CA/Browser Forum
Home » All CA/Browser Forum Posts » 2026-06-11 Minutes of the Code Signing Certificate Working Group

2026-06-11 Minutes of the Code Signing Certificate Working Group

Code Signing Working Group Minutes

June 11, 2026

Antitrust Reminder

The Note Well was read.

Review of Agenda

The agenda was reviewed. No additional discussion topics were proposed.


Discussion Topics

SCWG Alignment Ballot

Corey Bonnell announced that he will be leaving DigiCert and therefore will not be able to continue serving as the ballot driver for the SCWG alignment ballot.

Corey noted that the ballot has been in discussion phase for approximately a week and a half and that several useful comments had been received on the mailing list. He suggested identifying a new ballot driver and reviewing whether any of the comments also require corresponding changes in the TLS Baseline Requirements.

Martijn Katerbarg volunteered to assume responsibility for driving the ballot. As a result, an additional endorser would be required. Scott Rea agreed to serve as an endorser.

The group also discussed restarting the discussion period in order to incorporate comments received on the mailing list.

Know Your Customer (KYC) and Threat Intelligence Sharing Initiative

Karina Sirota Goodley presented a new Microsoft initiative focused on improving Know Your Customer (KYC) processes and threat intelligence sharing related to code signing abuse.

The initiative follows Microsoft’s recent work investigating the “Storm-1811” operation, which involved abuse of code signing certificates. Microsoft has been collaborating with several CAs on malicious certificate investigations and seeks to formalize information-sharing processes.

Karina explained that the proposal would create a structured framework for sharing threat intelligence and customer-related abuse information between Microsoft and participating CAs. The objective is to improve detection and response capabilities for malicious code signing activities.

The proposal was originally considered as a separate working group but was instead brought to the Code Signing Working Group because of the existing collaboration among relevant stakeholders.

Participants expressed interest in the initiative. Karina noted that additional Microsoft threat intelligence personnel were unable to attend this meeting but are expected to participate in a future meeting to provide more detail on the proposed platform, information-sharing mechanisms, and expected contributions from participants.

The Chair suggested continuing the discussion at future meetings and potentially expanding the topic during a future face-to-face meeting.


Any Other Business

Dean Coclin reminded the group that Working Group Chair and Vice Chair nomination and election activities will occur later in the year.

Thomas Zermeno announced that he intends to step down from the Vice Chair position at the end of the current term due to new responsibilities within SSL.com. Interested participants were encouraged to consider running for the Vice Chair role during the upcoming election cycle.


Adjourn

Attendees

Adam Fiock (SSL.com), Andrea Holland (IdenTrust), Corey Bonnell (DigiCert), Dean Coclin (DigiCert), Inaba Atsushi (GlobalSign), Iñigo Barreira (Sectigo), Karina Sirota (Microsoft), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Lora Randolph (Microsoft), Martijn Katerbarg (Sectigo), Nome Huang (TrustAsia), Scott Rea (eMudhra), Thomas Zermeno (SSL.com), Tim Crawford (CPA Canada/WebTrust), Wiktoria Więckowska (Asseco Data Systems SA (Certum))

Latest releases
Server Certificate Requirements
SC100: DNSSEC Clarification and Consolidation - Sep 7, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.16 - Ballot SMC018 - Sep 29, 2026

This ballot implements the requirements of CCADB Policy Section 6.3 relating to cross-certificates into the S/MIME BR effective immediately. The ballot also specifies that effective July 1, 2027 id-kp-emailProtection (mandatory) and the id-kp-clientAuth (optional) are the only extKeyUsage (EKU) permitted in both Subordinate CA Certificates and Subscriber Certificates. Finally, the ballot clarifies in the Definitions that Legacy Generation profiles were deprecated effective July 15, 2025. This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Dustin Hollinback (Apple) and Ashish Dhiman (GlobalSign)

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).