<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
StartCom votes YES.<br>
<br>
<div class="moz-cite-prefix">On 09/14/2015 10:11 PM, Dean Coclin
wrote:<br>
</div>
<blockquote
cite="mid:14D026C7F297AD44AC82578DD818CDD047B8E6B0CA@TUS1XCHEVSPIN35.SYMC.SYMANTEC.COM"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-fareast-language:ZH-CN;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal">Due to the confusion as to the voting
period on ballot 150, it failed for lack of quorum. We are
therefore submitting this as a new ballot. The discussion
period begins today followed by voting per the schedule
below. We believe we have captured all the comments but if
you have others, please feel free to remark.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b><o:p> </o:p></b></p>
<p class="MsoNormal"><b>Ballot 151- Revised Addition of Optional
OIDs for Indicating Level of Validation</b><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"> The following motion has been proposed by
Dean Coclin of Symantec and endorsed by Jeremy Rowley of
Digicert and Kirk Hall of Trend Micro.<span
style="color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">-- MOTION BEGINS –<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoListParagraph" style="text-indent:-.25in">1)<span
style="font-size:7.0pt;font-family:"Times New
Roman","serif""> </span>Modify section
1.2 of Baseline Requirements as follows:<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><b>1.2 Document Name and Identification</b><o:p></o:p></p>
<p class="MsoNormal">This certificate policy (CP) contains the
requirements for the issuance and management of
publicly‐trusted SSL certificates, as adopted by the
CA/Browser Forum. <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">The following Certificate Policy
identifiers are reserved for use by CAs as an optional means
of asserting compliance with this CP (OID arc 2.23.140.1.2) as
follows: <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) baseline‐ requirements(2)
domain‐validated(1)} (2.23.140.1.2.1); <o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal">{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) baseline‐ requirements(2)
organization-validated(2)} (2.23.140.1.2.2) and<o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><u>{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) baseline‐ requirements(2)
individual-validated(3)} (2.23.140.1.2.3).<o:p></o:p></u></p>
<p class="MsoNormal" style="text-indent:.5in"><span
style="color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoListParagraph" style="text-indent:-.25in">2)<span
style="font-size:7.0pt;font-family:"Times New
Roman","serif""> </span>Modify section
7.1.6.1 of the Baseline Requirements as follows:<o:p></o:p></p>
<p class="MsoNormal"><b><span style="color:#1F497D"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b>7.1.6.1. Reserved Certificate Policy
Identifiers </b><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">This section describes the content
requirements for the Root CA, Subordinate CA, and Subscriber
Certificates, as they relate to the identification of
Certificate Policy. <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">The following Certificate Policy
identifiers are reserved for use by CAs as an optional means
of asserting compliance with these Requirements as follows: <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) baseline‐requirements(2)
domain‐validated(1)} (2.23.140.1.2.1), if the Certificate
complies with these Requirements but lacks Subject Identity
Information that is verified in accordance with either Section
3.2.2.1 <u>or Section 3.2.3</u>.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">If the Certificate asserts the policy
identifier of 2.23.140.1.2.1, then it MUST NOT include
organizationName, givenName, surname, streetAddress,
localityName, stateOrProvinceName, or postalCode in the
Subject field. <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) baseline‐requirements(2)
organization-validated(2)} (2.23.140.1.2.2), if the
Certificate complies with these Requirements and includes
Subject Identity Information that is verified in accordance
with Section 3.2.2.1.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal"><u>{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) baseline‐requirements(2)
individual-validated(3)} (2.23.140.1.2.3), if the
Certificate complies with these Requirements and includes
Subject Identity Information that is verified in accordance
with Section 3.2.3.<o:p></o:p></u></p>
<p class="MsoNormal"><u> <o:p></o:p></u></p>
<p class="MsoNormal">If the Certificate asserts the policy
identifier of 2.23.140.1.2.2, then it MUST also include
organizationName, localityName <u>(to the extent such field
is required under Section 7.1.4.2.2)</u>,
stateOrProvinceName <u>(to the extent such field is required
under Section 7.1.4.2.2</u>), and countryName in the Subject
field. <u>If the Certificate asserts the policy identifier of
2.23.140.1.2.3, then it MUST also include (i) either
