CA/Browser Forum posts
Posts by author Wayne Thayer
2026-09-10 Minutes of the Server Certificate Working Group
September 10, 2026 by Wayne ThayerServer Certificate Working Group Meeting — 2026-09-10 MinutesMinutes 1. Opening Dimitris Zacharopoulos (HARICA) opened the Server Certificate Working Group teleconference of 2026-09-10. Dimitris Zacharopoulos (HARICA) confirmed the meeting was being recorded and took roll call from Webex. Dustin Hollenback (Apple) took the minutes. The Note Well was read: all participants are reminded that they must comply with the CA/Browser Forum’s Bylaws, which include an Antitrust Policy, a Code of Conduct, and an Intellectual Property Rights Agreement. Participants were directed to contact the Forum Chair with any comments or concerns. The agenda had been sent the previous day. No changes were proposed. 2. Minutes Approval No minutes were available to approve. Daryn Wright (Apple) will circulate the minutes of the previous teleconference as soon as he can. 3. Membership Applications Huawei submitted an application to join the Server Certificate Working Group as a Certificate Consumer. Dimitris Zacharopoulos (HARICA) reported that Dean Coclin (DigiCert) had confirmed the authority of the seal attached to the IPR acceptance letter. Dimitris Zacharopoulos (HARICA) stated he had given the remainder of the application only a quick review and had hoped another member of the working group would review it in detail. Dimitris Zacharopoulos (HARICA) asked whether there were any objections to approving Huawei as a Certificate Consumer, and initially heard none. Tobias Josefowitz (Opera) then asked whether anyone had examined the “provided to the public” element of the membership requirements, noting that some device makers maintain operating systems they do not deploy. Dimitris Zacharopoulos (HARICA) shared his screen and read the charter’s Certificate Consumer definition, which requires that the applicant “provides software intended to be used by the general public for browsing the web securely.” Chad Dandar (Cisco) suggested that, to satisfy Tobias Josefowitz’s question, the group simply read what the applicant had written in that section of the application. Dimitris Zacharopoulos (HARICA) reviewed that section and reported the applicant offers what it calls the Huawei Browser and HarmonyOS, and includes a link to its root certificate program documentation. He noted he had not tested the browser and did not know who could. Tobias Josefowitz (Opera) said that satisfied him. Ryan Dickson (Google Chrome) asked whether the group should first verify that the Certificate Consumer requirements had been met, saying it felt premature to call for objections before confirming the minimum requirements. Tobias Josefowitz (Opera) clarified that he did not necessarily have an objection. His concern was that device makers sometimes maintain operating systems they do not deploy, and he was not certain whether anyone is currently using this one. If people are, he was satisfied on the public requirement. Dimitris Zacharopoulos (HARICA) said it would help him, and help the minutes, to record specifically what the working group considers missing so the applicant can supply it. Tobias Josefowitz (Opera) proposed asking the applicant in which way it makes the browser available and which user group would be using it. Rich Smith (DigiCert) suggested asking how many devices the browser is currently deployed to. Tim Callan (Sectigo) observed that the charter language says “intended to be used,” which would also cover software in advance of deployment, so the number of current users may not be the relevant test. Tobias Josefowitz (Opera) and Rich Smith (DigiCert) both accepted the point. Rich Smith (DigiCert) added that some form of due diligence was still warranted. Tim Callan (Sectigo) responded that if the language is to remain, the group should find a way to verify it, and that revising the language could be an action item, noting he could see a member working toward a deployment it fully intends to make and seeing no reason to discourage that. Wayne Thayer (Fastly) reported that the applicant’s message of 2026-08-27 never reached his inbox and that he had therefore not reviewed the application. He suggested that many members were likely in the same position and proposed either asking the applicant questions or taking another two weeks, reviewing it at the face-to-face. Dimitris Zacharopoulos (HARICA) confirmed the application is in the mailing list archive. Martijn Katerbarg (Sectigo) noted the application states the browser can be downloaded through the Huawei AppGallery, which appears to be the default application store on Huawei devices, comparable to the Samsung app store on Samsung smartphones. Tobias Josefowitz (Opera) performed a web search during the call and reported that the Huawei Browser does appear to be used on Huawei devices, which he considered sufficient to qualify. Chris Clements (Google Chrome) stated that the group does not appear to have a clear standard operating procedure for a new Certificate Consumer. He proposed that the working group offer guidance and assign somebody, or some people, responsibility for verifying the seven charter criteria and presenting that to the group before calling for objections. Dimitris Zacharopoulos (HARICA) agreed to address this at the next meeting. Recorded in the meeting chat, Ryan Dickson (Google Chrome) wrote: “To be clear, my concern was less about this specific request and moreso related to the procedural due diligence that takes place between receiving one of these applications and collecting community objections. Like others said, it would be helpful that if before we ask for objections, someone has reviewed the applicant against the charter criteria and presented that to the group for review before we ask for objections.” Aaron Gable (ISRG) gave a detailed assessment. He noted that Huawei is a major smartphone and operating system vendor and that its browser and TLS validation work, adding that he saw no meaningful quality difference between the Huawei operating system and browser and those of other major Android-based smartphone