Server Certificate Working Group Meeting
April 27, 2023
Attendees:
Aaron Gable – (Let’s Encrypt), Adam Jones – (Microsoft), Adrian Mueller – (SwissSign), Bruce Morton – (Entrust), Chad Ehlers – (IdenTrust), Chris Clements – (Google), Clint Wilson – (Apple), Daryn Wright – (GoDaddy), Dimitris Zacharopoulos – (HARICA), Doug Beattie – (GlobalSign), Dustin Hollenback – (Microsoft), Ellie Lu – (TrustAsia Technologies, Inc.), Fumi Yoneda – (Japan Registry Services), Hogeun Yoo – (NAVER Cloud), Inigo Barreira – (Sectigo), Jamie Mackey – (US Federal PKI Management Authority), Janet Hines – (VikingCloud), Joanna Fox – (TrustCor Systems), Jos Purvis – (Fastly), Karina Sirota – (Microsoft), Marco Schambach – (IdenTrust), Martijn Katerbarg – (Sectigo), Nargis Mannan – (VikingCloud), Nate Smith – (GoDaddy), Pedro Fuentes – (OISTE Foundation), Peter Miskovic – (Disig), Rebecca Kelley – (Apple), Ryan Dickson – (Google), Sissel Hoel – (Buypass AS), Sooyoung Eo – (NAVER Cloud), Stephen Davidson – (DigiCert), Tadahiko Ito – (SECOM Trust Systems), Thomas Zermeno – (SSL.com), Tim Hollebeek – (DigiCert), Tobias Josefowitz – (Opera Software AS), Tsung-Min Kuo – (Chunghwa Telecom), Wendy Brown – (US Federal PKI Management Authority), Yoshiro Yoneya – (Japan Registry Services).
Server Certificate Working Group Agenda – 27 April 2023
- Roll Call and Begin Recording (* not needed)
- Read Antitrust Statement (* not needed)
- Review Agenda
- Minutes:
- 16 March: published
- 30 March: not ready yet
- 13 April: circulated within management list on 13/4
- Certificate consumers moratorium
- Update, if needed – Ben was not available to deliver update
- Does this mean that any application for consumers will not be discussed?
- Once requirements are updated, new applicants will need to re-apply.
- BRs format as per SC62 ballot
- Potential issues and solutions
- Ryan Dickson – increased number of tables in BRs 15 fold to improve readability, but this makes some parts like section 7, in paged pdf difficult to read
- Solution is make pageless markdown the default view and offer a pageless pdf as option for download
- Example is page 90
- Other concern, margins decreased making doc harder to read.
- Pagebreaks could be added to make it readable, however this will introduce a manual edit requirement to every ballot.
- On each version creation, the manual portion is redlining, everything else is automated
- The group agreed that this is a readability issue and will try out several solutions.
- Solution is make pageless markdown the default view and offer a pageless pdf as option for download
- Ryan Dickson – increased number of tables in BRs 15 fold to improve readability, but this makes some parts like section 7, in paged pdf difficult to read
- Potential issues and solutions
- Issues to discuss:
- GitHub issues
-
-
- Continue with the review of the open issues
-
-
-
-
- Several have been closed or combined into a ballot Ryan is putting forward.
-
-
- Ballot Status – see list below
- Any Other Business
- Next call: 11 May
- Adjourn
CURRENT STATUS OF BALLOTS
- Passed
- None
- Failed
- None
- Voting Period
- None
- Discussion Period
- None
- Review Period
- None
- Draft / Under Consideration
- SC59 – Revival of Debian Weak Keys Ballot – Chris Kemmerer (SSL.com)
- SCXX – SLO/Response for CRL & OCSP Responses – David Kluge (Google) / Clint Wilson (Apple): on hold
- SCXX – Make OCSP optional, require CRLs – Chris (Google). On hold?
- Want to change update from 7 days to 24 hours while dropping OCSP
- 4.9.7 requires update every 7 days, with next update field to 10 days
- Even if you don’t issue short lived certs – this will impact you, so ballot went from some to all CAs
- Discussion ended for time – moved to email thread
- SCXX – Clean-up ballot
-
-
- Fix inconsistencies between BRs and EVGs
- ISO 3166 (allow 3 characters) in EVG 9.2.8
- Typo in section 7.2.2 of the BRs
- Changing titles in BRs and EVGs to reflect that are for TLS cert types
-