CA/Browser Forum
Home » All CA/Browser Forum Posts

CA/Browser Forum posts

Filter posts by Author, Tag or Series

2026-09-10 Minutes of the Forum
September 10, 2026 by 2026-09-10 Minutes of the ForumMinutes: CA/B Forum Plenary Meeting - September 10, 2026 1. Opening Tim Callan (Sectigo) opened the plenary and the Note Well was read. Dustin Hollenback (Apple) took the minutes. Minutes Approval: Tim Callan (Sectigo) asked whether anyone opposed approval of the minutes of 2026-08-27. Hearing no opposition, those minutes were approved. 2. Working Group Updates Server Certificate Working Group: Dimitris Zacharopoulos (HARICA) reported that the working group had spent most of its previous meeting on reasons for revocation, a discussion led by Ben Wilson (Mozilla), who described a process for establishing why certificates are revoked and what problems revocation is intended to solve. Rather than create a subcommittee or ad hoc group, the working group decided to use the Server Certificate Working Group mailing list with specific subject tags to drive that discussion. The remainder of the time was spent on face-to-face agenda topics. Validation Subcommittee: Stephen Davidson (DigiCert) reported that the subcommittee’s last teleconference went through a series of proposals from Rich Smith (DigiCert) on modernizing aspects of the EV Guidelines, now circulated as a fully formed set of redlines. He noted the redlines went to the Server Certificate Working Group list rather than the Validation Subcommittee list; Rich Smith (DigiCert) confirmed he had intended to send them to validation but that they went to servercert, and he left them there. Stephen Davidson (DigiCert) also reported that discussion has begun, and will continue at the face-to-face and beyond, on the use of AI-based tools in conducting validation. The white paper and presentation materials are on the Validation Subcommittee mailing list. He invited insight from anyone with a view on how AI can be used in support of validation tasks under the CA/Browser Forum standards, on what guardrails should be imposed, and on record-keeping changes that might be advisable when AI is used. Code Signing Certificate Working Group: Martijn Katerbarg (Sectigo) reported the working group started meeting again last week and has mainly planned for the face-to-face. Microsoft gave a short update on threat intelligence sharing, for which they are starting a pilot with a small number of Certification Authorities, with the expectation it will expand over time. Face-to-face topics will include clarifying ambiguous language on the organization name in Code Signing Certificates when combined with an individual Code Signing Certificate, concerns raised about the reuse of private keys and key pairs, and a proposal to align the Code Signing guidelines with the TLS documents on Section 7. S/MIME Certificate Working Group: Stephen Davidson (DigiCert) reported that SMC-018, a ballot realigning the multi-purpose use cases, passed and is in IPR review until 2026-09-24, and encouraged anyone wishing to conduct a review to do so. He noted that if the revocation reasons change in the Server Certificate Working Group there is a potential knock-on effect in other working groups, including S/MIME, which mirrored those requirements, and that the S/MIME working group would want to feed into that discussion. He also reported a narrowing under one root program of the guardrails around use of the email protection EKU: where a publicly trusted hierarchy is used for email protection, the leaf certificates must contain an email address and therefore fall automatically within the scope of the S/MIME Baseline Requirements. A discussion has begun on whether the entire scope of the S/MIME Baseline Requirements should be read that way, and on defining which types of Subordinate CA Certificates are automatically pulled into scope. There is an issue open in the S/MIME GitHub. A cleanup ballot is coming shortly with minor changes keeping pace with the TLS working group, which he characterized as non-controversial. Network Security Working Group: Clint Wilson (Apple) was not present. David Kluge (Google Trust Services) gave the update, reporting little change since the last one. The working group is preparing for the face-to-face, where the topics will be the future of the Network and Certificate System Security Requirements and the direction for further improvements, CP/CPS disclosure of the network and certificate system security requirements and how they are implemented, and the adoption of AI for security and audit-related purposes. Definitions and Glossary Working Group: Tim Callan (Sectigo) gave the update on behalf of Polina Glazyrina (Sectigo). A ballot went into a discussion period and received good feedback that the group considered worth taking and addressing. Rather than proceed to a vote on that version, the group will withdraw it and put a revised ballot into a new discussion period. The exact timing is not settled. The working group has been placed on the plenary agenda for the face-to-face so the community can hold an open discussion on its vision for the glossary. Forum Infrastructure Subcommittee: Jos Purvis (Fastly) reported the subcommittee did not meet last week, so there was no update. IPR administration: Ben Wilson (Mozilla) will confirm whether the reminder was sent to members who have not signed version 1.4 of the IPR Agreement, warning that their membership would otherwise be terminated. The outstanding tasks are to update the member tools list of those members and to ensure they are removed from the website. 