CA/Browser Forum posts
CA/Browser Forum Releases Code Signing Baseline Requirements Public Comment Draft
August 25, 2014 by Ben WilsonIn 2013, the CA/Browser Forum voted to create a Code Signing Working Group whose sole purpose was to come up with a set of Baseline Requirements for the issuance of Code Signing Certificates. The result of that effort is the: Baseline Requirements for Code Signing Certificates, Public Comment Draft (doc) Baseline Requirements for Code Signing Certificates, Public Comment Draft (pdf) Once approved by the CA/B Forum and subsequent audit standards are created, all Certificate Authorities will be obligated to follow these Requirements when issuing and managing code signing certificates.
August 25, 2014 by Ben WilsonIn 2013, the CA/Browser Forum voted to create a Code Signing Working Group whose sole purpose was to come up with a set of Baseline Requirements for the issuance of Code Signing Certificates. The result of that effort is the: Baseline Requirements for Code Signing Certificates, Public Comment Draft (doc) Baseline Requirements for Code Signing Certificates, Public Comment Draft (pdf) Once approved by the CA/B Forum and subsequent audit standards are created, all Certificate Authorities will be obligated to follow these Requirements when issuing and managing code signing certificates.
2014-08-21 Minutes
August 21, 2014 by Ben WilsonNotes of Teleconference – CA/B Forum 21 Aug 2014 Antitrust Statement: Read by Ben.
August 21, 2014 by Ben WilsonNotes of Teleconference – CA/B Forum 21 Aug 2014 Antitrust Statement: Read by Ben.
2014-08-07 Minutes
August 7, 2014 by Ben WilsonMinutes of CA/B Forum Teleconference, 7 August 2014 Antitrust Statement: Read by Ben.
August 7, 2014 by Ben WilsonMinutes of CA/B Forum Teleconference, 7 August 2014 Antitrust Statement: Read by Ben.
Ballot 129 – PSL in BR 11.1.3 (passed)
August 4, 2014 by Ben WilsonVoting on Ballot 129 closed on 4 August 2014. Voting in Favor were: DigiCert, Disig, GlobalSign, GoDaddy, Symantec, Trend Micro, Trustwave, WoSign, and Mozilla. None were opposed and none abstained. Quorum was met and Ballot 129 passed resulting in Baseline_Requirements_V1_1_9. Gerv Markham of Mozilla made the following motion, and Ben Wilson from Digicert and Rick Andrews from Symantec have endorsed it. Reason for Ballot This ballot simply clarifies how to use the “Public Suffix List” (PSL) in Section 11.1.3 of the Baseline Requirements. The explanation in the footnote to section 11.1.3 of the Baseline Requirements about how to use the PSL is ambiguous because the PSL has two sections–the “ICANN DOMAINS” section and the “PRIVATE DOMAINS” section. Therefore, clarification is needed to explain that it is the ICANN DOMAINS section of the PSL that CAs should use.
August 4, 2014 by Ben WilsonVoting on Ballot 129 closed on 4 August 2014. Voting in Favor were: DigiCert, Disig, GlobalSign, GoDaddy, Symantec, Trend Micro, Trustwave, WoSign, and Mozilla. None were opposed and none abstained. Quorum was met and Ballot 129 passed resulting in Baseline_Requirements_V1_1_9. Gerv Markham of Mozilla made the following motion, and Ben Wilson from Digicert and Rick Andrews from Symantec have endorsed it. Reason for Ballot This ballot simply clarifies how to use the “Public Suffix List” (PSL) in Section 11.1.3 of the Baseline Requirements. The explanation in the footnote to section 11.1.3 of the Baseline Requirements about how to use the PSL is ambiguous because the PSL has two sections–the “ICANN DOMAINS” section and the “PRIVATE DOMAINS” section. Therefore, clarification is needed to explain that it is the ICANN DOMAINS section of the PSL that CAs should use.
Ballot 126 – Operational Existence (passed)
July 24, 2014 by Ben WilsonVoting on Ballot 126 closed on 24 July 2014. Voting in favor were Comodo, DigiCert, Network Solutions, QuoVadis, Symantec, Trend Micro, WoSign, and Mozilla. Visa abstained. Quorum was met and Ballot 126 passed, resulting in EV SSL Certificate Guidelines Version 1.5.0. Ballot 126 – Operational Existence Jeremy Rowley of Digicert made the following motion and Cecilia Kam of Symantec and Doug Beattie of GlobalSign have endorsed it:
July 24, 2014 by Ben WilsonVoting on Ballot 126 closed on 24 July 2014. Voting in favor were Comodo, DigiCert, Network Solutions, QuoVadis, Symantec, Trend Micro, WoSign, and Mozilla. Visa abstained. Quorum was met and Ballot 126 passed, resulting in EV SSL Certificate Guidelines Version 1.5.0. Ballot 126 – Operational Existence Jeremy Rowley of Digicert made the following motion and Cecilia Kam of Symantec and Doug Beattie of GlobalSign have endorsed it:
Baseline Requirements 1.1.7 and 1.1.8 Re-Posted
July 22, 2014 by Ben WilsonA couple of formatting errors were identified in the Baseline Requirements, and versions 1.1.7 and 1.1.8 have been replaced with corrected versions. Appendix A in versions prior to version 1.1.7 had parts of RSA public key exponent requirements as superscript. It should have read: “The CA SHALL confirm that the value of the public exponent is an odd number equal to 3 or more. Additionally, the public exponent SHOULD be in the range between 216+1 and 2256-1.” That is corrected in version 1.1.7. Also, versions 1.1.7 and 1.1.8 had combined the text at the end of section 11.1.4 as part of the title of section 11.2. That has been corrected in those two versions.
July 22, 2014 by Ben WilsonA couple of formatting errors were identified in the Baseline Requirements, and versions 1.1.7 and 1.1.8 have been replaced with corrected versions. Appendix A in versions prior to version 1.1.7 had parts of RSA public key exponent requirements as superscript. It should have read: “The CA SHALL confirm that the value of the public exponent is an odd number equal to 3 or more. Additionally, the public exponent SHOULD be in the range between 216+1 and 2256-1.” That is corrected in version 1.1.7. Also, versions 1.1.7 and 1.1.8 had combined the text at the end of section 11.1.4 as part of the title of section 11.2. That has been corrected in those two versions.
Ballot 127 – Verification of Agency in EV Guidelines 11.7.2 (passes)
July 17, 2014 by Ben WilsonVoting on Ballot 127 We received Yes votes from Actalis, Buypass, DigiCert, GlobalSign, Logius PKIoverheid, OpenTrust, QuoVadis, SECOM, Symantec, Trend Micro, Trustwave, TurkTrust, WoSign, and Mozilla.
July 17, 2014 by Ben WilsonVoting on Ballot 127 We received Yes votes from Actalis, Buypass, DigiCert, GlobalSign, Logius PKIoverheid, OpenTrust, QuoVadis, SECOM, Symantec, Trend Micro, Trustwave, TurkTrust, WoSign, and Mozilla.
2014-07-10 Minutes
July 10, 2014 by Ben WilsonMinutes of Teleconference held Thursday, 10 July 2014 Antitrust Statement: Read by Ben.
July 10, 2014 by Ben WilsonMinutes of Teleconference held Thursday, 10 July 2014 Antitrust Statement: Read by Ben.