CA/Browser Forum
Home » All CA/Browser Forum Posts » 2026-07-02 Minutes of the Server Certificate Working Group

2026-07-02 Minutes of the Server Certificate Working Group

Minutes:

Meeting Title: Server Certificate Working Group Teleconference

Date: 2026-07-02

Chair: Dimitris Zacharopoulos

Note Taker: Aaron Gable

1. Administrivia

  • Note Well read by Dimitris Zacharopoulos.
  • Roll Call will be taken automatically by Webex. 8 Minutes from the 18 June 2026 meeting (distributed 23 June) are approved.
  • Agenda is approved without changes.

2. Ballot Status

Ballot SC-101: Clarify Authorization Domain Names

  • The voting period just ended.
  • Dimitris intends to begin the IPR period later today.

Ballot SC-102: EVG Domain Ownership Validation Reuse

  • Dustin Hollenback says that the discussion period is extended due to the US holiday. 8 Intends to move it to the voting period around July 6 or 8.

Ballot SC-103: Require EKUs for Cross-Certified Subordinate CAs

  • No updates, still in extended discussion.

Ballot SC-100: DNSSEC Clarification and Consolidation

  • Rich Smith says on-list discussion has been light, and invites additional discussion here.
  • The primary discussion has been about introducing clarity around what CA do need to log, rather than just carve-outs for what they don’t need to log.
  • Rich Smith is open to suggestions for how to clarify that language.
  • Trevoli Ponds-White points out that doing so would change the ballot’s scope from just consolidation to logging changes as well.
  • Rich and Dimitris think it would fall under the existing “clarification” scope.
  • Scott Rea asks if this clarification should actually block the ballot? Maybe it could be saved for a follow-up cleanup ballot.
  • Dimitris says that a cleanup ballot isn’t the right place for changing logging requirements.
  • Trevoli says that they’ll try to put together clearer language in the next week, and that the ballot should just move on if they can’t get consensus on a proposal.

Ballot SC-XX: Improve Certificate Problem Reports

  • No update.

Ballot SC-XX: Allow ML-DSA

  • No update.

3. Adjournment

  • The next meeting will be 16 July, 2026.
  • The meeting is adjourned.

Attendees

Aaron Poulsen (SSL.com), Adam Fiock (SSL.com), Adriano Santoni (Actalis S.p.A.), Arman Asemani (Apple), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Corey Rasmussen (OATI), Cynethia Brown (US Federal PKI Management Authority), Daryn Wright (Apple), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Dustin Hollenback (Apple), Enrico Entschew (D-TRUST), Hazhar Ismail (MSC Trustgate Sdn Bhd), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Iñigo Barreira (Sectigo), Jeanette Snook (Visa), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Lucy Buecking (IdenTrust), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Michael Slaughter (Amazon), Michelle Coon (OATI), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Paul van Brouwershaven (Digitorus), Peter Miskovic (Disig), Polina Glazyrina (Sectigo), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Steven Deitte (GoDaddy), Tim Callan (Sectigo), Tobias Josefowitz (Opera Software AS), Trevoli Ponds-White (Amazon), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Wendy Brown (US Federal PKI Management Authority), Zoey Wang (TrustAsia)

Latest releases
Server Certificate Requirements
SC098: Process RFC 8657 CAA Parameters - Jun 16, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.15 - Ballot SMC017v2 - Jul 30, 2026

This ballot increases the minimum RSA key size for Root and Subordinate CA certificates in the S/MIME BRs from 2048 to 4096 bits for keys created after September 15, 2026, while retaining the 2048-bit minimum for Subscriber certificates. The ballot further requires that by September 15, 2027, CAs SHALL NOT issue Subscriber certificates from any Sub-CA whose RSA key modulus is less than 3072 bits, effectively sunsetting issuance from legacy 2048-bit Sub-CAs. The ballot also includes minor typographic corrections. This ballot is proposed by Martijn Katerbarg (Sectigo) and endorsed by Ben Wilson (Mozilla) and Stephen Davidson (DigiCert)

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).