3. Elections Nominations for the chairs have concluded. Three positions are contested: Forum Chair, Server Certificate Working Group Chair, and Network Security Working Group Chair. Three are uncontested and need only be confirmed: S/MIME Certificate Working Group Chair, Code Signing Certificate Working Group Chair, and Definitions and Glossary Working Group Chair. Tim Callan (Sectigo) reviewed the election timeline. Per the special elections ballot circulated 2026-09-07, the discussion period closes 2026-09-14 at 16:00 UTC, and voting runs from then until 2026-09-21 at 16:00 UTC. Candidates have the option, but not the obligation, to send a message to the list setting out their vision and qualifications; none had done so at the time of the call. 4. Face-to-Face 68, Vienna, Austria, hosted by eMudhra, 2026-09-22 to 2026-09-24 About half a dozen registration spots remain. Final numbers have been given to the venues, but Scott Rea (eMudhra) confirmed sign-ups can stay open for the remaining spots, since not every attendee joins every session. Members who signed up for the social event but can no longer attend, or whose plus one can no longer attend, should notify Scott Rea (eMudhra). Late additions can also be accommodated. Transport has been arranged between the Parliament venue and the Beethoven House, so personal transport is not required. A tour of the Parliament is scheduled for 17:00 on the first day for those who wish to participate. 5. Upcoming Meetings Face-to-Face 69, Scottsdale, Arizona, hosted by Sectigo: 2027-02-23 to 2027-02-25. Dates confirmed. Sign-ups are open on the wiki. Face-to-Face 70, Zurich, Switzerland, hosted by SwissSign: 2027-09-21 to 2027-09-23. Dates newly confirmed. Tim Callan (Sectigo) thanked SwissSign and asked members to mark their calendars. 6. Any Other Business None.
2026-09-10 Minutes of the Server Certificate Working Group
September 10, 2026 by Wayne ThayerServer Certificate Working Group Meeting — 2026-09-10 MinutesMinutes 1. Opening Dimitris Zacharopoulos (HARICA) opened the Server Certificate Working Group teleconference of 2026-09-10. Dimitris Zacharopoulos (HARICA) confirmed the meeting was being recorded and took roll call from Webex. Dustin Hollenback (Apple) took the minutes. The Note Well was read: all participants are reminded that they must comply with the CA/Browser Forum’s Bylaws, which include an Antitrust Policy, a Code of Conduct, and an Intellectual Property Rights Agreement. Participants were directed to contact the Forum Chair with any comments or concerns. The agenda had been sent the previous day. No changes were proposed. 2. Minutes Approval No minutes were available to approve. Daryn Wright (Apple) will circulate the minutes of the previous teleconference as soon as he can. 3. Membership Applications Huawei submitted an application to join the Server Certificate Working Group as a Certificate Consumer. Dimitris Zacharopoulos (HARICA) reported that Dean Coclin (DigiCert) had confirmed the authority of the seal attached to the IPR acceptance letter. Dimitris Zacharopoulos (HARICA) stated he had given the remainder of the application only a quick review and had hoped another member of the working group would review it in detail. Dimitris Zacharopoulos (HARICA) asked whether there were any objections to approving Huawei as a Certificate Consumer, and initially heard none. Tobias Josefowitz (Opera) then asked whether anyone had examined the “provided to the public” element of the membership requirements, noting that some device makers maintain operating systems they do not deploy. Dimitris Zacharopoulos (HARICA) shared his screen and read the charter’s Certificate Consumer definition, which requires that the applicant “provides software intended to be used by the general public for browsing the web securely.” Chad Dandar (Cisco) suggested that, to satisfy Tobias Josefowitz’s question, the group simply read what the applicant had written in that section of the application. Dimitris Zacharopoulos (HARICA) reviewed that section and reported the applicant offers what it calls the Huawei Browser and HarmonyOS, and includes a link to its root certificate program documentation. He noted he had not tested the browser and did not know who could. Tobias Josefowitz (Opera) said that satisfied him. Ryan Dickson (Google Chrome) asked whether the group should first verify that the Certificate Consumer requirements had been met, saying