<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:8.0pt;
        margin-left:.5in;
        mso-add-space:auto;
        line-height:105%;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst
        {mso-style-priority:34;
        mso-style-type:export-only;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        mso-add-space:auto;
        line-height:105%;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle
        {mso-style-priority:34;
        mso-style-type:export-only;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        mso-add-space:auto;
        line-height:105%;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast
        {mso-style-priority:34;
        mso-style-type:export-only;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:8.0pt;
        margin-left:.5in;
        mso-add-space:auto;
        line-height:105%;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:"Calibri",sans-serif;
        mso-ligatures:none;}
span.EmailStyle22
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:376316341;
        mso-list-template-ids:-1022694216;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1
        {mso-list-id:684018532;
        mso-list-type:hybrid;
        mso-list-template-ids:9349004 690277728 -182568390 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l1:level1
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:.25in;
        text-indent:-.25in;
        mso-ansi-font-weight:bold;
        mso-bidi-font-weight:bold;}
@list l1:level2
        {mso-level-start-at:5;
        mso-level-number-format:bullet;
        mso-level-text:-;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:.75in;
        text-indent:-.25in;
        font-family:"Calibri",sans-serif;
        mso-fareast-font-family:Calibri;}
@list l1:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        margin-left:1.25in;
        text-indent:-9.0pt;}
@list l1:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:1.75in;
        text-indent:-.25in;}
@list l1:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:2.25in;
        text-indent:-.25in;}
@list l1:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        margin-left:2.75in;
        text-indent:-9.0pt;}
@list l1:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:3.25in;
        text-indent:-.25in;}
@list l1:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:3.75in;
        text-indent:-.25in;}
@list l1:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        margin-left:4.25in;
        text-indent:-9.0pt;}
@list l2
        {mso-list-id:984820713;
        mso-list-template-ids:1708297182;}
@list l2:level1
        {mso-level-start-at:7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l3
        {mso-list-id:1155609866;
        mso-list-template-ids:252102498;}
@list l3:level1
        {mso-level-start-at:6;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l3:level2
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link="#0563C1" vlink="#954F72" style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal><span style='font-size:12.0pt'>Final <span style='color:black'>Minutes of the Code Signing Certificate Working Group</span> <b>February 9, 2023</b><o:p></o:p></span></p><p class=MsoNormal><b><span style='font-size:12.0pt'><o:p> </o:p></span></b></p><p class=MsoNormal><b><span style='font-size:12.0pt'>Attendance (in alphabetical order):<o:p></o:p></span></b></p><p class=MsoNormal><span style='font-size:12.0pt'>Andrea Holland (VikingCloud), Atsushi Inaba (GlobalSign), Ben Dewberry (Keyfactor), Brianca Martin (Amazon Trust Services), Bruce Morton (Entrust), Corey Bonnell (DigiCert), Dean Coclin (DigiCert), Ian McMillan (Microsoft), Inigo Barreira (Sectigo), Martijn Katerbarg (Sectigo), Mohit Kumar (GlobalSign), Roberto Quinones (Intel), Rollin Yu (TrustAsia), Tim Crawford (WebTrust), Tim Hollebeek (DigiCert)<o:p></o:p></span></p><p class=MsoNormal><b><u><span style='font-size:12.0pt'><o:p><span style='text-decoration:none'> </span></o:p></span></u></b></p><p class=MsoNormal><b><u><span style='font-size:12.0pt'>Minutes<o:p></o:p></span></u></b></p><ol style='margin-top:0in' start=1 type=1><li class=MsoListParagraphCxSpFirst style='margin-left:-.25in;mso-add-space:auto;mso-list:l1 level1 lfo3'><b><span style='font-size:12.0pt;line-height:105%'>Antitrust statement read<o:p></o:p></span></b></li><li class=MsoListParagraphCxSpLast style='margin-left:-.25in;mso-add-space:auto;mso-list:l1 level1 lfo3'><b><span style='font-size:12.0pt;line-height:105%'>Approval of minutes</span></b><span style='font-size:12.0pt;line-height:105%'>: Jan 26<sup>th</sup> minutes have not been sent out<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level1 lfo3'><span style='font-size:12.0pt'>Ballot: Malware base revocation (Martijn)<o:p></o:p></span></li><ul style='margin-top:0in' type=disc><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Received some pushback on the mailing list.<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Discussion from Martijn K., Bruce M., Ian M., and Tim H. around revamping the entire revocation section. <o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Agreed to pull revocation sections from the TLS and SMIME BRs and removing unnecessary items and added necessary sections like backdating and revocation investigations.