CA/Browser Forum
Home » All CA/Browser Forum Posts » 2026-06-11 Minutes of the Code Signing Certificate Working Group

2026-06-11 Minutes of the Code Signing Certificate Working Group

Code Signing Working Group Minutes

June 11, 2026

Antitrust Reminder

The Note Well was read.

Review of Agenda

The agenda was reviewed. No additional discussion topics were proposed.


Discussion Topics

SCWG Alignment Ballot

Corey Bonnell announced that he will be leaving DigiCert and therefore will not be able to continue serving as the ballot driver for the SCWG alignment ballot.

Corey noted that the ballot has been in discussion phase for approximately a week and a half and that several useful comments had been received on the mailing list. He suggested identifying a new ballot driver and reviewing whether any of the comments also require corresponding changes in the TLS Baseline Requirements.

Martijn Katerbarg volunteered to assume responsibility for driving the ballot. As a result, an additional endorser would be required. Scott Rea agreed to serve as an endorser.

The group also discussed restarting the discussion period in order to incorporate comments received on the mailing list.

Know Your Customer (KYC) and Threat Intelligence Sharing Initiative

Karina Sirota Goodley presented a new Microsoft initiative focused on improving Know Your Customer (KYC) processes and threat intelligence sharing related to code signing abuse.

The initiative follows Microsoft’s recent work investigating the “Storm-1811” operation, which involved abuse of code signing certificates. Microsoft has been collaborating with several CAs on malicious certificate investigations and seeks to formalize information-sharing processes.

Karina explained that the proposal would create a structured framework for sharing threat intelligence and customer-related abuse information between Microsoft and participating CAs. The objective is to improve detection and response capabilities for malicious code signing activities.

The proposal was originally considered as a separate working group but was instead brought to the Code Signing Working Group because of the existing collaboration among relevant stakeholders.

Participants expressed interest in the initiative. Karina noted that additional Microsoft threat intelligence personnel were unable to attend this meeting but are expected to participate in a future meeting to provide more detail on the proposed platform, information-sharing mechanisms, and expected contributions from participants.

The Chair suggested continuing the discussion at future meetings and potentially expanding the topic during a future face-to-face meeting.


Any Other Business

Dean Coclin reminded the group that Working Group Chair and Vice Chair nomination and election activities will occur later in the year.

Thomas Zermeno announced that he intends to step down from the Vice Chair position at the end of the current term due to new responsibilities within SSL.com. Interested participants were encouraged to consider running for the Vice Chair role during the upcoming election cycle.


Adjourn

Attendees

Adam Fiock (SSL.com), Andrea Holland (IdenTrust), Corey Bonnell (DigiCert), Dean Coclin (DigiCert), Inaba Atsushi (GlobalSign), Iñigo Barreira (Sectigo), Karina Sirota (Microsoft), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Lora Randolph (Microsoft), Martijn Katerbarg (Sectigo), Nome Huang (TrustAsia), Scott Rea (eMudhra), Thomas Zermeno (SSL.com), Tim Crawford (CPA Canada/WebTrust), Wiktoria Więckowska (Asseco Data Systems SA (Certum))

Latest releases
Server Certificate Requirements
SC098: Process RFC 8657 CAA Parameters - Jun 16, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.15 - Ballot SMC017v2 - Jul 30, 2026

This ballot increases the minimum RSA key size for Root and Subordinate CA certificates in the S/MIME BRs from 2048 to 4096 bits for keys created after September 15, 2026, while retaining the 2048-bit minimum for Subscriber certificates. The ballot further requires that by September 15, 2027, CAs SHALL NOT issue Subscriber certificates from any Sub-CA whose RSA key modulus is less than 3072 bits, effectively sunsetting issuance from legacy 2048-bit Sub-CAs. The ballot also includes minor typographic corrections. This ballot is proposed by Martijn Katerbarg (Sectigo) and endorsed by Ben Wilson (Mozilla) and Stephen Davidson (DigiCert)

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).