<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:10.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;
        mso-ligatures:none;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:309017034;
        mso-list-type:hybrid;
        mso-list-template-ids:1670441168 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New",serif;}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New",serif;}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New",serif;}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l1
        {mso-list-id:462768804;
        mso-list-template-ids:-1981520408;}
@list l1:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New",serif;
        mso-bidi-font-family:"Times New Roman";}
@list l1:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link="#0563C1" vlink="#954F72" style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><span style='font-size:11.0pt'>Final Minutes: </span><b><span style='font-size:12.0pt;color:#1D1D1D'>Code Signing WG Meeting: May 4, 2023</span></b><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal><b><span style='font-size:12.0pt;color:#1D1D1D'> </span></b><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal><b><span style='font-size:12.0pt;color:#1D1D1D'>Attendance:</span></b><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:12.0pt;color:#1D1D1D'>Atsushi Inaba (GlobalSign), Corey Bonnell (DigiCert), Dean Coclin (DigiCert), Tim Hollebeek (DigiCert), Janet Hines (VikingCloud), Martijn Katerbarg (Sectigo), Tim Crawford (BDO),  Ben Dewberry (Keyfactor), Bruce Morton (Entrust), Ian McMillan (Microsoft), Mohit Kumar (GlobalSign), Rollin Yu (TrustAsia), Eva Van Steenberge (GlobalSign)  </span><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal><b><span style='font-size:12.0pt;color:#1D1D1D'> </span></b><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal><b><u><span style='font-size:12.0pt;color:#1D1D1D'>Minutes</span></u></b><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal style='mso-line-height-alt:11.55pt'><b><span style='font-size:12.0pt;color:#1D1D1D'>Antitrust statement: </span></b><span style='font-size:12.0pt;color:#1D1D1D'>The Antitrust statement was read.</span><span style='color:#1D1D1D'><o:p></o:p></span></p><p class=MsoNormal style='margin-bottom:8.0pt;mso-line-height-alt:11.55pt'><b><span style='font-size:12.0pt;color:#1D1D1D'>Approval of minutes</span></b><span style='font-size:12.0pt;color:#1D1D1D'>: Minutes for 26 January 2023 & 20 April 2023 approved<o:p></o:p></span></p><ul type=disc><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level1 lfo3'>Ballot: CSC 18 – Malware base revocation (Martijn)<o:p></o:p></li><ul type=circle><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Sending out v2.1 soon<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Noted a few small changes<o:p></o:p></li><ul type=square><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level3 lfo3'>Request from Ian<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level3 lfo3'>Changed effective date to allow both using the new procedure right away or wait until the effective date (April 15, 2024)<o:p></o:p></li></ul><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Tim will send around internally for review.<o:p></o:p></li></ul><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level1 lfo3'><span style='background:white'>Ballot: Remove SSL BR References (Dimitris was not present so Bruce gave update) </span><o:p></o:p></li><ul type=circle><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'><span style='background:white'>Review of the capitalized terms has started but is not complete</span><o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'><span style='background:white'>Looking for two endorsers </span><o:p></o:p></li></ul><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level1 lfo3'><span style='background:white'>F2F Agenda Topics Discussion </span><o:p></o:p></li><ul type=circle><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Discussion around possible presentation from Microsoft but Ian is looking for some idea of the main topics<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Suggested there may be time to discuss signing services after the revocation and 3647 ballot but may need to wait for updates based other ballots<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Suggested to discuss Timestamping changes<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Suggested discussing removing text allowing for keys not stored in hw <o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Bruce suggested discussing high risk items, and Tim mentioned that in previous discussions post June the plan was to remove high risk language, Bruce agreed. <o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Bruce suggested potentially a clean-up ballot <o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Ben suggested discussion around some of the proposed changes in the CSBRs and will think about specific topics for discussion<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Some side discussion between Bruce and Ian about the future of EV certificates, potential topic for MS to present on and/or have on the agenda at the F2F<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Ian suggested discussing certificate transparency for code signing certificates were there was discussion amongst the attendees that it was a good topic to add<o:p></o:p></li></ul><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level1 lfo3'>In summary; timestamping changes, high risk language, potentially some specific CSBR github discussion threads, EV/OV certificates, certificate transparency<o:p></o:p></li><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level1 lfo3'>Other business<o:p></o:p></li><ul type=circle><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level2 lfo3'>Discussed request for new interested party participant from Hydraulic Software, Dean will connect with Wayne to accomplish. <o:p></o:p></li></ul><li class=MsoListParagraph style='color:#1D1D1D;line-height:11.55pt;mso-list:l0 level1 lfo3'>Next Meeting: May 18<sup>th</sup> 2023<o:p></o:p></li><li class=MsoListParagraph style='line-height:11.55pt;mso-list:l0 level1 lfo3'><span style='color:#1D1D1D'>Adjourn</span><o:p></o:p></li></ul></div></body></html>