<o:p></o:p></span></li></ul><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level1 lfo3'><span style='font-size:12.0pt'>Ballot: Signing Service Update (Bruce)<o:p></o:p></span></li><ul style='margin-top:0in' type=disc><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Previous action item was to change the definition of Signing Service to align what a signing service does and its models.<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Proposed definition- **Subscriber Key Protection Service**: An organization that generates the Key Pair and securely generates and manages the Private Key associated with a Subscriber's Code Signing Certificate.<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Discussion from Bruce M., Tim H., Ian M., Inigo B., and Martijn K. on the requirements for signing service: who generates, who activates, who stores, how it is stored and how is it managed. Discussion around adjusting the name from Signing Service to Subscriber Key Protection Service as the focus of the Signing Service is on protection not the artifact being signed.<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Next step is to close out the comments, push through the new definition, get a second proposal, and effective date.<o:p></o:p></span></li></ul><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level1 lfo3'><span style='font-size:12.0pt'>Ballot: Remove SSL BR References – tabled discussion<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level1 lfo3'><span style='font-size:12.0pt'>Other business – F2F prep<o:p></o:p></span></li><ul style='margin-top:0in' type=disc><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt'>Top 3 Goals are being worked on <o:p></o:p></span></li></ul></ol><p class=MsoPlainText style='margin-left:1.25in;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                                  </span>i.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt'>Revocation ballot<o:p></o:p></span></p><p class=MsoPlainText style='margin-left:1.25in;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                                 </span>ii.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt'>Subscriber Key Protection Service ballot<o:p></o:p></span></p><p class=MsoPlainText style='margin-left:1.25in;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                               </span>iii.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt'>SSL BR reference ballot<o:p></o:p></span></p><ol style='margin-top:0in' start=6 type=1><ul style='margin-top:0in' type=disc><li class=MsoListParagraphCxSpFirst style='margin-left:-.25in;mso-add-space:auto;mso-list:l1 level2 lfo3'><span style='font-size:12.0pt;line-height:105%'>Additional goals: <o:p></o:p></span></li></ul></ol><p class=MsoListParagraphCxSpMiddle style='margin-left:1.25in;mso-add-space:auto;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt;line-height:105%'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                                  </span>i.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt;line-height:105%'>timestamp updates<o:p></o:p></span></p><p class=MsoListParagraphCxSpMiddle style='margin-left:1.25in;mso-add-space:auto;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt;line-height:105%'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                                 </span>ii.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt;line-height:105%'>high risk applicants<o:p></o:p></span></p><p class=MsoListParagraphCxSpMiddle style='margin-left:1.25in;mso-add-space:auto;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt;line-height:105%'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                               </span>iii.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt;line-height:105%'>validity period<o:p></o:p></span></p><p class=MsoListParagraphCxSpMiddle style='margin-left:1.25in;mso-add-space:auto;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt;line-height:105%'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                               </span>iv.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt;line-height:105%'>shorter lived certificates<o:p></o:p></span></p><p class=MsoListParagraphCxSpMiddle style='margin-left:1.25in;mso-add-space:auto;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo3'><![if !supportLists]><span style='font-size:12.0pt;line-height:105%'><span style='mso-list:Ignore'><span style='font:7.0pt "Times New Roman"'>                                                 </span>v.<span style='font:7.0pt "Times New Roman"'>      </span></span></span><![endif]><span style='font-size:12.0pt;line-height:105%'>certificate transparency<o:p></o:p></span></p><ol style='margin-top:0in' start=7 type=1><li class=MsoListParagraphCxSpLast style='margin-left:-.25in;mso-add-space:auto;mso-list:l1 level1 lfo3'><span style='font-size:12.0pt;line-height:105%'>Next Meeting – Potentially cancel the meeting on 23 February<o:p></o:p></span></li><li class=MsoPlainText style='margin-left:-.25in;mso-list:l1 level1 lfo3'><span style='font-size:12.0pt'>Adjourn   <o:p></o:p></span></li></ol><p class=MsoNormal><span style='font-size:12.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:12.0pt'><o:p> </o:p></span></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p></div></body></html>