CA/Browser Forum
Home » All CA/Browser Forum Posts » 2025-06-26 Minutes of the Code Signing Certificate Working Group

2025-06-26 Minutes of the Code Signing Certificate Working Group

Certificate Signing Certificate Working Group (CSCWG) – Meeting Minutes

Date: June 26, 2025

Note Well

The Note Well was read.

Review of Agenda

Agenda reviewed and accepted with the addition of a PQC ballot discussion requested by Brianca.

Approval of Minutes

  • 15 May minutes: Approved without objections.
  • 29 May minutes: Deferred approval to the next meeting due to late distribution.

Discussion Topics

PQC Ballot

  • Corey confirmed readiness, pending input from Microsoft.
  • Karina stated Microsoft is currently not ready to support the ballot, citing ongoing internal evaluations of PQC implications.
  • Brianca raised a concern about halting community progress based on one company’s readiness.
  • Scott suggested shelving the ballot temporarily until Microsoft or other consumers indicate readiness.
  • Bruce raised concerns regarding the voting structure and its appropriateness given the limited number of certificate consumers.
  • Consensus: PQC ballot shelved temporarily until conditions change (either Microsoft readiness or additional consumer engagement).

CSC-30 Ballot Failure and Future Actions

  • Martijn expressed concern over repeated failures of similar ballots (CSC-28, CSC-29, CSC-30) and is hesitant to request further effort without clear progress.
  • Karina acknowledged delays due to recent internal team changes at Microsoft.
  • Nate agreed to follow up internally on another ballot driven by Microsoft, recognizing a pressing deadline.
  • Corey suggested discussing the possibility of splitting CSC-30 into multiple ballots during the next meeting.

Any Other Business

No other business.

Next Meeting

July 10th

Latest releases
Server Certificate Requirements
SC095v3: Clean-up 2025 - Apr 2, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.14 - Ballot SMC016 - May 5, 2026

This ballot maintains consistency between the S/MIME Baseline Requirements and the TLS Baseline Requirements with changes introduced by Ballots SC096 and SC097. Specifically, this ballot: Creates a carve-out of the logging requirements for DNSSEC specifically, stating these are not in scope. For audit purposes, change management logging is able to confirm if the appropriate controls are in effect or not. Sunsets all remaining use of SHA-1 signatures in Certificates and CRLs. It is noted that most uses of SHA-1 signatures are already deprecated by SC097. With this ballot, all unexpired Subordinate CA Certificates issuing S/MIME containing the SHA-1 signature algorithm must be revoked. This proposal does not prohibit the use of SHA-1 to generate issuerKeyHash or issuerNameHash values as currently required by RFC 5019. Includes minor formatting corrections.

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).