organizationName or givenName and surname, (ii) localityName
(to the extent such field is required under Section
7.1.4.2.2), (iii) stateOrProvinceName (to the extent
required under Section 7.1.4.2.2), and (iv) countryName in
the Subject field.</u><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoListParagraph" style="text-indent:-.25in">3)<span
style="font-size:7.0pt;font-family:"Times New
Roman","serif""> </span>Modify the
definition of “EV OID” in the EV Guidelines as follows:<o:p></o:p></p>
<p class="MsoListParagraph"><o:p> </o:p></p>
<p class="MsoNormal"><b>EV OID</b>: An identifying number, in
the form of an “object identifier,” that is included in the
certificatePolicies field of a certificate that: (i) indicates
which CA policy statement relates to that certificate, and
(ii) <u>is either the CA/Browser Forum EV policy identifier
or a policy identifier that</u>, by pre-agreement with one
or more Application Software Supplier, marks the certificate
as being an EV Certificate.<o:p></o:p></p>
<p class="MsoListParagraph"><o:p> </o:p></p>
<p class="MsoListParagraph" style="text-indent:-.25in">4)<span
style="font-size:7.0pt;font-family:"Times New
Roman","serif""> </span>Modify Section
9.3.2 of the EV Guidelines as follows:<o:p></o:p></p>
<p class="MsoNormal">Each EV Certificate issued by the CA to a
Subscriber MUST contain a policy identifier <u>that is either</u>
defined by <u>these Guidelines or </u>the CA in the
certificate’s certificatePolicies extension that: (i)
indicates which CA policy statement relates to that
Certificate, (ii) asserts the CA’s adherence to and compliance
with these Guidelines, and (iii), <u>is either the CA/Browser
Forum’s EV policy identifier or a policy identifier that, </u>by
pre-agreement with the Application Software Supplier, marks
the Certificate as being an EV Certificate.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><u>The following Certificate Policy
identifier is the CA/Browser Forum’s EV policy identifier: <o:p></o:p></u></p>
<p class="MsoNormal"><u>{joint‐iso‐itu‐t(2)
international‐organizations(23) ca‐browser‐forum(140)
certificate‐policies(1) ev-guidelines (1) } (2.23.140.1.1),
if the Certificate complies with these Guidelines.<o:p></o:p></u></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">If the ballot passes, the custodian of the
Forum OIDs will be instructed to obtain the new OID for IV as
indicated above.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">-- MOTION ENDS –<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">The review period for this ballot shall
commence at 2200 UTC on Monday, September 14, 2015, and will
close at 2200 UTC on Monday, September 21, 2015. Unless the
motion is withdrawn during the review period, the voting
period will start immediately thereafter and will close at
2200 UTC on Monday, September 28, 2015. Votes must be cast by
posting an on-list reply to this thread.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">A vote in favor of the motion must indicate
a clear 'yes' in the response. A vote against must indicate a
clear 'no' in the response. A vote to abstain must indicate a
clear 'abstain' in the response. Unclear responses will not be
counted. The latest vote received from any representative of a
voting member before the close of the voting period will be
counted. Voting members are listed here: <a
moz-do-not-send="true" href="https://cabforum.org/members/"><span
style="color:windowtext">https://cabforum.org/members/</span></a><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal">In order for the motion to be adopted, two
thirds or more of the votes cast by members in the CA category
and greater than 50% of the votes cast by members in the
browser category must be in favor. Quorum is currently nine
(9) members– at least nine members must participate in the
ballot, either by voting in favor, voting against, or
abstaining.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Dean Coclin<o:p></o:p></p>
<p class="MsoNormal">Chair CA/B Forum<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Public mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Public@cabforum.org">Public@cabforum.org</a>
<a class="moz-txt-link-freetext" href="https://cabforum.org/mailman/listinfo/public">https://cabforum.org/mailman/listinfo/public</a>
</pre>
</blockquote>
<br>
<div class="moz-signature">-- <br>
<table border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td colspan="2">Regards </td>
</tr>
<tr>
<td colspan="2"> </td>
</tr>
<tr>
<td>Signer: </td>
<td>Eddy Nigg, COO/CTO</td>
</tr>
<tr>
<td> </td>
<td><a href="http://www.startcom.org">StartCom Ltd.</a></td>
</tr>
<tr>
<td>XMPP: </td>
<td><a href="xmpp:startcom@startcom.org">startcom@startcom.org</a></td>
</tr>
<tr>
<td>Blog: </td>
<td><a href="http://blog.startcom.org">Join the Revolution!</a></td>
</tr>
<tr>
<td>Twitter: </td>
<td><a href="http://twitter.com/eddy_nigg">Follow Me</a></td>
</tr>
<tr>
<td colspan="2"> </td>
</tr>
</tbody>
</table>
</div>
</body>
</html>