CA/Browser Forum
Home » All CA/Browser Forum Posts » Ballot SMC05: Adoption of CAA for S/MIME

Ballot SMC05: Adoption of CAA for S/MIME

The Intellectual Property Review (IPR) period for Ballot SMC05 (Adoption of CAA for S/MIME) has completed. No IPR Exclusion Notices were filed, and the ballot is adopted as of February 20, 2024.

The new S/MIME BR v.1.0.3 have been published to the CABF public website in accordance with the Bylaws: https://cabforum.org/uploads/CA-Browser-Forum-SMIMEBR-1.0.3.pdf

Notice of Review Period SMC05: Adoption of CAA for S/MIME

This Review Notice is sent pursuant to Section 4.1 of the CA/Browser Forum’s Intellectual Property Rights Policy (v1.3). This 30-day Review Period is for the Final Maintenance Guideline that is attached to this Review Notice.

Ballot for Review: Ballot SMC05, redline at https://cabforum.org/wp-content/uploads/CA-Browser-Forum-SMIMEBR-1.0.3-redline.pdf Start of Review Period: January 17, 2024 End of Review Period: 2359 UTC on February 16, 2024 Please forward a written notice to exclude Essential Claims by email to smcwg-public@cabforum.org and a copy to the CA/B Forum public mailing list public@cabforum.org before the end of the Review Period.

See current version of CA/Browser Forum Intellectual Property Rights Policy for details. See also https://cabforum.org/ipr-policy/. An optional format for an Exclusion Notice is available at https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf.

Voting Results

The voting period for Ballot SMC05: Adoption of CAA for S/MIME has completed, and the ballot has passed.

Certificate Issuers

19 votes total, with no abstentions:

  • 19 Issuers voting YES: Actalis S.p.A., Asseco Data Systems SA (Certum), Chunghwa Telecom, DigiCert, D-TRUST, eMudhra, Entrust, GDCA, GlobalSign, HARICA, IdenTrust, OISTE Foundation, SECOM Trust Systems, Sectigo, SSL.com, SwissSign, Telia Company, VikingCloud, Visa
  • 0 Issuers voting NO
  • 0 Issuers ABSTAIN

Certificate Consumers

3 votes total, with no abstentions:

  • 3 Consumers voting YES: Apple, Mozilla, rundQuadrat
  • 0 Consumers voting NO
  • 0 Consumers ABSTAIN

100% of voting Certificate Consumers voted in favor

Bylaws Requirements

  1. Bylaw 2.3(f) requires:
    1. A “yes” vote by two-thirds of Certificate Issuer votes and by 50%-plus-one of Certificate Consumer votes. Votes to abstain are not counted for this purpose. This requirement was MET for Certificate Issuers and MET for Certificate Consumers.
    2. At least one Certificate Issuer and one Certificate Consumer Member must vote in favor of a ballot for the ballot to be adopted. This requirement was MET.
  2. Bylaw 2.3(g) requires that a ballot result only be considered valid when “more than half of the number of currently active Members has participated”. The number of currently active Voting Members is the average number of Voting Member organizations that have participated in the previous three meetings. Votes to abstain are counted in determining quorum. The quorum was 10 for this ballot. This requirement was MET.

This ballot now enters the 30-day IP Rights Review Period to permit members to review the ballot for relevant IP rights issues. The IP Rights Review Period ends at 1700 UTC on December 8, 2023.

Ballot SMC05: Adoption of CAA for S/MIME

Purpose of Ballot:

The ballot proposes changes to the S/MIME Baseline Requirements to introduce the use of Certification Authority Authorization (CAA) Processing for Email Addresses as defined in RFC 9495. It also includes minor typographic corrections.

The following motion has been proposed by Corey Bonnell of DigiCert and endorsed by Dimitris Zacharopoulos of HARICA and Ben Wilson of Mozilla.

Motion begins

This ballot modifies Version 1.0.2 of the “Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates” (“S/MIME Baseline Requirements”) resulting in Version 1.0.3.

The proposed modifications to the S/MIME Baseline Requirements may be found at https://github.com/cabforum/smime/compare/5fb2a7ee94d1c5684d5f32af11572e8c10cd2f8c...1fbbdc8f908e6eba779b4ea0de1cbfd20e156c3a

The SMCWG Chair or Vice-Chair is permitted to update the Relevant Dates and Version Number of the S/MIME Baseline Requirements to reflect final dates.

Motion ends

This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows:

Discussion (7 days)

  • Start Time: Wednesday January 3, 2024 18:00 UTC
  • End Time: Wednesday January 10, 2024 23:30 UTC

Vote for approval (7 days)

  • Start Time: January 10, 2024 23:30 UTC
  • End Time: January 17, 2024 23:30 UTC
Latest releases
Server Certificate Requirements
SC-089: Mass Revocation Planning - Aug 26, 2025

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.12 - Ballot SMC014 - Oct 13, 2025

This ballot introduces requirements that a Certificate Issuer MUST deploy DNSSEC validation back to the IANA DNSSEC root trust anchor on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective, effective March 15, 2026. The ballot is intended to maintain consistency in the S/MIME Baseline Requirements with the requirements of Ballot SC-085 which implemented identical requirements in the TLS Baseline Requirements. Note: SC-085 also introduced requirements in TLS Baseline Requirements for the use of DNSSEC in domain control validation. These requirements are automatically adopted in the S/MIME BR by the email domain control methods that include a normative reference to section 3.2.2.4 of the TLS Baseline Requirements. The draft also includes minor corrections to web links in the text. This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Client Wilson (Apple) and Ashish Dhiman (GlobalSign).

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).