vendors. He considered criteria one through five clearly met: the applicant provides a software product for browsing the web, provides regular updates, provides documentation requiring certificate issuers to comply with the Baseline Requirements, validates chains of trust, and publishes documentation of the Certification Authorities in its trust store. He identified concerns with criteria six and seven. On criterion six, the applicant’s root program requirements direct issuers to submit an application to an email address but give no indication of what the application is or where to obtain a form. On criterion seven, the requirements direct issuers to report misissuance immediately but provide no contact address or method. He also noted that ISRG’s Root CA Certificates are included in the Huawei trust store without any communication to ISRG about when or why, and that ISRG has never disclosed an incident directly to Huawei. Outcome: the application was not approved. The working group will seek clarification from the applicant on criteria six and seven, a member will verify that the browser functions, and the application will be discussed at the face-to-face meeting. 4. Face-to-Face 68 Agenda Ryan Dickson (Google Chrome) had circulated a list of four proposed topics: (1) Section 7 cleanup and modernizing certificate profile expectations, including revisiting the legacy framing around technically constrained Subordinate CAs; (2) profile-specific linting expectations, moving beyond generic Baseline Requirements minimums toward validating against a CA Owner’s explicitly stated commitments and profiles; (3) aligning the Baseline Requirements with dedicated hierarchy expectations, defining TLS-specific Subordinate CA profiles and a future timeline requiring certificates chaining to them to lead to Root CA Certificates serving TLS use cases exclusively; and (4) domain transparency and issuance information, revisiting the SC-093 discussion of domain control validation methods in certificates. Dimitris Zacharopoulos (HARICA) had separately proposed a topic on CP versus CPS versus CP/CPS and on expectations for RFC 2119 language. Dimitris Zacharopoulos (HARICA) said he will open the working group session at the face-to-face with a summary of activity since the previous face-to-face, covering the changes and the pull requests released since. Ben Wilson (Mozilla) is working on the revocation circumstances topic and has started preparing a small task force for that area. Topic 1, Section 7 cleanup and modernizing certificate profile expectations, was added to the agenda, the group having previously been in favor. Aaron Gable (ISRG) stated he was most interested in topic 1 and second most interested in topic 3, which aligns with his SC-103 ballot. He considered topics 2, 3, and 4 low priority and did not want to displace other business by including them. Ryan Dickson (Google Chrome) considered topic 4 premature and said it should not be discussed. He reported he has started slides and a GitHub pull request covering topics 1, 2, and 3, which he considers interrelated because they all touch Section 7. He described four or five concrete proposed changes: consolidating the current tabular inheritance, where reading one certificate profile requires consulting roughly ten tables, into a single table per profile carrying all fields and extensions with no cross-references unless absolutely necessary, which he described as preventing the wild goose chase implementers face today; identifying profiles that could be removed or sunset, making no commentary on timing; and establishing a clear expectation that Certification Authorities define in their policies exactly what they do, which creates a path to CA-specific linting and should dramatically reduce the likelihood of mass misissuance events. Dimitris Zacharopoulos (HARICA) suggested discussing the topics in the sequence 1, then 3, then 2, so that linting expectations come after the hierarchies and content expectations are settled. Ryan Dickson (Google Chrome) said the group could take them in any order but asked that they be considered collectively, since each influences the others, and that it would be useful to state what the finished product is hoped to look like even if that is years away. Dimitris Zacharopoulos (HARICA) proposed inviting two external parties who have worked on machine-readable profile formats and linting to participate in that portion of the meeting as interested parties. Ryan Dickson (Google Chrome) asked first whether existing working group members had already thought about or implemented such solutions and would share their experience as both an issuer and an implementer. Dimitris Zacharopoulos (HARICA) said HARICA is designing such a solution as part of an action plan for a recent incident but has nothing concrete to present or discuss beyond design issues. Aaron Gable (ISRG) said ISRG has spent time on this, and that one of its recent incident reports involved writing custom linters to enforce each of its CP/CPS profiles. He was reticent to commit to presenting because the Server Certificate Working Group session at the face-to-face is at 04:30 his local time and he did not know how much of it he would attend. Rich Smith (DigiCert) said he is working on something in the same subject area but could not guarantee it would be ready to demonstrate at the face-to-face. Dimitris Zacharopoulos (HARICA) asked him to send a message if it is, so that time could be allocated for a presentation. Dimitris Zacharopoulos (HARICA) will update the wiki to reflect the decisions taken, and asked that any further proposed topics be sent to the list or to him directly. He noted the topics already agreed will cover the working group’s two-hour allocation at the face-to-face. 5. Ballot Status In Discussion Period:
