<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p><font face="Calibri">+1</font><br>
</p>
<div class="moz-cite-prefix">Il 28/02/2024 10:16, Dimitris
Zacharopoulos (HARICA) via Cscwg-public ha scritto:<br>
</div>
<blockquote type="cite"
cite="mid:0100018def00533a-ed751293-2780-4d97-8825-f7d1841724b7-000000@email.amazonses.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<title></title>
<div align="center">
<table width="30%" cellspacing="2" cellpadding="2" border="1">
<tbody>
<tr>
<td valign="top" bgcolor="#ffff00"> <span
style="color: red;">NOTICE:</span> Pay attention -
external email - Sender is
<a class="moz-txt-link-abbreviated" href="mailto:0100018def00533a-ed751293-2780-4d97-8825-f7d1841724b7-000000@amazonses.com">0100018def00533a-ed751293-2780-4d97-8825-f7d1841724b7-000000@amazonses.com</a>
</td>
</tr>
</tbody>
</table>
<br>
</div>
<br>
<br>
Dear Members,
<br>
<br>
As we discussed today at the F2F#61 meeting, I would like to
propose a ballot to mark the "Guidelines For The Issuance And
Management Of Extended Validation Code Signing Certificates" as
obsolete. I suggest that we update the <a
href="https://cabforum.org/working-groups/code-signing/ev-code-signing-certificate-guidelines/"
moz-do-not-send="true">
latest EVCS Guidelines v1.4</a> to version 1.5 with the
following changes:
<br>
<br>
--- BEGIN DRAFT BALLOT LANGUAGE ---
<br>
<br>
In the "Notice to Readers" section, update the second paragraph to
state:
<br>
<br>
<b>"The Code Signing Working Group considers this document
OBSOLETE
as of XX XXXXXXXX XXXX. CAs SHOULD NOT use this standard but
instead SHOULD use the "Baseline Requirements for the Issuance
and
Management of PubliclyâTrusted Code Signing Certificates" that
has
incorporated and improved requirements related to Extended
Validation (EV) Code Signing Certificates"</b>
<br>
<br>
Update section 17.1 to state the following:
<br>
<br>
"
<b><span lang="EN-US">As this document is marked OBSOLETE, CAs
SHOULD NOT be audited against this standard.</span></b> "
<br>
<br>
--- END DRAFT BALLOT LANGUAGE ---
<br>
<br>
The <b>XX XXXXXXXX XXXX</b> will include an <b>effective date</b>
we decide. I propose this date is <b>in the past</b> but I am not
sure what would be a reasonable date. One thought is
to ask if there is a CA Member that has been audited recently
against the EV CS Guidelines v1.4. Another thought is to ask CPA
Canada and ACAB'c for feedback about when they stopped issuing
Audit Letters that cover the EV CS Guidelines v1.4. Other ideas
are
welcome.
<br>
<br>
Can I also have two endorsers so I can reserve a ballot number?
<br>
<br>
<br>
Thank you,
<br>
Dimitris.
<br>
<br>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<pre class="moz-quote-pre" wrap="">_______________________________________________
Cscwg-public mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Cscwg-public@cabforum.org">Cscwg-public@cabforum.org</a>
<a class="moz-txt-link-freetext" href="https://lists.cabforum.org/mailman/listinfo/cscwg-public">https://lists.cabforum.org/mailman/listinfo/cscwg-public</a>
</pre>
</blockquote>
</body>
</html>