CA/Browser Forum
Home » All CA/Browser Forum Posts » 2026-07-16 Minutes of the Server Certificate Working Group

2026-07-16 Minutes of the Server Certificate Working Group

Minutes:

CA/Browser Forum

Server Certificate Working Group Minutes

July 16, 2026

Opening Matters

Dimitris Zacharopoulos chaired the meeting. The meeting was called to order. The meeting was recorded, the list of attendees is below, and the Note Well was read.

Review of Agenda

No changes to the agenda were proposed.

Approval of Minutes

Draft minutes for the July 2, 2026, meeting were not yet available and approval was deferred until the next meeting.

Membership Applications

Beijing Zhongyu Yongxin Network Technology Co., Ltd. (Interested Party)

The Working Group considered the application for Interested Party membership.

Dean Coclin reported that he had reviewed the application and confirmed that it had been properly completed, executed by the organization’s CTO, and included the current IPR agreement.

No objections were raised. The application was approved by consensus. Wayne would notify the applicant and add the organization to the appropriate mailing lists.

Ballot Status

SC-100 – DNSSEC Clarification and Consolidation

  • Rich Smith provided an update on the remaining discussion surrounding evidence retention for DNSSEC validation.

  • The principal remaining issue was whether the ballot should prescribe specific logging requirements. Following discussions with Trevoli Ponds-White (Amazon), the proposal will be to avoid mandating a particular implementation or logging mechanism. Instead, the ballot will be revised to require that CAs retain sufficient evidence demonstrating that DNSSEC validation was performed, while allowing flexibility regarding how that evidence is maintained.

  • Participants generally agreed that this approach would appropriately balance assurance with implementation flexibility.

  • Dimitris noted that the proposed revision also appeared to address concerns previously raised by Henry Birge-Lee on the mailing list regarding acceptable evidence.

  • Rich indicated that revised ballot language would be posted, after which the required discussion period would restart before the ballot could proceed to voting.

SC-103 – Require EKUs for Cross-Certified Subordinate CAs

  • No update was provided because the ballot sponsor was not present.

Ballots Under IPR Review

The Working Group noted that SC-101v2 and SC-102 remained under IPR review.

Recently Published

SC-087 (Registration Number Improvement for EV Certificates) has completed IPR review and the updated EV Guidelines (v2.0.3) have been published.

Draft Ballots Under Consideration

Certificate Problem Reports / Revocation Clarification

  • Martijn Katerbarg reported no update due to being on holiday.

ML-DSA

  • Gurleen Grewal reported that work continues on preparing the ballot preamble before publication.

Revocation Timeline for CP/CPS Deviations

  • Dimitris reported that work has been slower than anticipated and noted that HARICA expects to publish an incident soon involving a CP/CPS documentation mistake, highlighting the practical importance of the proposal.

Any Other Business

None.

Next Meeting

The next Server Certificate Working Group meeting will be held on 30 July 2026.

Meeting Adjourned

Attendees:

Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Arman Asemani (Apple), Ben Wilson (Mozilla), Chris Clements (Google), Clint Wilson (Apple), Daryn Wright (Apple), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Dustin Hollenback (Apple), Georgy Sebastian (Amazon), Gurleen Grewal (Google), Hazhar Ismail (MSC Trustgate Sdn Bhd), Inaba Atsushi (GlobalSign), Jaime Hablutzel (OISTE Foundation), Jeanette Snook (Visa), Johnny Reading (GoDaddy), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kateryna Aleksieieva (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lilia Dubko (CPA Canada/WebTrust), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Martijn Katerbarg (Sectigo), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Polina Glazyrina (Sectigo), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Sven Rajala (Keyfactor), Tadahiko Ito (SECOM Trust Systems), Tobias Josefowitz (Opera Software AS), Trevoli Ponds-White (Amazon), Tsung-Min Kuo (Chunghwa Telecom), Wendy Brown (US Federal PKI Management Authority)

Latest releases
Server Certificate Requirements
SC098: Process RFC 8657 CAA Parameters - Jun 16, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.15 - Ballot SMC017v2 - Jul 30, 2026

This ballot increases the minimum RSA key size for Root and Subordinate CA certificates in the S/MIME BRs from 2048 to 4096 bits for keys created after September 15, 2026, while retaining the 2048-bit minimum for Subscriber certificates. The ballot further requires that by September 15, 2027, CAs SHALL NOT issue Subscriber certificates from any Sub-CA whose RSA key modulus is less than 3072 bits, effectively sunsetting issuance from legacy 2048-bit Sub-CAs. The ballot also includes minor typographic corrections. This ballot is proposed by Martijn Katerbarg (Sectigo) and endorsed by Ben Wilson (Mozilla) and Stephen Davidson (DigiCert)

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).