September 10, 2026 by Wayne ThayerServer Certificate Working Group Meeting — 2026-09-10 MinutesMinutes 1. Opening Dimitris Zacharopoulos (HARICA) opened the Server Certificate Working Group teleconference of 2026-09-10. Dimitris Zacharopoulos (HARICA) confirmed the meeting was being recorded and took roll call from Webex. Dustin Hollenback (Apple) took the minutes. The Note Well was read: all participants are reminded that they must comply with the CA/Browser Forum’s Bylaws, which include an Antitrust Policy, a Code of Conduct, and an Intellectual Property Rights Agreement. Participants were directed to contact the Forum Chair with any comments or concerns. The agenda had been sent the previous day. No changes were proposed. 2. Minutes Approval No minutes were available to approve. Daryn Wright (Apple) will circulate the minutes of the previous teleconference as soon as he can. 3. Membership Applications Huawei submitted an application to join the Server Certificate Working Group as a Certificate Consumer. Dimitris Zacharopoulos (HARICA) reported that Dean Coclin (DigiCert) had confirmed the authority of the seal attached to the IPR acceptance letter. Dimitris Zacharopoulos (HARICA) stated he had given the remainder of the application only a quick review and had hoped another member of the working group would review it in detail. Dimitris Zacharopoulos (HARICA) asked whether there were any objections to approving Huawei as a Certificate Consumer, and initially heard none. Tobias Josefowitz (Opera) then asked whether anyone had examined the “provided to the public” element of the membership requirements, noting that some device makers maintain operating systems they do not deploy. Dimitris Zacharopoulos (HARICA) shared his screen and read the charter’s Certificate Consumer definition, which requires that the applicant “provides software intended to be used by the general public for browsing the web securely.” Chad Dandar (Cisco) suggested that, to satisfy Tobias Josefowitz’s question, the group simply read what the applicant had written in that section of the application. Dimitris Zacharopoulos (HARICA) reviewed that section and reported the applicant offers what it calls the Huawei Browser and HarmonyOS, and includes a link to its root certificate program documentation. He noted he had not tested the browser and did not know who could. Tobias Josefowitz (Opera) said that satisfied him. Ryan Dickson (Google Chrome) asked whether the group should first verify that the Certificate Consumer requirements had been met, saying it felt premature to call for objections before confirming the minimum requirements. Tobias Josefowitz (Opera) clarified that he did not necessarily have an objection. His concern was that device makers sometimes maintain operating systems they do not deploy, and he was not certain whether anyone is currently using this one. If people are, he was satisfied on the public requirement. Dimitris Zacharopoulos (HARICA) said it would help him, and help the minutes, to record specifically what the working group considers missing so the applicant can supply it. Tobias Josefowitz (Opera) proposed asking the applicant in which way it makes the browser available and which user group would be using it. Rich Smith (DigiCert) suggested asking how many devices the browser is currently deployed to. Tim Callan (Sectigo) observed that the charter language says “intended to be used,” which would also cover software in advance of deployment, so the number of current users may not be the relevant test. Tobias Josefowitz (Opera) and Rich Smith (DigiCert) both accepted the point. Rich Smith (DigiCert) added that some form of due diligence was still warranted. Tim Callan (Sectigo) responded that if the language is to remain, the group should find a way to verify it, and that revising the language could be an action item, noting he could see a member working toward a deployment it fully intends to make and seeing no reason to discourage that. Wayne Thayer (Fastly) reported that the applicant’s message of 2026-08-27 never reached his inbox and that he had therefore not reviewed the application. He suggested that many members were likely in the same position and proposed either asking the applicant questions or taking another two weeks, reviewing it at the face-to-face. Dimitris Zacharopoulos (HARICA) confirmed the application is in the mailing list archive. Martijn Katerbarg (Sectigo) noted the application states the browser can be downloaded through the Huawei AppGallery, which appears to be the default application store on Huawei devices, comparable to the Samsung app store on Samsung smartphones. Tobias Josefowitz (Opera) performed a web search during the call and reported that the Huawei Browser does appear to be used on Huawei devices, which he considered sufficient to qualify. Chris Clements (Google Chrome) stated that the group does not appear to have a clear standard operating procedure for a new Certificate Consumer. He proposed that the working group offer guidance and assign somebody, or some people, responsibility for verifying the seven charter criteria and presenting that to the group before calling for objections. Dimitris Zacharopoulos (HARICA) agreed to address this at the next meeting. Recorded in the meeting chat, Ryan Dickson (Google Chrome) wrote: “To be clear, my concern was less about this specific request and moreso related to the procedural due diligence that takes place between receiving one of these applications and collecting community objections. Like others said, it would be helpful that if before we ask for objections, someone has reviewed the applicant against the charter criteria and presented that to the group for review before we ask for objections.” Aaron Gable (ISRG) gave a detailed assessment. He noted that Huawei is a major smartphone and operating system vendor and that its browser and TLS validation work, adding that he saw no meaningful quality difference between the Huawei operating system and browser and those of other major Android-based smartphone vendors. He considered criteria one through five clearly met: the applicant provides a software product for browsing the web, provides regular updates, provides documentation requiring certificate issuers to comply with the Baseline Requirements, validates chains of trust, and publishes documentation of the Certification Authorities in its trust store. He identified concerns with criteria six and seven. On criterion six, the applicant’s root program requirements direct issuers to submit an application to an email address but give no indication of what the application is or where to obtain a form. On criterion seven, the requirements direct issuers to report misissuance immediately but provide no contact address or method. He also noted that ISRG’s Root CA Certificates are included in the Huawei trust store without any communication to ISRG about when or why, and that ISRG has never disclosed an incident directly to Huawei. Outcome: the application was not approved. The working group will seek clarification from the applicant on criteria six and seven, a member will verify that the browser functions, and the application will be discussed at the face-to-face meeting. 