it felt premature to call for objections before confirming the minimum requirements. Tobias Josefowitz (Opera) clarified that he did not necessarily have an objection. His concern was that device makers sometimes maintain operating systems they do not deploy, and he was not certain whether anyone is currently using this one. If people are, he was satisfied on the public requirement. Dimitris Zacharopoulos (HARICA) said it would help him, and help the minutes, to record specifically what the working group considers missing so the applicant can supply it. Tobias Josefowitz (Opera) proposed asking the applicant in which way it makes the browser available and which user group would be using it. Rich Smith (DigiCert) suggested asking how many devices the browser is currently deployed to. Tim Callan (Sectigo) observed that the charter language says “intended to be used,” which would also cover software in advance of deployment, so the number of current users may not be the relevant test. Tobias Josefowitz (Opera) and Rich Smith (DigiCert) both accepted the point. Rich Smith (DigiCert) added that some form of due diligence was still warranted. Tim Callan (Sectigo) responded that if the language is to remain, the group should find a way to verify it, and that revising the language could be an action item, noting he could see a member working toward a deployment it fully intends to make and seeing no reason to discourage that. Wayne Thayer (Fastly) reported that the applicant’s message of 2026-08-27 never reached his inbox and that he had therefore not reviewed the application. He suggested that many members were likely in the same position and proposed either asking the applicant questions or taking another two weeks, reviewing it at the face-to-face. Dimitris Zacharopoulos (HARICA) confirmed the application is in the mailing list archive. Martijn Katerbarg (Sectigo) noted the application states the browser can be downloaded through the Huawei AppGallery, which appears to be the default application store on Huawei devices, comparable to the Samsung app store on Samsung smartphones. Tobias Josefowitz (Opera) performed a web search during the call and reported that the Huawei Browser does appear to be used on Huawei devices, which he considered sufficient to qualify. Chris Clements (Google Chrome) stated that the group does not appear to have a clear standard operating procedure for a new Certificate Consumer. He proposed that the working group offer guidance and assign somebody, or some people, responsibility for verifying the seven charter criteria and presenting that to the group before calling for objections. Dimitris Zacharopoulos (HARICA) agreed to address this at the next meeting. Recorded in the meeting chat, Ryan Dickson (Google Chrome) wrote: “To be clear, my concern was less about this specific request and moreso related to the procedural due diligence that takes place between receiving one of these applications and collecting community objections. Like others said, it would be helpful that if before we ask for objections, someone has reviewed the applicant against the charter criteria and presented that to the group for review before we ask for objections.” Aaron Gable (ISRG) gave a detailed assessment. He noted that Huawei is a major smartphone and operating system vendor and that its browser and TLS validation work, adding that he saw no meaningful quality difference between the Huawei operating system and browser and those of other major Android-based smartphone vendors. He considered criteria one through five clearly met: the applicant provides a software product for browsing the web, provides regular updates, provides documentation requiring certificate issuers to comply with the Baseline Requirements, validates chains of trust, and publishes documentation of the Certification Authorities in its trust store. He identified concerns with criteria six and seven. On criterion six, the applicant’s root program requirements direct issuers to submit an application to an email address but give no indication of what the application is or where to obtain a form. On criterion seven, the requirements direct issuers to report misissuance immediately but provide no contact address or method. He also noted that ISRG’s Root CA Certificates are included in the Huawei trust store without any communication to ISRG about when or why, and that ISRG has never disclosed an incident directly to Huawei. Outcome: the application was not approved. The working group will seek clarification from the applicant on criteria six and seven, a member will verify that the browser functions, and the application will be discussed at the face-to-face meeting. 