<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-2022-jp">
<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta name=Generator content="Microsoft Word 14 (filtered medium)"><title>Ballot 152 - Issuance of SHA-1 certificates through 2016</title><style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:"\@SimSun";
        panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:SimSun;
        mso-fareast-language:ZH-CN;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:SimSun;
        mso-fareast-language:ZH-CN;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;
        font-weight:normal;
        font-style:normal;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:26950464;
        mso-list-template-ids:-1585043792;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1
        {mso-list-id:220601603;
        mso-list-template-ids:1298954288;}
@list l1:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l1:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2
        {mso-list-id:938216563;
        mso-list-template-ids:2118025262;}
@list l2:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l2:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l2:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3
        {mso-list-id:1437366014;
        mso-list-template-ids:-2092135470;}
@list l3:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l3:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4
        {mso-list-id:1589191328;
        mso-list-template-ids:-32479900;}
@list l4:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l4:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l4:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Symantec and the endorsers withdraw this ballot.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal style='margin-left:.5in'><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> public-bounces@cabforum.org [mailto:public-bounces@cabforum.org] <b>On Behalf Of </b>Rick Andrews<br><b>Sent:</b> Friday, October 02, 2015 10:45 AM<br><b>To:</b> public@cabforum.org<br><b>Subject:</b> [cabfpub] Ballot 152 - Issuance of SHA-1 certificates through 2016<o:p></o:p></span></p></div></div><p class=MsoNormal style='margin-left:.5in'><o:p> </o:p></p><p style='margin-left:.5in'><b><span style='font-family:"Calibri","sans-serif"'>Ballot 152</span> </b><b><span style='font-family:"Calibri","sans-serif"'>-</span> </b><b><span style='font-family:"Calibri","sans-serif"'>Issuance of SHA-1 certificates through 2016</span></b><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>The following motion has been proposed by</span> <span style='font-family:"Calibri","sans-serif"'>Rick Andrews of Symantec and endorsed by</span> <span style='font-family:"Calibri","sans-serif"'>Bruce Morton of Entrust, Jody Cloutier of Microsoft, and Kirk Hall of Trend Micro.</span><o:p></o:p></p><p style='margin-left:1.5in'><span style='font-family:"Calibri","sans-serif"'> </span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>-- MOTION BEGINS –</span><o:p></o:p></p><p style='margin-left:1.5in'><span style='font-family:"Calibri","sans-serif"'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif"'>1)</span><span style='font-size:7.5pt;font-family:"Times New Roman","serif"'>     </span> <span style='font-family:"Calibri","sans-serif"'>Modify section</span> <span style='font-family:"Calibri","sans-serif"'>7.1.3 of Baseline Requirements as follows:</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>The purpose of the ballot is to</span> <span style='font-family:"Calibri","sans-serif";color:#1F497D'>allow the issuance of SHA-1 certificates through 2016, with maximum Expiry Date of 31 December 2016. Although the vast majority of customers have been able or will be able to transition to SHA-2 certificates by the issuance termination date of 31 December 2015, a very small number of very large enterprise customers have disclosed to us that they simply cannot complete this work before the issuance deadline. This is attributed to the sheer volume of certificates that they need to migrate (numbering in the thousands), and their end-of-year blackout period. These customers accept the risk of continuing to use new SHA-1 certificates, and assert that if they can continue to enroll for and receive SHA-1 certificates through 2016 (all with an expiration date of 31 December 2016 or earlier), they will be able to complete the transition by the end of 2016.</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>We realize that extending the issuance period will extend the collision attack period. Although we feel that the BRs already mandate enough entropy (typically in the certificate serial number) to guard against that attack, it can be further mitigated by limiting SHA-1 certificate issuance to Subordinate CAs that have a basicConstraints pathLength = 0.</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>The intent of the ballot is to allow limited issuance of SHA-1 certificates through 2016, as long as any SHA-1 certificate created in 2016 expires by the end of 2016. We also correct the number of the Section number in the body of the Section (which incorrectly references $B!H(JSection 9.4.2$B!I(J (J–(J that mistake was probably made in the conversion to RFC 3647 format).</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>BR 1.3.0 currently reads:</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>$B!H(J7.1.3. Algorithm Object Identifiers</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>Effective 1 January 2016, CAs MUST NOT issue any new Subscriber certificates or Subordinate CA certificates using the SHA$B!