4. Face-to-Face 68 Agenda Ryan Dickson (Google Chrome) had circulated a list of four proposed topics: (1) Section 7 cleanup and modernizing certificate profile expectations, including revisiting the legacy framing around technically constrained Subordinate CAs; (2) profile-specific linting expectations, moving beyond generic Baseline Requirements minimums toward validating against a CA Owner’s explicitly stated commitments and profiles; (3) aligning the Baseline Requirements with dedicated hierarchy expectations, defining TLS-specific Subordinate CA profiles and a future timeline requiring certificates chaining to them to lead to Root CA Certificates serving TLS use cases exclusively; and (4) domain transparency and issuance information, revisiting the SC-093 discussion of domain control validation methods in certificates. Dimitris Zacharopoulos (HARICA) had separately proposed a topic on CP versus CPS versus CP/CPS and on expectations for RFC 2119 language. Dimitris Zacharopoulos (HARICA) said he will open the working group session at the face-to-face with a summary of activity since the previous face-to-face, covering the changes and the pull requests released since. Ben Wilson (Mozilla) is working on the revocation circumstances topic and has started preparing a small task force for that area. Topic 1, Section 7 cleanup and modernizing certificate profile expectations, was added to the agenda, the group having previously been in favor. Aaron Gable (ISRG) stated he was most interested in topic 1 and second most interested in topic 3, which aligns with his SC-103 ballot. He considered topics 2, 3, and 4 low priority and did not want to displace other business by including them. Ryan Dickson (Google Chrome) considered topic 4 premature and said it should not be discussed. He reported he has started slides and a GitHub pull request covering topics 1, 2, and 3, which he considers interrelated because they all touch Section 7. He described four or five concrete proposed changes: consolidating the current tabular inheritance, where reading one certificate profile requires consulting roughly ten tables, into a single table per profile carrying all fields and extensions with no cross-references unless absolutely necessary, which he described as preventing the wild goose chase implementers face today; identifying profiles that could be removed or sunset, making no commentary on timing; and establishing a clear expectation that Certification Authorities define in their policies exactly what they do, which creates a path to CA-specific linting and should dramatically reduce the likelihood of mass misissuance events. Dimitris Zacharopoulos (HARICA) suggested discussing the topics in the sequence 1, then 3, then 2, so that linting expectations come after the hierarchies and content expectations are settled. Ryan Dickson (Google Chrome) said the group could take them in any order but asked that they be considered collectively, since each influences the others, and that it would be useful to state what the finished product is hoped to look like even if that is years away. Dimitris Zacharopoulos (HARICA) proposed inviting two external parties who have worked on machine-readable profile formats and linting to participate in that portion of the meeting as interested parties. Ryan Dickson (Google Chrome) asked first whether existing working group members had already thought about or implemented such solutions and would share their experience as both an issuer and an implementer. Dimitris Zacharopoulos (HARICA) said HARICA is designing such a solution as part of an action plan for a recent incident but has nothing concrete to present or discuss beyond design issues. Aaron Gable (ISRG) said ISRG has spent time on this, and that one of its recent incident reports involved writing custom linters to enforce each of its CP/CPS profiles. He was reticent to commit to presenting because the Server Certificate Working Group session at the face-to-face is at 04:30 his local time and he did not know how much of it he would attend. Rich Smith (DigiCert) said he is working on something in the same subject area but could not guarantee it would be ready to demonstrate at the face-to-face. Dimitris Zacharopoulos (HARICA) asked him to send a message if it is, so that time could be allocated for a presentation. Dimitris Zacharopoulos (HARICA) will update the wiki to reflect the decisions taken, and asked that any further proposed topics be sent to the list or to him directly. He noted the topics already agreed will cover the working group’s two-hour allocation at the face-to-face. 5. Ballot Status In Discussion Period:
2026-08-27 Minutes of the Server Certificate Working Group
August 27, 2026 by Wayne ThayerFinal minutes for the CA/Browser Forum Server Certificate Working group - August 27, 2026Meeting Date: 2026-08-27 Note Well: Dimitris Zacharopoulos chaired the meeting.
August 27, 2026 by Wayne ThayerFinal minutes for the CA/Browser Forum Server Certificate Working group - August 27, 2026Meeting Date: 2026-08-27 Note Well: Dimitris Zacharopoulos chaired the meeting.
2026-08-13 Minutes of the Server Certificate Working Group