4. Face-to-Face 68 Agenda Ryan Dickson (Google Chrome) had circulated a list of four proposed topics: (1) Section 7 cleanup and modernizing certificate profile expectations, including revisiting the legacy framing around technically constrained Subordinate CAs; (2) profile-specific linting expectations, moving beyond generic Baseline Requirements minimums toward validating against a CA Owner’s explicitly stated commitments and profiles; (3) aligning the Baseline Requirements with dedicated hierarchy expectations, defining TLS-specific Subordinate CA profiles and a future timeline requiring certificates chaining to them to lead to Root CA Certificates serving TLS use cases exclusively; and (4) domain transparency and issuance information, revisiting the SC-093 discussion of domain control validation methods in certificates. Dimitris Zacharopoulos (HARICA) had separately proposed a topic on CP versus CPS versus CP/CPS and on expectations for RFC 2119 language. Dimitris Zacharopoulos (HARICA) said he will open the working group session at the face-to-face with a summary of activity since the previous face-to-face, covering the changes and the pull requests released since. Ben Wilson (Mozilla) is working on the revocation circumstances topic and has started preparing a small task force for that area. Topic 1, Section 7 cleanup and modernizing certificate profile expectations, was added to the agenda, the group having previously been in favor. Aaron Gable (ISRG) stated he was most interested in topic 1 and second most interested in topic 3, which aligns with his SC-103 ballot. He considered topics 2, 3, and 4 low priority and did not want to displace other business by including them. Ryan Dickson (Google Chrome) considered topic 4 premature and said it should not be discussed. He reported he has started slides and a GitHub pull request covering topics 1, 2, and 3, which he considers interrelated because they all touch Section 7. He described four or five concrete proposed changes: consolidating the current tabular inheritance, where reading one certificate profile requires consulting roughly ten tables, into a single table per profile carrying all fields and extensions with no cross-references unless absolutely necessary, which he described as preventing the wild goose chase implementers face today; identifying profiles that could be removed or sunset, making no commentary on timing; and establishing a clear expectation that Certification Authorities define in their policies exactly what they do, which creates a path to CA-specific linting and should dramatically reduce the likelihood of mass misissuance events. Dimitris Zacharopoulos (HARICA) suggested discussing the topics in the sequence 1, then 3, then 2, so that linting expectations come after the hierarchies and content expectations are settled. Ryan Dickson (Google Chrome) said the group could take them in any order but asked that they be considered collectively, since each influences the others, and that it would be useful to state what the finished product is hoped to look like even if that is years away. Dimitris Zacharopoulos (HARICA) proposed inviting two external parties who have worked on machine-readable profile formats and linting to participate in that portion of the meeting as interested parties. Ryan Dickson (Google Chrome) asked first whether existing working group members had already thought about or implemented such solutions and would share their experience as both an issuer and an implementer. Dimitris Zacharopoulos (HARICA) said HARICA is designing such a solution as part of an action plan for a recent incident but has nothing concrete to present or discuss beyond design issues. Aaron Gable (ISRG) said ISRG has spent time on this, and that one of its recent incident reports involved writing custom linters to enforce each of its CP/CPS profiles. He was reticent to commit to presenting because the Server Certificate Working Group session at the face-to-face is at 04:30 his local time and he did not know how much of it he would attend. Rich Smith (DigiCert) said he is working on something in the same subject area but could not guarantee it would be ready to demonstrate at the face-to-face. Dimitris Zacharopoulos (HARICA) asked him to send a message if it is, so that time could be allocated for a presentation. Dimitris Zacharopoulos (HARICA) will update the wiki to reflect the decisions taken, and asked that any further proposed topics be sent to the list or to him directly. He noted the topics already agreed will cover the working group’s two-hour allocation at the face-to-face. 5. Ballot Status In Discussion Period:
Ballot SC104: Set presence of AIA extension to SHOULD for Subscriber Certificates
September 3, 2026 by Voting Results Certificate Issuers 21 votes in total:
2026-08-27 Minutes of the Server Certificate Working Group
August 27, 2026 by Wayne ThayerFinal minutes for the CA/Browser Forum Server Certificate Working group - August 27, 2026Meeting Date: 2026-08-27 Note Well: Dimitris Zacharopoulos chaired the meeting.
2026-08-13 Minutes of the Forum
August 13, 2026 by Minutes: CA/B Forum plenary Meeting - August 13, 2026 1. Roll Call – from recording 2. Read note-well Dean Coclin chaired the meeting. The note-well had been read during the immediately preceding Server Certificate Working Group meeting.
