CA/Browser Forum

Server Certificate Ballots

Open Ballots (GitHub Pull Requests)

  • Ballot SC74: Clarify that CAs must follow the outline of Section 6 of RFC 3647 for CP/CPS documents
    Apr 21, 2024

    Clarify that CAs must follow the outline of Section 6 of RFC 3647 for their CP and/or CPS documents.

  • Ballot SC-073: Compromised and Weak Keys
    Apr 17, 2024

  • Ballot SC-070: Clarify the use of DTPs for domain control validation …
    Feb 23, 2024

    …(#475)

    • Clarify the use of third-party DNS recursive resolvers

    Add a sentence to BRs Section 3.2.2.4 clarifying that the use of DNS recursive resolvers which are operated outside the CAs audit scope qualifies as use of a Delegated Third Party, which is forbidden for domain control validation.

    • Include clarifications for Domain Contact and IP Address Contact

    These are clarifications that the CA must obtain information to be used in the Domain Validation process directly from Domain Name Registrars or IP Address Registration Authorities. CAs must not use third-party services outside their audit scope.

    • Add the same DNS clarification to 3.2.2.5

    • Simplify references to Domain Contact

    • Consolidate new text into 3.2.2, and cover 3.2.2.8 CAA

    • Add effective date for CAA

    • Improve effective date table

    • Improve 1.3.2 effective date


  • Ballot SC-XX: Measure all hours and days to the second
    Dec 21, 2023

    In light of https://bugzilla.mozilla.org/show_bug.cgi?id=1865080, this ballot ensures that all readers of the BRs understand that time periods measured in days (such as validation document reuse periods, random value usage periods, and revocation timelines) are measured precisely, not in calendar days.

    Notes:

    • This ballot bears some similarity to Ballot SC-52, which never came to a vote.
    • This ballot does not strictly define a “month”, allowing infrequent tasks to continue to be executed on the same numeric day of each month, regardless of the number of days in that month.

Closed Ballots (GitHub Pull Requests)

Passed Ballots

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).