August 13, 2026 by Wayne ThayerFinal minutes for the Server Certificate Working Group teleconference - August 13, 2026Meeting Date: 2026-08-13 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The meeting was recorded and the Note Well was read. Review of Agenda: No changes were made to the published agenda. Approval of Minutes: July 30, 2026 Teleconference approved without objection. Membership Applications: Wayne Thayer introduced an Interested Party application from GÉANT. Dean Coclin raised a question regarding whether the individual, Nicole Harris, who signed the application as Head of Security had sufficient authority to bind the organization to the IPR Agreement. Stephen Davidson noted that GÉANT is part of the European research and education network community and provides services to universities. Scott Rea noted that Nicole Harris typically represents GÉANT in working groups. Dean Coclin noted that Forum agreements have historically been signed by someone with authority to bind the organization, typically an executive or someone from legal. Dustin Hollenback asked how the Forum determines whether a signatory has the necessary authority. Dean Coclin suggested requesting confirmation that the signatory has authority to bind GÉANT. He noted that previous inquiries of this type have generally resulted either in confirmation of the signatory’s authority or a new signature from an appropriately authorized individual. Dean Coclin will follow up with GÉANT regarding the signatory’s authority, and the application will be revisited after a response is received. Ballot Status: SC-102: Wayne Thayer reported that SC-102 had completed its IPR Review Period. A new version of the TLS Baseline Requirements incorporating SC-102 was published earlier in the day. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: SC-103 remains in the Discussion Period. No additional discussion occurred. SC-100 - DNSSEC Clarification and Consolidation: SC-100 recently entered the IPR Review Period. Draft Ballots: Improved Certificate Problem Reports and Clarify the Meaning of Revocation: Martijn Katerbarg reported that he intends to address what he hopes is the final outstanding comment and then move the ballot forward. Allow ML-DSA: Stephen Davidson and Gurleen Grewal reported that work continues toward a combined ballot. Gurleen Grewal indicated that the work is getting close to completion. Georgy Sebastian reported on behalf of Amazon Trust Services that Michael Slaughter had updated the proposal and was seeking feedback on the proposed language. Georgy Sebastian shared the latest version during the meeting. Gurleen Grewal indicated that the newly shared version should be considered the canonical version and that links to the other PRs could be removed. Wayne Thayer indicated that the ballot tracking information would be updated accordingly. Revocation Timeline for CP/CPS Deviations: Dimitris Zacharopoulos was not present to provide an update. The item was tabled. Any Other Business: SC-101v2 and Reuse of Validation Data: Wayne Thayer raised a mailing list question concerning Section 4.2.1 and reuse of validation data following changes to validation requirements. The specific question was whether permitted reuse continues when a validation method is indirectly affected by a change to a definition on which the method relies. Dustin Hollenback initially expressed concern about allowing reuse following such a change but noted the practical difficulty of expecting CAs and Root Programs to track indirect changes to definitions outside the validation method itself. Dustin Hollenback noted that, particularly as validation reuse periods continue to decrease, allowing reuse in this situation may be a reasonable approach and would avoid creating compliance “gotchas” without a clear ecosystem benefit. Wayne Thayer agreed that this was consistent with his reading of the requirement and stated that the language appears intended to prevent existing validations from immediately becoming unusable following a requirements change. Dustin Hollenback distinguished an indirect change to an external definition from a direct change to the validation method itself and questioned whether the same treatment should apply to a direct change. Wayne Thayer noted that Section 4.2.1 explicitly permits reuse following a change to a validation method for the applicable reuse period unless the ballot making the change specifically provides otherwise. Rich Smith noted that he believed the relevant reuse language may predate SC-101. The discussion generally supported the interpretation that reuse remains permitted for the applicable reuse period unless the ballot introducing the change specifically prohibits it. Wayne Thayer indicated that the minutes from the discussion could be used to help respond to the mailing list question. Attendance by Members of Other Working Groups: Wayne Thayer raised a question from a member of another CA/Browser Forum Working Group who wanted to attend the Forum Plenary teleconference but was not a member of the Server Certificate Working Group. Because the Forum Plenary begins immediately after the SCWG teleconference, the individual asked whether they could join the SCWG call while waiting for the Forum portion to begin. Martijn Katerbarg noted that face-to-face meetings provide precedent for allowing attendees to be present during sessions of Working Groups to which they do not belong. He suggested that such individuals be permitted to listen but not participate in the SCWG discussion. Martijn Katerbarg also noted that the Forum portion of the call can begin earlier than scheduled, making it difficult for a participant to know precisely when to join if they cannot listen to the preceding SCWG meeting. Dean Coclin agreed that allowing the individual to listen without participating in the SCWG discussion was reasonable. Arman Asemani suggested reversing the order of the calls so that the Forum Plenary occurs first and non-SCWG members can leave before the SCWG meeting begins. Dean Coclin, Martijn Katerbarg, Dustin Hollenback, and Wayne Thayer discussed the previous ordering of the calls and recalled that the order had been changed in part because of differences in meeting duration. Andrea Holland noted that holding the Forum Plenary first would also allow participants who do not wish to attend the SCWG meeting to leave afterward. Dean Coclin indicated that he would be open to changing the order but wanted Dimitris