
- None
- Discussion Period
- None
- Review Period
- None
- Draft / Under Consideration
- SC59 – Revival of Debian Weak Keys Ballot – Chris Kemmerer (SSL.com)
- SCXX – SLO/Response for CRL & OCSP Responses – David Kluge (Google) / Clint Wilson (Apple): on hold
- SCXX – Make OCSP optional, require CRLs – Chris (Google). On hold?
- Want to change update from 7 days to 24 hours while dropping OCSP
- 4.9.7 requires update every 7 days, with next update field to 10 days
- Even if you don’t issue short lived certs – this will impact you, so ballot went from some to all CAs
- Discussion ended for time – moved to email thread
- SCXX – Clean-up ballot
- Fix inconsistencies between BRs and EVGs
- ISO 3166 (allow 3 characters) in EVG 9.2.8
- Typo in section 7.2.2 of the BRs
- Changing titles in BRs and EVGs to reflect that are for TLS cert types