<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<font face="Cambria">Thanks, Ben.<br>
<br>
Assuming that any combination (of 1,2, 3) or no combination at all
would be acceptable, could we add something like "at least one or
any combination of following" so that it is explicitly clear?<br>
<br>
Thanks,<br>
M.D.<br>
<br>
</font><font face="Cambria"><span
style="mso-bookmark:_MailEndCompose">CAs MAY limit their
liability as described in Section 9.8 of the Baseline
Requirements except that a CA MAY NOT limit its liability to
Subscribers or Relying Parties for legally recognized and
provable claims to a monetary amount less than: <br>
<br>
</span></font><br>
<div class="moz-cite-prefix">On 7/26/2017 5:12 AM, Ben Wilson wrote:<br>
</div>
<blockquote
cite="mid:173c31aaf76343689082bdf0cb1765d0@EX2.corp.digicert.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
<style><!--
/* Font Definitions */
@font-face
{font-family:"Tms Rmn";
panose-1:2 2 6 3 4 5 5 2 3 4;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
{font-family:Cambria;
panose-1:2 4 5 3 5 4 6 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";
color:black;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;
color:black;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
span.EmailStyle20
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle22
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle23
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle24
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle25
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle26
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle27
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle29
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle30
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:1153714135;
mso-list-type:hybrid;
mso-list-template-ids:1926148482 -2000241400 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
{mso-level-text:"\(%1\)";
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level2
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level3
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l0:level4
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level5
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level6
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l0:level7
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level8
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level9
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l1
{mso-list-id:1469737925;
mso-list-type:hybrid;
mso-list-template-ids:1077960606 910054074 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l1:level1
{mso-level-start-at:2;
mso-level-text:"\(%1\)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:.8in;
text-indent:-.25in;}
@list l1:level2
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:1.3in;
text-indent:-.25in;}
@list l1:level3
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:1.8in;
text-indent:-9.0pt;}
@list l1:level4
{mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:2.3in;
text-indent:-.25in;}
@list l1:level5
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:2.8in;
text-indent:-.25in;}
@list l1:level6
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:3.3in;
text-indent:-9.0pt;}
@list l1:level7
{mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:3.8in;
text-indent:-.25in;}
@list l1:level8
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:4.3in;
text-indent:-.25in;}
@list l1:level9
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:4.8in;
text-indent:-9.0pt;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><a moz-do-not-send="true"
name="_MailEndCompose"><span style="color:windowtext">Rather
than tack on these two additional limits, what if it were
simplified to read:<o:p></o:p></span></a></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><span
style="color:windowtext"><o:p> </o:p></span></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">CAs
MAY limit their liability as described in Section 9.8 of the
Baseline Requirements except that a CA MAY NOT limit its
liability to Subscribers or Relying Parties for legally
recognized and provable claims to a monetary amount less
than: </span><span style="mso-bookmark:_MailEndCompose"><span
style="font-size:10.0pt;font-family:"Times New
Roman",serif;color:windowtext"><o:p></o:p></span></span></p>
<p class="MsoNormal"
style="margin-top:6.8pt;text-align:justify;text-autospace:ideograph-other"><span
style="mso-bookmark:_MailEndCompose"> <u>(1)</u>
two thousand US dollars per Subscriber or Relying Party per
EV Certificate<u>;<o:p></o:p></u></span></p>
<p class="MsoNormal"