Zacharopoulos’s input. Wayne Thayer summarized the discussion as supporting allowing the individual to join the SCWG portion as an observer but not participate in the discussion. The group will separately consider whether to change the ordering of the Forum Plenary and SCWG teleconferences. Adjourn: The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-27. Attendees: Arman Asemani (Apple), Nate Smith (GoDaddy), Zoey Wang, Logan Mabe (Microsoft), Rollin Yu (TrustAsia), Jun Okura (Cybertrust), Andrea Holland (IdenTrust), Martijn Katerbarg (Sectigo), Gurleen Grewal (GTS), Hogeun Yoo (NAVER Cloud Trust Services), Alvin Wang (SHECA), Sándor Szőke (Microsec), Ben Wilson (Mozilla), Clint Wilson, Tobias Josefowitz (Opera), Moritz Schaal (D-Trust), Polina Glazyrina (Sectigo), Adam Jones (Microsoft), Kateryna Aleksieieva (Certum by Asseco), Sean Huang (TWCA), Lucy Buecking (IdenTrust), Dustin Hollenback, Scott Rea (eMudhra), Kiran Tummala, Paul van Brouwershaven (Digitorus), Karina Goodley, Cynetheia Brown (FPKIMA), Janet Hines (SSL.com), Nome Huang (TrustAsia), Chris Clements (Google Chrome), Daryn Wright, Li-Chun Chen (Chunghwa Telecom), Stephen Davidson (DigiCert), Atsushi Inaba (GlobalSign), Tsung-Min Kuo (Chunghwa Telecom), Rich Smith (DigiCert), Ryan Dickson (Google Chrome), Dean Coclin (DigiCert), Fumiaki Ono (SECOM Trust Systems), Steven Deitte (GoDaddy), Georgy Sebastian (Amazon Trust Services), Jos Purvis (Fastly), Sandy Balzer (SwissSign), Luis Cervantes (SSL.com), Aaron Poulsen (SSL.com), Rob White (GoDaddy), Wayne Thayer (Fastly)
August 13, 2026 by Wayne ThayerFinal minutes for the Server Certificate Working Group teleconference - August 13, 2026Meeting Date: 2026-08-13 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The meeting was recorded and the Note Well was read. Review of Agenda: No changes were made to the published agenda. Approval of Minutes: July 30, 2026 Teleconference approved without objection. Membership Applications: Wayne Thayer introduced an Interested Party application from GÉANT. Dean Coclin raised a question regarding whether the individual, Nicole Harris, who signed the application as Head of Security had sufficient authority to bind the organization to the IPR Agreement. Stephen Davidson noted that GÉANT is part of the European research and education network community and provides services to universities. Scott Rea noted that Nicole Harris typically represents GÉANT in working groups. Dean Coclin noted that Forum agreements have historically been signed by someone with authority to bind the organization, typically an executive or someone from legal. Dustin Hollenback asked how the Forum determines whether a signatory has the necessary authority. Dean Coclin suggested requesting confirmation that the signatory has authority to bind GÉANT. He noted that previous inquiries of this type have generally resulted either in confirmation of the signatory’s authority or a new signature from an appropriately authorized individual. Dean Coclin will follow up with GÉANT regarding the signatory’s authority, and the application will be revisited after a response is received. Ballot Status: SC-102: Wayne Thayer reported that SC-102 had completed its IPR Review Period. A new version of the TLS Baseline Requirements incorporating SC-102 was published earlier in the day. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: SC-103 remains in the Discussion Period. No additional discussion occurred. SC-100 - DNSSEC Clarification and Consolidation: SC-100 recently entered the IPR Review Period. Draft Ballots: Improved Certificate Problem Reports and Clarify the Meaning of Revocation: Martijn Katerbarg reported that he intends to address what he hopes is the final outstanding comment and then move the ballot forward. Allow ML-DSA: Stephen Davidson and Gurleen Grewal reported that work continues toward a combined ballot. Gurleen Grewal indicated that the work is getting close to completion. Georgy Sebastian reported on behalf of Amazon Trust Services that Michael Slaughter had updated the proposal and was seeking feedback on the proposed language. Georgy Sebastian shared the latest version during the meeting. Gurleen Grewal indicated that the newly shared version should be considered the canonical version and that links to the other PRs could be removed. Wayne Thayer indicated that the ballot tracking information would be updated accordingly. Revocation Timeline for CP/CPS Deviations: Dimitris Zacharopoulos was not present to provide an update. The item was tabled. Any Other Business: SC-101v2 and Reuse of Validation Data: Wayne Thayer raised a mailing list question concerning Section 4.2.1 and reuse of validation data following changes to validation requirements. The specific question was whether permitted reuse continues when a validation method is indirectly affected by a change to a definition on which the method relies. Dustin Hollenback initially expressed concern about allowing reuse following such a change but noted the practical difficulty of expecting CAs and Root Programs to track indirect changes to definitions outside the validation method itself. Dustin Hollenback noted that, particularly as validation reuse periods continue to decrease, allowing reuse in this situation may be a reasonable approach and would avoid creating compliance “gotchas” without a clear ecosystem benefit. Wayne Thayer agreed that this was consistent with his reading of the requirement and stated that the language appears intended to prevent existing validations from immediately becoming unusable following a requirements change. Dustin Hollenback distinguished an indirect change to an external definition from a direct change to the validation method itself and questioned whether the same treatment should apply to a direct change. Wayne Thayer noted that Section 4.2.1 explicitly permits reuse following a change to a validation method for the applicable reuse period unless the ballot making the change specifically provides otherwise. Rich Smith noted that he believed the relevant reuse language may predate SC-101. The discussion generally supported the interpretation that reuse remains permitted for the