2026-08-13 Minutes of the Server Certificate Working Group
August 13, 2026 by Wayne ThayerFinal minutes for the Server Certificate Working Group teleconference - August 13, 2026Meeting Date: 2026-08-13 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The meeting was recorded and the Note Well was read. Review of Agenda: No changes were made to the published agenda. Approval of Minutes: July 30, 2026 Teleconference approved without objection. Membership Applications: Wayne Thayer introduced an Interested Party application from GÉANT. Dean Coclin raised a question regarding whether the individual, Nicole Harris, who signed the application as Head of Security had sufficient authority to bind the organization to the IPR Agreement. Stephen Davidson noted that GÉANT is part of the European research and education network community and provides services to universities. Scott Rea noted that Nicole Harris typically represents GÉANT in working groups. Dean Coclin noted that Forum agreements have historically been signed by someone with authority to bind the organization, typically an executive or someone from legal. Dustin Hollenback asked how the Forum determines whether a signatory has the necessary authority. Dean Coclin suggested requesting confirmation that the signatory has authority to bind GÉANT. He noted that previous inquiries of this type have generally resulted either in confirmation of the signatory’s authority or a new signature from an appropriately authorized individual. Dean Coclin will follow up with GÉANT regarding the signatory’s authority, and the application will be revisited after a response is received. Ballot Status: SC-102: Wayne Thayer reported that SC-102 had completed its IPR Review Period. A new version of the TLS Baseline Requirements incorporating SC-102 was published earlier in the day. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: SC-103 remains in the Discussion Period. No additional discussion occurred. SC-100 - DNSSEC Clarification and Consolidation: SC-100 recently entered the IPR Review Period. Draft Ballots: Improved Certificate Problem Reports and Clarify the Meaning of Revocation: Martijn Katerbarg reported that he intends to address what he hopes is the final outstanding comment and then move the ballot forward. Allow ML-DSA: Stephen Davidson and Gurleen Grewal reported that work continues toward a combined ballot. Gurleen Grewal indicated that the work is getting close to completion. Georgy Sebastian reported on behalf of Amazon Trust Services that Michael Slaughter had updated the proposal and was seeking feedback on the proposed language. Georgy Sebastian shared the latest version during the meeting. Gurleen Grewal indicated that the newly shared version should be considered the canonical version and that links to the other PRs could be removed. Wayne Thayer indicated that the ballot tracking information would be updated accordingly. Revocation Timeline for CP/CPS Deviations: Dimitris Zacharopoulos was not present to provide an update. The item was tabled. Any Other Business: SC-101v2 and Reuse of Validation Data: Wayne Thayer raised a mailing list question concerning Section 4.2.1 and reuse of validation data following changes to validation requirements. The specific question was whether permitted reuse continues when a validation method is indirectly affected by a change to a definition on which the method relies. Dustin Hollenback initially expressed concern about allowing reuse following such a change but noted the practical difficulty of expecting CAs and Root Programs to track indirect changes to definitions outside the validation method itself. Dustin Hollenback noted that, particularly as validation reuse periods continue to decrease, allowing reuse in this situation may be a reasonable approach and would avoid creating compliance “gotchas” without a clear ecosystem benefit. Wayne Thayer agreed that this was consistent with his reading of the requirement and stated that the language appears intended to prevent existing validations from immediately becoming unusable following a requirements change. Dustin Hollenback distinguished an indirect change to an external definition from a direct change to the validation method itself and questioned whether the same treatment should apply to a direct change. Wayne Thayer noted that Section 4.2.1 explicitly permits reuse following a change to a validation method for the applicable reuse period unless the ballot making the change specifically provides otherwise. Rich Smith noted that he believed the relevant reuse language may predate SC-101. The discussion generally supported the interpretation that reuse remains permitted for the applicable reuse period unless the ballot introducing the change specifically prohibits it. Wayne Thayer indicated that the minutes