style="margin-top:6.8pt;text-align:justify;text-autospace:ideograph-other"><span
style="mso-bookmark:_MailEndCompose"><u>
(2) one hundred thousand US dollars – aggregated across
all claims, Subscribers, and Relying Parties – per EV
Certificate; and/or<o:p></o:p></u></span></p>
<p class="MsoNormal"
style="margin-top:6.8pt;text-align:justify;text-autospace:ideograph-other"><span
style="mso-bookmark:_MailEndCompose"><u>
(3) five million US dollars – aggregated across all
claims, Subscribers, and Relying Parties – for all EV
Certificates issued by the CA during any continuous
12-month period. <o:p></o:p></u></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><u><o:p><span
style="text-decoration:none"> </span></o:p></u></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><u>These
limitations are notwithstanding anything in the Baseline
Requirements purportedly to the contrary.<o:p></o:p></u></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">A
CA's indemnification obligations and a Root CA’s obligations
with respect to subordinate CAs are set forth in Section 9.9
of the Baseline Requirements.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><span
style="color:windowtext"><o:p> </o:p></span></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><span
style="color:windowtext"><o:p> </o:p></span></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><span
style="color:windowtext"><o:p> </o:p></span></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><span
style="color:windowtext"><o:p> </o:p></span></span></p>
<span style="mso-bookmark:_MailEndCompose"></span>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Public
[<a class="moz-txt-link-freetext" href="mailto:public-bounces@cabforum.org">mailto:public-bounces@cabforum.org</a>] <b>On Behalf Of </b>Ben
Wilson via Public<br>
<b>Sent:</b> Tuesday, July 25, 2017 6:37 PM<br>
<b>To:</b> Moudrick M. Dadashov <a class="moz-txt-link-rfc2396E" href="mailto:md@ssc.lt"><md@ssc.lt></a>;
CA/Browser Forum Public Discussion List
<a class="moz-txt-link-rfc2396E" href="mailto:public@cabforum.org"><public@cabforum.org></a><br>
<b>Subject:</b> Re: [cabfpub] Pre-Ballot 209 EV
Liability<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Would this work?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Notwithstanding the foregoing, a CA MAY
limit its liability to Subscribers or Relying Parties for
legally recognized and provable claims to <u>not less than</u>:
(1) one hundred thousand US dollars – aggregated across all
claims, Subscribers, and Relying Parties – per EV Certificate;
and<u>/or</u> (2) five million US dollars – aggregated across
all claims, Subscribers, and Relying Parties – for all EV
Certificates issued by the CA during any continuous 12-month
period. These limitations are notwithstanding anything in the
Baseline Requirements purportedly to the contrary.<o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Moudrick M. Dadashov [<a
moz-do-not-send="true" href="mailto:md@ssc.lt">mailto:md@ssc.lt</a>]
<br>
<b>Sent:</b> Tuesday, July 25, 2017 5:48 PM<br>
<b>To:</b> Ben Wilson <<a moz-do-not-send="true"
href="mailto:ben.wilson@digicert.com">ben.wilson@digicert.com</a>>;
CA/Browser Forum Public Discussion List <<a
moz-do-not-send="true"
href="mailto:public@cabforum.org">public@cabforum.org</a>><br>
<b>Subject:</b> Re: [cabfpub] Pre-Ballot 209 EV
Liability<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span
style="font-family:"Cambria",serif">Would you mind
to show how it would sound now? :)</span><br>
<br>
Thanks,<br>
M.D.<o:p></o:p></p>
<div>
<p class="MsoNormal">On 7/26/2017 2:14 AM, Ben Wilson wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="color:windowtext">And it
should be an “and” or a “but”, but rephrased nevertheless.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:2.0pt"><b><span
style="font-family:"Arial",sans-serif;color:#0174C3">Ben
Wilson, JD, CISA, CISSP</span></b><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">VP
Compliance</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">+1
801 701 9678</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"><img
style="width:1.3875in;height:.3in" id="_x0000_i1025"
src="cid:part5.6BC55D66.CB9A7687@ssc.lt" height="29"
border="0" width="133"></span><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Ben Wilson <br>
<b>Sent:</b> Tuesday, July 25, 2017 5:11 PM<br>
<b>To:</b> Ben Wilson <a moz-do-not-send="true"
href="mailto:ben.wilson@digicert.com"><ben.wilson@digicert.com></a>;
CA/Browser Forum Public Discussion List <a
moz-do-not-send="true"
href="mailto:public@cabforum.org"><public@cabforum.org></a>;
Moudrick M. Dadashov <a moz-do-not-send="true"
href="mailto:md@ssc.lt"><md@ssc.lt></a><br>