applicable reuse period unless the ballot introducing the change specifically prohibits it. Wayne Thayer indicated that the minutes from the discussion could be used to help respond to the mailing list question. Attendance by Members of Other Working Groups: Wayne Thayer raised a question from a member of another CA/Browser Forum Working Group who wanted to attend the Forum Plenary teleconference but was not a member of the Server Certificate Working Group. Because the Forum Plenary begins immediately after the SCWG teleconference, the individual asked whether they could join the SCWG call while waiting for the Forum portion to begin. Martijn Katerbarg noted that face-to-face meetings provide precedent for allowing attendees to be present during sessions of Working Groups to which they do not belong. He suggested that such individuals be permitted to listen but not participate in the SCWG discussion. Martijn Katerbarg also noted that the Forum portion of the call can begin earlier than scheduled, making it difficult for a participant to know precisely when to join if they cannot listen to the preceding SCWG meeting. Dean Coclin agreed that allowing the individual to listen without participating in the SCWG discussion was reasonable. Arman Asemani suggested reversing the order of the calls so that the Forum Plenary occurs first and non-SCWG members can leave before the SCWG meeting begins. Dean Coclin, Martijn Katerbarg, Dustin Hollenback, and Wayne Thayer discussed the previous ordering of the calls and recalled that the order had been changed in part because of differences in meeting duration. Andrea Holland noted that holding the Forum Plenary first would also allow participants who do not wish to attend the SCWG meeting to leave afterward. Dean Coclin indicated that he would be open to changing the order but wanted Dimitris Zacharopoulos’s input. Wayne Thayer summarized the discussion as supporting allowing the individual to join the SCWG portion as an observer but not participate in the discussion. The group will separately consider whether to change the ordering of the Forum Plenary and SCWG teleconferences. Adjourn: The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-27. Attendees: Arman Asemani (Apple), Nate Smith (GoDaddy), Zoey Wang, Logan Mabe (Microsoft), Rollin Yu (TrustAsia), Jun Okura (Cybertrust), Andrea Holland (IdenTrust), Martijn Katerbarg (Sectigo), Gurleen Grewal (GTS), Hogeun Yoo (NAVER Cloud Trust Services), Alvin Wang (SHECA), Sándor Szőke (Microsec), Ben Wilson (Mozilla), Clint Wilson, Tobias Josefowitz (Opera), Moritz Schaal (D-Trust), Polina Glazyrina (Sectigo), Adam Jones (Microsoft), Kateryna Aleksieieva (Certum by Asseco), Sean Huang (TWCA), Lucy Buecking (IdenTrust), Dustin Hollenback, Scott Rea (eMudhra), Kiran Tummala, Paul van Brouwershaven (Digitorus), Karina Goodley, Cynetheia Brown (FPKIMA), Janet Hines (SSL.com), Nome Huang (TrustAsia), Chris Clements (Google Chrome), Daryn Wright, Li-Chun Chen (Chunghwa Telecom), Stephen Davidson (DigiCert), Atsushi Inaba (GlobalSign), Tsung-Min Kuo (Chunghwa Telecom), Rich Smith (DigiCert), Ryan Dickson (Google Chrome), Dean Coclin (DigiCert), Fumiaki Ono (SECOM Trust Systems), Steven Deitte (GoDaddy), Georgy Sebastian (Amazon Trust Services), Jos Purvis (Fastly), Sandy Balzer (SwissSign), Luis Cervantes (SSL.com), Aaron Poulsen (SSL.com), Rob White (GoDaddy), Wayne Thayer (Fastly)
2026-07-30 Minutes of the Server Certificate Working Group
July 30, 2026 by Wayne ThayerMinutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia)
July 30, 2026 by Wayne ThayerMinutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia)
2026-07-16 Minutes of the Server Certificate Working Group
July 16, 2026 by Wayne ThayerMinutes: CA/Browser Forum Server Certificate Working Group Minutes July 16, 2026 Opening Matters Dimitris Zacharopoulos chaired the meeting. The meeting was called to order. The meeting was recorded, the list of attendees is below, and the Note Well was read.
July 16, 2026 by Wayne ThayerMinutes: CA/Browser Forum Server Certificate Working Group Minutes July 16, 2026 Opening Matters Dimitris Zacharopoulos chaired the meeting. The meeting was called to order. The meeting was recorded, the list of attendees is below, and the Note Well was read.
2026-07-02 Minutes of the Server Certificate Working Group
July 2, 2026 by Wayne ThayerMinutes: Meeting Title: Server Certificate Working Group Teleconference
July 2, 2026 by Wayne ThayerMinutes: Meeting Title: Server Certificate Working Group Teleconference
2026-06-18 Minutes of the Server Certificate Working Group
June 18, 2026 by Wayne ThayerMinutes: Roll Call – from recording We also had the following persons present: Naresh Charugundla (Microsoft), Rajeev Mohindra (Microsoft), Logan Mabe (Microsoft) who were not registered in the Member’s tool. Read note-well The note-well was read by Dimitris. Review of Agenda The Agenda as provided on list prior to the call (see above). Minutes June 4, 2026 (Draft minutes were distributed on 2026-06-16) – are Approved Membership Applications No current Applications to review. Ballot Status SC101v2 (https://github.com/cabforum/servercert/pull/627) Clarify Authorization Domain Names (Aaron Gable) Ballot moved to V2 with substantive change being effective date in 3.2.2.5.3. A couple of other editorial updates also. Expected to go to discussion period tomorrow.
June 18, 2026 by Wayne ThayerMinutes: Roll Call – from recording We also had the following persons present: Naresh Charugundla (Microsoft), Rajeev Mohindra (Microsoft), Logan Mabe (Microsoft) who were not registered in the Member’s tool. Read note-well The note-well was read by Dimitris. Review of Agenda The Agenda as provided on list prior to the call (see above). Minutes June 4, 2026 (Draft minutes were distributed on 2026-06-16) – are Approved Membership Applications No current Applications to review. Ballot Status SC101v2 (https://github.com/cabforum/servercert/pull/627) Clarify Authorization Domain Names (Aaron Gable) Ballot moved to V2 with substantive change being effective date in 3.2.2.5.3. A couple of other editorial updates also. Expected to go to discussion period tomorrow.