>(J1 hash algorithm. CAs MAY continue to sign certificates to verify OCSP responses using SHA1 until 1 January 2017. This Section 9.4.2 does not apply to Root CA or CA cross certificates. CAs MAY continue to use their existing SHA$B!>(J1 Root Certificates. SHA$B!>(J2 Subscriber certificates SHOULD NOT chain up to a SHA$B!>(J1 Subordinate CA Certificate.$B!I(J</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>$B!H(JEffective 16 January 2015, CAs SHOULD NOT issue Subscriber Certificates utilizing the SHA$B!>(J1 algorithm with an Expiry Date greater than 1 January 2017 because Application Software Providers are in the process of deprecating and/or removing the SHA$B!>(J1 algorithm from their software, and they have communicated that CAs and Subscribers using such certificates do so at their own risk.$B!I(J</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>Modify section 7.1.3 of Baseline Requirements as follows:</span> <span style='font-family:"Calibri","sans-serif";color:#1F497D'>(see attached Word or PDF files to more clearly view the</span> <span style='font-family:"Calibri","sans-serif";color:#1F497D'>proposed</span> <span style='font-family:"Calibri","sans-serif";color:#1F497D'>changes):</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>$B!H(J7.1.3. Algorithm Object Identifiers</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>Effective 1 January 2016, CAs MUST NOT issue any new Subordinate CA certificates using the SHA$B!>(J1 hash algorithm. Effective 1 January 2017, CAs MUST NOT issue any new Subscriber certificates using the SHA$B!>(J1 hash algorithm. CAs MAY continue to sign certificates to verify OCSP responses using SHA1 until 1 January 2017. This Section 7.1.3 does not apply to Root CA or CA cross certificates. CAs MAY continue to use their existing SHA$B!>(J1 Root Certificates. SHA$B!>(J2 Subscriber certificates SHOULD NOT chain up to a SHA$B!>(J1 Subordinate CA Certificate.</span> <o:p></o:p></p><(Jp style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>Effective 16 January 2015, CAs SHOULD NOT issue Subscriber Certificates utilizing the SHA$B!>(J1 algorithm with an Expiry Date greater than 1 January 2017 because Application Software Providers are in the process of deprecating and/or removing the SHA$B!>(J1 algorithm from their software, and they have communicated that CAs and Subscribers using such certificates do so at their own risk.</span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'> </span><o:p></o:p></p><p style='margin-left:1.0in'><span style='font-family:"Calibri","sans-serif";color:#1F497D'>Effective 1 January 2016, CAs MUST NOT issue Subscriber Certificates utilizing the SHA$B!>(J1 algorithm with an Expiry Date greater than 1 January 2017. Any SHA-1 Subscriber Certificates issued after 1 January 2016 must be signed by a Subordinate CA certificate with a basicConstraints pathLen=0.$B!I(J</span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>-- MOTION ENDS (J–(J</span><o:p></o:p></p><p style='margin-left:1.5in'><span style='font-family:"Calibri","sans-serif"'> </span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>The review period for this ballot shall commence at 2200 UTC on Monday,</span> <span style='font-family:"Calibri","sans-serif"'>October <span style='color:#1F497D'>5</span>, 2015, and will close at 2200 UTC on Monday,</span> <span style='font-family:"Calibri","sans-serif"'>October</span> <span style='font-family:"Calibri","sans-serif";color:#1F497D'>12</span><span style='font-family:"Calibri","sans-serif"'>, 2015. Unless the motion is withdrawn during the review period, the voting period will start immediately thereafter and will close at 2200 UTC on Monday,</span> <span style='font-family:"Calibri","sans-serif"'>October</span> <span style='font-family:"Calibri","sans-serif"'>1<span style='color:#1F497D'>9</span>, 2015. Votes must be cast by posting an on-list reply to this thread.</span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>A vote in favor of the motion must indicate a clear 'yes' in the response. A vote against must indicate a clear 'no' in the response. A vote to abstain must indicate a clear 'abstain' in the response. Unclear responses will not be counted. The latest vote received from any representative of a voting member before the close of the voting period will be counted. Voting members are listed here: </span><a href="https://cabforum.org/members/"><span style='font-family:"Calibri","sans-serif"'>https://cabforum.org/members/</span></a><o:p></o:p></p><p style='margin-left:1.5in'><span style='font-family:"Calibri","sans-serif"'> </span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>In order for the motion to be adopted, two thirds or more of the votes cast by members in the CA category and greater than 50% of the votes cast by members in the browser category must be in favor. Quorum is currently nine (9) members(J–(J at least nine members must participate in the ballot, either by voting in favor, voting against, or abstaining.</span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-family:"Calibri","sans-serif"'>-Rick</span><o:p></o:p></p><p style='margin-left:.5in'><span style='font-size:10.0pt;font-family:"Arial","sans-serif";color:black'><<...>> <<...>> </span><o:p></o:p></p></div></body></html>