<b>Subject:</b> RE: [cabfpub] Pre-Ballot 209 EV
Liability</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext">Never mind
– I think I now see your point. Not “up to” it needs to
be “not less than $5 million.” Would that make it
clearer?</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:2.0pt"><b><span
style="font-family:"Arial",sans-serif;color:#0174C3">Ben
Wilson, JD, CISA, CISSP</span></b><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">VP
Compliance</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">+1
801 701 9678</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"><img
style="width:1.3833in;height:.3041in"
id="_x0000_i1026"
src="cid:part9.224845E7.D7478B5A@ssc.lt" height="29"
border="0" width="133"></span><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Public [<a
moz-do-not-send="true"
href="mailto:public-bounces@cabforum.org">mailto:public-bounces@cabforum.org</a>]
<b>On Behalf Of </b>Ben Wilson via Public<br>
<b>Sent:</b> Tuesday, July 25, 2017 5:10 PM<br>
<b>To:</b> Moudrick M. Dadashov <<a
moz-do-not-send="true" href="mailto:md@ssc.lt">md@ssc.lt</a>>;
CA/Browser Forum Public Discussion List <<a
moz-do-not-send="true"
href="mailto:public@cabforum.org">public@cabforum.org</a>><br>
<b>Subject:</b> Re: [cabfpub] Pre-Ballot 209 EV
Liability</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext">It’s
permissive – a CA MAY limit its liability. Maybe we
should say “up to $5 million”. Then, would that be
clearer - that it can be less than $5 million?</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:2.0pt"><b><span
style="font-family:"Arial",sans-serif;color:#0174C3">Ben
Wilson, JD, CISA, CISSP</span></b><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">VP
Compliance</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">+1
801 701 9678</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"><img
style="width:1.3875in;height:.3in" id="_x0000_i1027"
src="cid:part13.64D06DC1.ED2388A5@ssc.lt" height="29"
border="0" width="133"></span><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Moudrick M. Dadashov [<a
moz-do-not-send="true" href="mailto:md@ssc.lt">mailto:md@ssc.lt</a>]
<br>
<b>Sent:</b> Tuesday, July 25, 2017 4:35 PM<br>
<b>To:</b> Ben Wilson <<a moz-do-not-send="true"
href="mailto:ben.wilson@digicert.com">ben.wilson@digicert.com</a>>;
CA/Browser Forum Public Discussion List <<a
moz-do-not-send="true"
href="mailto:public@cabforum.org">public@cabforum.org</a>><br>
<b>Subject:</b> Re: [cabfpub] Pre-Ballot 209 EV
Liability</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span
style="font-family:"Cambria",serif">With "and" I
don't see its optional.<br>
<br>
Again, just to understand the model: is per EV certificate
amount is NOT fixed whereas 12-month continuous amount is
the only option ($5 mln.)?<br>
<br>
Thanks,<br>
M.D. </span><o:p></o:p></p>
<div>
<p class="MsoNormal">On 7/26/2017 1:28 AM, Ben Wilson wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="color:windowtext">All of
the provisions would provide optional caps that CAs
could place on EV liability. The 12-month $5 Million
cap allows a CA to cap all EV liability to all those EV
certificates issued within a single year. </span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:2.0pt"><b><span
style="font-family:"Arial",sans-serif;color:#0174C3">Ben
Wilson, JD, CISA, CISSP</span></b><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">VP
Compliance</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">+1
801 701 9678</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"><img
style="width:1.3833in;height:.3041in"
id="_x0000_i1028"
src="cid:part17.3FA1B138.1548C62C@ssc.lt"
height="29" border="0" width="133"></span><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Moudrick M. Dadashov [<a
moz-do-not-send="true" href="mailto:md@ssc.lt">mailto:md@ssc.lt</a>]
<br>
<b>Sent:</b> Tuesday, July 25, 2017 4:24 PM<br>
<b>To:</b> Ben Wilson <a moz-do-not-send="true"
href="mailto:ben.wilson@digicert.com"><ben.wilson@digicert.com></a>;
CA/Browser Forum Public Discussion List <a
moz-do-not-send="true"
href="mailto:public@cabforum.org"><public@cabforum.org></a><br>
<b>Subject:</b> Re: [cabfpub] Pre-Ballot 209 EV
Liability</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span
style="font-family:"Cambria",serif">Ok. Do I
understand the intention correctly: to have a "floating
liability" amount per EV certificate and "fixed
liability" amount per continuous 12-month period?<br>
<br>
Thanks,<br>
M.D.</span><o:p></o:p></p>
<div>
<p class="MsoNormal">On 7/26/2017 1:10 AM, Ben Wilson
wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="color:windowtext">No.