2026-06-04 Minutes of the Server Certificate Working Group
June 4, 2026 by Wayne ThayerMinutes: Dimitris leading the meeting and taking minutes Dimitris read the note-well. No changes were requested for the agenda. Minutes approval May 21, 2026 - these minutes were distributed on 2026-05-21. The minutes were approved. Next call: June 18, 2026 Attendees Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Adam Folson (IdenTrust), Adriano Santoni (Actalis S.p.A.), Alexandros Afentoulis (HARICA), Alvin Wang (SHECA), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Cynethia Brown (US Federal PKI Management Authority), Daryn Wright (Apple), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Dustin Hollenback (Apple), Eamon Zhang (TrustAsia), Eleftheria Theologou (HARICA), Enrico Entschew (D-TRUST), Eric Hampshire (Cisco Systems), Georgy Sebastian (Amazon), Grace Cimaszewski (Grace Cimaszewski (Private Person)), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hazhar Ismail (MSC Trustgate Sdn Bhd), Henry Birge-Lee (Henry Birge-Lee (Private person)), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), India Donald (US Federal PKI Management Authority), Jan Smith (US Federal PKI Management Authority), Jinhwan Shin (CPA Canada/WebTrust), Joe DeBlasio (Google), John Mason (Microsoft), Johnny Reading (GoDaddy), Joseph Cigin (Joseph Cigin (Private Person)), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Kateryna Aleksieieva (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lilia Dubko (CPA Canada/WebTrust), Lucy Buecking (IdenTrust), Mads Henriksveen (Buypass AS), Mahua Chaudhuri (Microsoft), Marijn Nagelkerke (360 Browser), Mark Gamache (Mark Gamache (Private Person)), Mark Nelson (IdenTrust), Martijn Katerbarg (Sectigo), Masaru Sakamoto (Cybertrust Japan), Masatoshi Shigaki (CPA Canada/WebTrust), Matthew McPherrin (Let’s Encrypt), Michelle Coon (OATI), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nick France (Sectigo), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Paul van Brouwershaven (Entrust), Paul van Brouwershaven (Digitorus), Pekka Lahtiharju (Telia Company), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rob Brady (SGNR, LLC), Rob Stradling (Sectigo), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Sven Rajala (Keyfactor), Tadahiko Ito (SECOM Trust Systems), Tathan Thacker (IdenTrust), Thomas Connelly (US Federal PKI Management Authority), Thomas Zermeno (SSL.com), Tim Callan (Sectigo), Tim Crawford (CPA Canada/WebTrust), Tobias Josefowitz (Opera Software AS), Trevoli Ponds-White (Amazon), Tsung-Min Kuo (Chunghwa Telecom), Vikas Khanna (Microsoft), Vinay Kumar (OATI), Wayne Thayer (Fastly), Wendy Brown (US Federal PKI Management Authority), Zhao Kuisen (NovaVanguard Technology Co., Ltd.).
June 4, 2026 by Wayne ThayerMinutes: Dimitris leading the meeting and taking minutes Dimitris read the note-well. No changes were requested for the agenda. Minutes approval May 21, 2026 - these minutes were distributed on 2026-05-21. The minutes were approved. Next call: June 18, 2026 Attendees Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Adam Folson (IdenTrust), Adriano Santoni (Actalis S.p.A.), Alexandros Afentoulis (HARICA), Alvin Wang (SHECA), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Cynethia Brown (US Federal PKI Management Authority), Daryn Wright (Apple), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Dustin Hollenback (Apple), Eamon Zhang (TrustAsia), Eleftheria Theologou (HARICA), Enrico Entschew (D-TRUST), Eric Hampshire (Cisco Systems), Georgy Sebastian (Amazon), Grace Cimaszewski (Grace Cimaszewski (Private Person)), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hazhar Ismail (MSC Trustgate Sdn Bhd), Henry Birge-Lee (Henry Birge-Lee (Private person)), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), India Donald (US Federal PKI Management Authority), Jan Smith (US Federal PKI Management Authority), Jinhwan Shin (CPA Canada/WebTrust), Joe DeBlasio (Google), John Mason (Microsoft), Johnny Reading (GoDaddy), Joseph Cigin (Joseph Cigin (Private Person)), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Kateryna Aleksieieva (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lilia Dubko (CPA Canada/WebTrust), Lucy Buecking (IdenTrust), Mads Henriksveen (Buypass AS), Mahua Chaudhuri (Microsoft), Marijn Nagelkerke (360 Browser), Mark Gamache (Mark Gamache (Private Person)), Mark Nelson (IdenTrust), Martijn Katerbarg (Sectigo), Masaru Sakamoto (Cybertrust Japan), Masatoshi Shigaki (CPA Canada/WebTrust), Matthew McPherrin (Let’s Encrypt), Michelle Coon (OATI), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nick France (Sectigo), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Paul van Brouwershaven (Entrust), Paul van Brouwershaven (Digitorus), Pekka Lahtiharju (Telia Company), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rob Brady (SGNR, LLC), Rob Stradling (Sectigo), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Sven Rajala (Keyfactor), Tadahiko Ito (SECOM Trust Systems), Tathan Thacker (IdenTrust), Thomas Connelly (US Federal PKI Management Authority), Thomas Zermeno (SSL.com), Tim Callan (Sectigo), Tim Crawford (CPA Canada/WebTrust), Tobias Josefowitz (Opera Software AS), Trevoli Ponds-White (Amazon), Tsung-Min Kuo (Chunghwa Telecom), Vikas Khanna (Microsoft), Vinay Kumar (OATI), Wayne Thayer (Fastly), Wendy Brown (US Federal PKI Management Authority), Zhao Kuisen (NovaVanguard Technology Co., Ltd.).
2026-05-21 Minutes of the Server Certificate Working Group
May 21, 2026 by Wayne ThayerMinutes: 1. Begin Recording - Roll Call Meeting called to order by Dimitris Zacharopoulos.
May 21, 2026 by Wayne ThayerMinutes: 1. Begin Recording - Roll Call Meeting called to order by Dimitris Zacharopoulos.
Ballot SC098v2: Process RFC 8657 CAA Parameters
May 13, 2026 by Wayne ThayerVoting Results Certificate Issuers 23 votes in total:
May 13, 2026 by Wayne ThayerVoting Results Certificate Issuers 23 votes in total: