<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:12.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:8.0pt;
margin-left:.5in;
mso-add-space:auto;
line-height:105%;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst
{mso-style-priority:34;
mso-style-type:export-only;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
mso-add-space:auto;
line-height:105%;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle
{mso-style-priority:34;
mso-style-type:export-only;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
mso-add-space:auto;
line-height:105%;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast
{mso-style-priority:34;
mso-style-type:export-only;
margin-top:0in;
margin-right:0in;
margin-bottom:8.0pt;
margin-left:.5in;
mso-add-space:auto;
line-height:105%;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Aptos",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
mso-ligatures:none;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:312218189;
mso-list-template-ids:-1534014110;}
@list l0:level1
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level2
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:1.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level3
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:1.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level4
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:2.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level5
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:2.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level6
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:3.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level7
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:3.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level8
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:4.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l0:level9
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:4.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l1
{mso-list-id:671882060;
mso-list-type:hybrid;
mso-list-template-ids:-308140276 -889948414 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l1:level1
{mso-level-start-at:0;
mso-level-number-format:bullet;
mso-level-text:-;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Calibri",sans-serif;
mso-fareast-font-family:"Times New Roman";}
@list l1:level2
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Courier New";}
@list l1:level3
{mso-level-number-format:bullet;
mso-level-text:\F0A7;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;}
@list l1:level4
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Symbol;}
@list l1:level5
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Courier New";}
@list l1:level6
{mso-level-number-format:bullet;
mso-level-text:\F0A7;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;}
@list l1:level7
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Symbol;}
@list l1:level8
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Courier New";}
@list l1:level9
{mso-level-number-format:bullet;
mso-level-text:\F0A7;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;}
@list l2
{mso-list-id:806168009;
mso-list-template-ids:-1196909296;}
@list l2:level1
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level2
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:1.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level3
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:1.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level4
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:2.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level5
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:2.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level6
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:3.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level7
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:3.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level8
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:4.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l2:level9
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:4.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3
{mso-list-id:2039351985;
mso-list-template-ids:-1841762598;}
@list l3:level1
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level2
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:1.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level3
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:1.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level4
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:2.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level5
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:2.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level6
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:3.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level7
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:3.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level8
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:4.0in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
@list l3:level9
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:4.5in;
mso-level-number-position:left;
text-indent:-.25in;
mso-ansi-font-size:10.0pt;
font-family:Symbol;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link="#467886" vlink="#96607D" style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal>CSCWG Final minutes May 16, 2024</p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Attendance:<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Mohit Kumar - GlobalSign<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Dean Coclin-DigiCert<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Atsushi INABA - GlobalSign<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Ben Dewberry -Keyfactor<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Brian Winters - IdenTrust<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Brianca Martin - Amazon<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Bruce Morton - Entrust<o:p></o:p></span></p><p class=MsoNormal><span lang=ES style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Corey Bonnell-Digicert<o:p></o:p></span></p><p class=MsoNormal><span lang=ES style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Dimitris Zacharopoulos - HARICA<o:p></o:p></span></p><p class=MsoNormal><span lang=ES style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Martijn Katerbarg - Sectigo<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Richard Kisley (Guest)<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif;letter-spacing:-.2pt;mso-ligatures:none'>Scott Rea - eMudhra<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Antitrust statement was read. <o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Meeting Minutes of 2<sup>nd</sup>-May-24 approved.<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Following Ballots were discussed. <o:p></o:p></span></p><p class=MsoNormal><u><span style='font-family:"Arial",sans-serif'>-Removing EV Guidelines References: <o:p></o:p></span></u></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Dimitris removed the Organization Identifier requirements from the updates that had objection from the group. There was alignment on using EV Codesigning certificates vs EV Certificates. Updates to be made by Dimitris. Ballot Process can be started if no further comments and looks right.<o:p></o:p></span></p><p class=MsoNormal><u><span style='font-family:"Arial",sans-serif'>-CSC - 23:<o:p></o:p></span></u></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>It was not received publicly so it has not been published. Corey mentioned it is required step. Bruce will send it to Public list so Corey can take from there for publication.<o:p></o:p></span></p><p class=MsoNormal><u><span style='font-family:"Arial",sans-serif'>-CSC-24: </span></u><span style='font-family:"Arial",sans-serif'>Time-stamp Requirements update<u><o:p></o:p></u></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>No further comments from anyone. Voting will be started.<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Proposal for PCI-HSM acceptance for CA HSMs evaluation by R.Kisley was discussed<o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Kisley mentioned that:-<o:p></o:p></span></p><ul style='margin-top:0in' type=disc><li class=MsoListParagraphCxSpFirst style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>PCI has high level assurance requirements<o:p></o:p></span></li><li class=MsoListParagraphCxSpMiddle style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>FIPS program has long queue so good to have other option<o:p></o:p></span></li><li class=MsoListParagraphCxSpLast style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>PCI Version 4 is proposed as PCI version 3 is going to expire in 2026<o:p></o:p></span></li></ul><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>So request is to add PCI HSM as an alternative criteria to FIPS. <o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Bruce mentioned that need to understand if it will be accepted by Root programs. <o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Dimitris mentioned that Certification of standard is also important. <o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Richard Kisley to reach out to Microsoft/raise this in F2F. <o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>F2F Agenda was discussed and following topics identified for discussion:<o:p></o:p></span></p><ul style='margin-top:0in' type=disc><li class=MsoListParagraphCxSpFirst style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>Maximum Certificate Validity period for Codesigning certificates<o:p></o:p></span></li><li class=MsoListParagraphCxSpMiddle style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>EV Codesigning changes by Microsoft, dependent usecases on EV and future direction <o:p></o:p></span></li><li class=MsoListParagraphCxSpMiddle style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>Problem of change in Subject DN for publishers impacting continuity of upgrades and Use of Subject Organization specific EKU <o:p></o:p></span></li><li class=MsoListParagraphCxSpMiddle style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>CT Logging<o:p></o:p></span></li><li class=MsoListParagraphCxSpLast style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>Need for Organization Identifier for Codesigning certificates<o:p></o:p></span></li></ul><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Dean to share the list ahead to Ian. <o:p></o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'>Membership of Encryption Consulting, okay to join as interested party. <o:p></o:p></span></p><ul style='margin-top:0in' type=disc><li class=MsoListParagraph style='margin-bottom:0in;margin-left:0in;mso-add-space:auto;line-height:normal;mso-list:l1 level1 lfo3'><span style='font-family:"Arial",sans-serif'>No objections raised<o:p></o:p></span></li></ul><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-family:"Arial",sans-serif'><o:p> </o:p></span></p><div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Arial",sans-serif;color:#48565E;mso-ligatures:none'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Arial",sans-serif;color:#48565E;mso-ligatures:none'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;mso-ligatures:none'><o:p> </o:p></span></p></div><p class=MsoNormal><o:p> </o:p></p></div></body></html>