Because they MAY do both. An “or” would mean that
they have to choose between the two, which isn’t the
intent.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:2.0pt"><b><span
style="font-family:"Arial",sans-serif;color:#0174C3">Ben
Wilson, JD, CISA, CISSP</span></b><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">VP
Compliance</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">+1
801 701 9678</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:windowtext"><img
style="width:1.3875in;height:.3in"
id="_x0000_i1029"
src="cid:part21.B416F02A.3C6A984D@ssc.lt"
height="29" border="0" width="133"></span><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:windowtext"> </span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Moudrick M. Dadashov [<a
moz-do-not-send="true" href="mailto:md@ssc.lt">mailto:md@ssc.lt</a>]
<br>
<b>Sent:</b> Tuesday, July 25, 2017 4:09 PM<br>
<b>To:</b> Ben Wilson <a moz-do-not-send="true"
href="mailto:ben.wilson@digicert.com"><ben.wilson@digicert.com></a>;
CA/Browser Forum Public Discussion List <a
moz-do-not-send="true"
href="mailto:public@cabforum.org"><public@cabforum.org></a><br>
<b>Subject:</b> Re: [cabfpub] Pre-Ballot 209 EV
Liability</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span
style="font-family:"Cambria",serif">Hi Ben,<br>
<br>
could it be "or" between (1) and (2)?<br>
<br>
Thanks,<br>
M.D.</span><o:p></o:p></p>
<div>
<p class="MsoNormal">On 7/25/2017 11:59 PM, Ben Wilson
via Public wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">Here is another pre-ballot for
discussion.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><b>Ballot 209 - EV Liability</b><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">In Section 18 of the EV Guidelines,
add the following sentences to the end of the first
paragraph:<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Notwithstanding the foregoing, a CA
MAY limit its liability to Subscribers or Relying
Parties for legally recognized and provable claims to:
(1) one hundred thousand US dollars – aggregated
across all claims, Subscribers, and Relying Parties –
per EV Certificate; and (2) five million US dollars –
aggregated across all claims, Subscribers, and Relying
Parties – for all EV Certificates issued by the CA
during any continuous 12-month period. These
limitations are notwithstanding anything in the
Baseline Requirements purportedly to the contrary.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Such that Section 18 of the EV
Guidelines would read:<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">CAs MAY limit their liability as
described in Section 9.8 of the Baseline Requirements
except that a CA MAY NOT limit its liability to
Subscribers or Relying Parties for legally recognized
and provable claims to a monetary amount less than two
thousand US dollars per Subscriber or Relying Party
per EV Certificate. <u>Notwithstanding the foregoing,
a CA MAY limit its liability to Subscribers or
Relying Parties for legally recognized and provable
claims to: (1) one hundred thousand US dollars –
aggregated across all claims, Subscribers, and
Relying Parties – per EV Certificate; and (2) five
million US dollars – aggregated across all claims,
Subscribers, and Relying Parties – for all EV
Certificates issued by the CA during any continuous
12-month period. These limitations are
notwithstanding anything in the Baseline
Requirements purportedly to the contrary</u>.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">A CA's indemnification obligations
and a Root CA’s obligations with respect to
subordinate CAs are set forth in Section 9.9 of the
Baseline Requirements.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><b><span
style="font-family:"Arial",sans-serif;color:#0174C3">Ben
Wilson, JD, CISA, CISSP</span></b><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">VP
Compliance</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:2.0pt"><span
style="font-family:"Arial",sans-serif;color:#686869">+1
801 701 9678</span><o:p></o:p></p>
<p class="MsoNormal"><img
style="width:1.3833in;height:.3041in"
id="Picture_x0020_1"
src="cid:part25.05A1AD9B.896FCB8E@ssc.lt"
height="29" border="0" width="133"><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
<br>
<br>
<o:p></o:p></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>Public mailing list<o:p></o:p></pre>
<pre><a moz-do-not-send="true" href="mailto:Public@cabforum.org">Public@cabforum.org</a><o:p></o:p></pre>
<pre><a moz-do-not-send="true" href="https://cabforum.org/mailman/listinfo/public">https://cabforum.org/mailman/listinfo/public</a><o:p></o:p></pre>
</blockquote>
<p class="MsoNormal"> <o:p></o:p></p>
</blockquote>
<p class="MsoNormal"> <o:p></o:p></p>
</blockquote>
<p class="MsoNormal"> <o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</blockquote>
<br>
</body>
</html>