from the discussion could be used to help respond to the mailing list question. Attendance by Members of Other Working Groups: Wayne Thayer raised a question from a member of another CA/Browser Forum Working Group who wanted to attend the Forum Plenary teleconference but was not a member of the Server Certificate Working Group. Because the Forum Plenary begins immediately after the SCWG teleconference, the individual asked whether they could join the SCWG call while waiting for the Forum portion to begin. Martijn Katerbarg noted that face-to-face meetings provide precedent for allowing attendees to be present during sessions of Working Groups to which they do not belong. He suggested that such individuals be permitted to listen but not participate in the SCWG discussion. Martijn Katerbarg also noted that the Forum portion of the call can begin earlier than scheduled, making it difficult for a participant to know precisely when to join if they cannot listen to the preceding SCWG meeting. Dean Coclin agreed that allowing the individual to listen without participating in the SCWG discussion was reasonable. Arman Asemani suggested reversing the order of the calls so that the Forum Plenary occurs first and non-SCWG members can leave before the SCWG meeting begins. Dean Coclin, Martijn Katerbarg, Dustin Hollenback, and Wayne Thayer discussed the previous ordering of the calls and recalled that the order had been changed in part because of differences in meeting duration. Andrea Holland noted that holding the Forum Plenary first would also allow participants who do not wish to attend the SCWG meeting to leave afterward. Dean Coclin indicated that he would be open to changing the order but wanted Dimitris Zacharopoulos’s input. Wayne Thayer summarized the discussion as supporting allowing the individual to join the SCWG portion as an observer but not participate in the discussion. The group will separately consider whether to change the ordering of the Forum Plenary and SCWG teleconferences. Adjourn: The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-27. Attendees: Arman Asemani (Apple), Nate Smith (GoDaddy), Zoey Wang, Logan Mabe (Microsoft), Rollin Yu (TrustAsia), Jun Okura (Cybertrust), Andrea Holland (IdenTrust), Martijn Katerbarg (Sectigo), Gurleen Grewal (GTS), Hogeun Yoo (NAVER Cloud Trust Services), Alvin Wang (SHECA), Sándor Szőke (Microsec), Ben Wilson (Mozilla), Clint Wilson, Tobias Josefowitz (Opera), Moritz Schaal (D-Trust), Polina Glazyrina (Sectigo), Adam Jones (Microsoft), Kateryna Aleksieieva (Certum by Asseco), Sean Huang (TWCA), Lucy Buecking (IdenTrust), Dustin Hollenback, Scott Rea (eMudhra), Kiran Tummala, Paul van Brouwershaven (Digitorus), Karina Goodley, Cynetheia Brown (FPKIMA), Janet Hines (SSL.com), Nome Huang (TrustAsia), Chris Clements (Google Chrome), Daryn Wright, Li-Chun Chen (Chunghwa Telecom), Stephen Davidson (DigiCert), Atsushi Inaba (GlobalSign), Tsung-Min Kuo (Chunghwa Telecom), Rich Smith (DigiCert), Ryan Dickson (Google Chrome), Dean Coclin (DigiCert), Fumiaki Ono (SECOM Trust Systems), Steven Deitte (GoDaddy), Georgy Sebastian (Amazon Trust Services), Jos Purvis (Fastly), Sandy Balzer (SwissSign), Luis Cervantes (SSL.com), Aaron Poulsen (SSL.com), Rob White (GoDaddy), Wayne Thayer (Fastly)
Ballot SMC018: Realignment of Multipurpose use cases
August 11, 2026 by Stephen Davidson[Adopted] Ballot SMC018: Realignment of Multipurpose use casesThe Intellectual Property Review (IPR) period for Ballot SMC017v2 (Increase Minimum RSA CA Key Size) has completed. No IPR Exclusion Notices were filed, and the ballot is adopted as of September 28, 2026. The new S/MIME BR v.1.0.16 have been published to the CABF public website in accordance with the Bylaws: https://cabforum.org/uploads/CA-Browser-Forum-SMIMEBR-1.0.16.pdf [IPR Review] Ballot SMC018: Realignment of Multipurpose use casesThis Review Notice is sent pursuant to Section 4.1 of the CA/Browser Forum’s Intellectual Property Rights Policy (v1.4). This Review Period of 30 days is for one Final Maintenance Guidelines. The complete Draft Maintenance Guideline that is the subject of this Review Notice is here.
Ballot SC100: DNSSEC Clarification and Consolidation
August 6, 2026 by Voting Results Certificate Issuers 22 votes in total:
2026-07-30 Minutes of the Server Certificate Working Group
July 30, 2026 by Wayne ThayerMinutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia)
2026-07-16 Minutes of the Server Certificate Working Group
July 16, 2026 by Wayne ThayerMinutes: CA/Browser Forum Server Certificate Working Group Minutes July 16, 2026 Opening Matters Dimitris Zacharopoulos chaired the meeting. The meeting was called to order. The meeting was recorded, the list of attendees is below, and the Note Well was read.
Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).