2026-02-05 Minutes of the Code Signing Certificate Working Group
Code Signing Working Group – Meeting Minutes
Minutes
Tom led the discussion as Martijn was unable to attend.
Tom read the Note Well.
OCSP discussion for Servercert alignment ballot
Karina is discussing internally at Microsoft on how best to proceed. She plans to send an update to the group in the next few days.
Migration to single profile
Tom said sections 1 and 2 of the proposal are available on Github. Tom led the group through the proposal. No concerns were raised on the changes. Corey said it would be good to discuss overall goal before discussing concrete language changes.
Karina said that Microsoft wants more widespread use of code signing but provides strong identity. In particular, the validation should be closer to EV than OV.
Karina said she is working on a ballot that removes phone validation, as methods with durable proof is preferred.
Inigo suggested looking into eIDAS for validation for code signing certificates.
Topics for F2F
Karina said she will send out the proposal for removing phone validation and it can be discussed at the F2F. Corey suggested discussing the single profile at the F2F.
Other business
The group agreed to meet on February 19th to discuss the F2F agenda.
Meeting adjourned. The next meeting will be February 19th.
Attendees
Brian Winters (IdenTrust), Corey Bonnell (DigiCert), Inaba Atsushi (GlobalSign), Iñigo Barreira (Sectigo), Karina Sirota (Microsoft), Luis Cervantes (SSL.com), Marco Schambach (IdenTrust), Nome Huang (TrustAsia), Scott Rea (eMudhra), Thomas Zermeno (SSL.com), Tim Crawford (CPA Canada/WebTrust), Wiktoria Więckowska (Asseco Data Systems SA (Certum))