<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">Hi,<br>
<br>
SSC votes: "Yes".<br>
<br>
Thanks,<br>
M.D.<br>
<br>
On 2/7/2013 6:44 AM, Jeremy Rowley wrote:<br>
</div>
<blockquote cite="mid:058a01ce04ed$e052dc10$a0f89430$@digicert.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
p.line874, li.line874, div.line874
{mso-style-name:line874;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
p.line862, li.line862, div.line862
{mso-style-name:line862;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="line874"><span style="font-size:10.0pt">If passed, the
motion will restrict CAs from issuing Certificates with
extensions and other contents that the CA doesn’t understand
or have a purpose of including in the certificate.<o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">----- <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">Jeremy Rowley
made the following motion, and Ryan Hurst and Robin Alden
endorsed it: <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">... Motion
Begins ... <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">... Erratum
Begins ... <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">A. In Section
10.2.3, after the first paragraph, insert: “The CA SHALL
establish and follow a documented procedure for verifying
all data requested for inclusion in the Certificate by the
Applicant.” <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">B. In Appendix
B, add paragraph numbers to the headings: “(1) Root CA
Certificate”, “(2) Subordinate CA Certificate”, and “(3)
Subscriber Certificate”. <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">C. In three
places in Appendix B, delete: “All other fields and
extensions MUST be set in accordance with RFC 5280.” <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">D. In Appendix
B, insert paragraph 4, as follows <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">“(4) All
Certificates <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">All other
fields and extensions MUST be set in accordance with RFC
5280. The CA SHALL NOT issue a Certificate that contains a
keyUsage flag, extendedKeyUsage value, Certificate
extension, or other data not specified in this Appendix B
unless the CA is aware of a reason for including the data in
the Certificate. <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">CAs SHALL NOT
issue a Certificate with: <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">a) Extensions
that do not apply in the context of the public Internet
(such as an extendedKeyUsage value for a service that is
only valid in the context of a privately managed network),
unless: <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">i. such value
falls within an OID arc for which the Applicant demonstrates
ownership; or <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">ii. the
Applicant can otherwise demonstrate the right to assert the
data in a public context; or <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">b) semantics
that, if included, will mislead a Relying Party about the
certificate information verified by the CA (such as
including extendedKeyUsage value for a smart card, where the
CA is not able to verify that the corresponding Private Key
is confined to such hardware due to remote issuance). <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">... Erratum
ends ... <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">The review
period for this ballot shall commence at 21:00 UTC on 7
February 2013 and will close at 21:00 UTC on 14 February
2013. Unless the motion is withdrawn during the review
period, the voting period will start immediately thereafter
and will close at 21:00 UTC on 21 February 2013. Votes must
be cast by posting an on-list reply to this thread. <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">... Motions
ends ... <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">A vote in
favor of the motion must indicate a clear 'yes' in the
response. <o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">A vote against
must indicate a clear 'no' in the response. A vote to
abstain must indicate a clear 'abstain' in the response.
Unclear responses will not be counted. The latest vote
received from any representative of a voting member before
the close of the voting period will be counted. <o:p></o:p></span></p>
<p class="line862"><span style="font-size:10.0pt">Voting members
are listed here: <a moz-do-not-send="true"
href="http://www.cabforum.org/forum.html">http://www.cabforum.org/forum.html</a>
<o:p></o:p></span></p>
<p class="line874"><span style="font-size:10.0pt">In order for
the motion to be adopted, two thirds or more of the votes
cast by members in the CA category and one half or more of
the votes cast by members in the browser category must be in
favor. Also, at least six members must participate in the
ballot, either by voting in favor, voting against or
abstaining. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt"><o:p> </o:p></span></p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Public mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Public@cabforum.org">Public@cabforum.org</a>
<a class="moz-txt-link-freetext" href="https://cabforum.org/mailman/listinfo/public">https://cabforum.org/mailman/listinfo/public</a>
</pre>
</blockquote>
<br>
</body>
</html>