CA/Browser Forum
Home » All CA/Browser Forum Posts » 2026-07-30 Minutes of the Server Certificate Working Group

2026-07-30 Minutes of the Server Certificate Working Group

Minutes for the Server Certificate Working Group teleconference - July 30, 2026

Meeting Date:

  • 2026-07-30

Note Well:

  • Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence.
  • The Note Well was read.
  • Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis.

Review of Agenda:

  • No changes or additions were proposed to the published agenda.

Approval of Minutes:

  • July 2, 2026 Teleconference approved without objection.
  • July 16, 2026 Teleconference approved without objection.

Membership Applications:

  • There were no new membership applications.

Ballot Status:

  • SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward.
  • SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance.
  • Ballots in Voting: None.
  • Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire.
  • Draft Ballots:
    • Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update.
    • Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time.
    • No update was available on Dimitris Zacharopoulos’s revocation timeline ballot.

CCADB Roadmap and API Discussion:

  • Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users.
  • Discussion included:
    • Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting.
    • Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion.
    • Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert.
    • Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion.
    • Stephen Davidson agreed to initiate the mailing list discussion.

Any Other Business:

  • No other business was discussed.

Adjourn

  • The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13.

Attendees:

Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia)

Latest releases
Server Certificate Requirements
SC098: Process RFC 8657 CAA Parameters - Jun 16, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.15 - Ballot SMC017v2 - Jul 30, 2026

This ballot increases the minimum RSA key size for Root and Subordinate CA certificates in the S/MIME BRs from 2048 to 4096 bits for keys created after September 15, 2026, while retaining the 2048-bit minimum for Subscriber certificates. The ballot further requires that by September 15, 2027, CAs SHALL NOT issue Subscriber certificates from any Sub-CA whose RSA key modulus is less than 3072 bits, effectively sunsetting issuance from legacy 2048-bit Sub-CAs. The ballot also includes minor typographic corrections. This ballot is proposed by Martijn Katerbarg (Sectigo) and endorsed by Ben Wilson (Mozilla) and Stephen Davidson (DigiCert)

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).