<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">It’s important to apply the requirements objectively. We can’t apply the rules one way for one applicant because we want X result, and then apply the rules a different way for another applicant because we want Y result. People who care about antitrust issues and competition law might be concerned about the inequitable and inconsistent application of rules to achieve a certain result.<br class=""><div class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div class="" style="color: rgb(0, 0, 0); font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-position: normal; font-variant-caps: normal; font-variant-numeric: normal; font-variant-alternates: normal; font-variant-east-asian: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; font-family: Helvetica; line-height: normal;"><div style="margin: 0px; font-size: 14px; line-height: normal; -webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: initial;" class=""><div style="margin: 0px; font-stretch: normal; line-height: normal;" class=""><br class=""></div><div style="margin: 0px; font-stretch: normal; line-height: normal;" class="">Best regards,</div><div style="margin: 0px; font-stretch: normal; line-height: normal; min-height: 17px;" class=""><br class=""></div><div style="margin: 0px; font-stretch: normal; line-height: normal;" class="">Virginia Fournier</div><div style="margin: 0px; font-stretch: normal; line-height: normal;" class="">Senior Standards Counsel</div><div style="margin: 0px; font-stretch: normal; line-height: normal;" class=""><span style="color: rgb(113, 113, 113);" class=""></span> Apple Inc.</div><div style="margin: 0px; font-stretch: normal; line-height: normal;" class=""><span style="font-stretch: normal; line-height: normal; font-family: "Apple SD Gothic Neo";" class="">☏</span><span class="Apple-converted-space"> </span>669-227-9595</div><div style="margin: 0px; font-stretch: normal; line-height: normal; color: rgb(4, 51, 255);" class=""><span style="font-stretch: normal; line-height: normal; font-family: "Zapf Dingbats"; color: rgb(0, 0, 0);" class="">✉︎</span><span style="color: rgb(0, 0, 0);" class=""> <a href="mailto:vmf@apple.com" class="">vmf@apple.com</a></span></div><div style="margin: 0px; font-stretch: normal; line-height: normal; color: rgb(87, 157, 255); min-height: 17px;" class=""><br class=""></div></div></div></div></div></div></div></div><br class="Apple-interchange-newline">
</div>
<div><br class=""><div class="">On Jun 28, 2018, at 8:50 AM, <a href="mailto:public-request@cabforum.org" class="">public-request@cabforum.org</a> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="">Send Public mailing list submissions to<br class=""><span class="Apple-tab-span" style="white-space:pre"> </span><a href="mailto:public@cabforum.org" class="">public@cabforum.org</a><br class=""><br class="">To subscribe or unsubscribe via the World Wide Web, visit<br class=""><span class="Apple-tab-span" style="white-space:pre"> </span>https://cabforum.org/mailman/listinfo/public<br class="">or, via email, send a message with subject or body 'help' to<br class=""><span class="Apple-tab-span" style="white-space:pre"> </span>public-request@cabforum.org<br class=""><br class="">You can reach the person managing the list at<br class=""><span class="Apple-tab-span" style="white-space:pre"> </span>public-owner@cabforum.org<br class=""><br class="">When replying, please edit your Subject line so it is more specific<br class="">than "Re: Contents of Public digest..."<br class=""><br class=""><br class="">Today's Topics:<br class=""><br class=""> 1. Re: Membership Application of Sony (Phillip)<br class=""><br class=""><br class="">----------------------------------------------------------------------<br class=""><br class="">Message: 1<br class="">Date: Thu, 28 Jun 2018 11:50:13 -0400<br class="">From: "Phillip" <philliph@comodo.com><br class="">To: "'Tim Hollebeek'" <tim.hollebeek@digicert.com>, "'CA/Browser Forum<br class=""><span class="Apple-tab-span" style="white-space:pre"> </span>Public Discussion List'" <public@cabforum.org>, "'Kirk Hall'"<br class=""><span class="Apple-tab-span" style="white-space:pre"> </span><Kirk.Hall@entrustdatacard.com><br class="">Subject: Re: [cabfpub] Membership Application of Sony<br class="">Message-ID: <016901d40ef7$b4af10f0$1e0d32d0$@comodo.com><br class="">Content-Type: text/plain; charset="utf-8"<br class=""><br class="">Given that this is the first outing for this set of rules, I think it is important to bear in mind the ultimate objective rather than the rules we only just created. That does not mean breaking the rules but we should be prepared to change them if needed. So rather than asking if Sony?s application meets the requirements, I look for how they can meet those requirements. <br class=""><br class=""><br class=""><br class="">That does of course leave open the question of what the ultimate objective is and this will of course differ from member to member. But whatever your objective might happen to be, I suggest that you consider the fact that Sony controls a vast number of devices that are used by consumers every day. Sony was Apple before Apple was Apple and Microsoft before Microsoft was Microsoft.<br class=""><br class=""><br class=""><br class="">One objective CABForum has set itself to meet is to encourage use of best practices in management of Trust stores. The ability to update code stores is clearly critical to that objective. But what if people come to CABForum having decided they want to update their trust stores and are looking for best practices on how to do that?<br class=""><br class=""><br class=""><br class=""><br class=""><br class=""><br class=""><br class="">From: Public <public-bounces@cabforum.org> On Behalf Of Tim Hollebeek via Public<br class="">Sent: Thursday, June 28, 2018 8:14 AM<br class="">To: Kirk Hall <Kirk.Hall@entrustdatacard.com>; CA/Browser Forum Public Discussion List <public@cabforum.org><br class="">Subject: Re: [cabfpub] Membership Application of Sony<br class=""><br class=""><br class=""><br class="">Right, this was the original intent.<br class=""><br class=""><br class=""><br class="">The CABF membership is the union of all CWG memberships. You can?t just join CABF.<br class=""><br class=""><br class=""><br class="">Since there?s only one CWG right now, the SCWG, the membership rules are basically the same as they are now. But as we add WGs, the membership rules expand by exactly the marginal scope of the new WG.<br class=""><br class=""><br class=""><br class="">-Tim<br class=""><br class=""><br class=""><br class="">From: Public [mailto:public-bounces@cabforum.org] On Behalf Of Kirk Hall via Public<br class="">Sent: Wednesday, June 27, 2018 8:21 PM<br class="">To: CA/Browser Forum Public Discussion List <public@cabforum.org <mailto:public@cabforum.org> ><br class="">Subject: Re: [cabfpub] Membership Application of Sony<br class=""><br class=""><br class=""><br class="">Mike ? see my later message on this subject. Under the new governance structure, any new member must ?qualify? twice ? once based on the Forum membership requirement (which for browsers is rather vague), and again for whatever Working Group(s) the applicant wants to participate in (there must be at least one).<br class=""><br class=""><br class=""><br class="">Here the Forum level requirement for a browser is:<br class=""><br class=""><br class=""><br class="">(3) Certificate Consumer: The member organization produces a software product, such as a browser, intended for use by the general public for relying upon certificates and is a member of a CWG [Chartered Working Group, such as the new Server Certificate Working Group].<br class=""><br class=""><br class=""><br class="">In this case, the requirements for being a browser member of the Server Certificate Working Group are much more specific than the requirements for being a browser member of the Forum itself. <br class=""><br class=""><br class=""><br class="">(3) A Certificate Consumer can participate in this Working Group if it produces a software product intended for use by the general public for browsing the Web securely.<br class=""><br class=""><br class=""><br class="">I think that pattern will be repeated as other new WGs are created. In the end, it will be the WG requirements that will limit how many browsers (Certificate Consumers) get to join.<br class=""><br class=""><br class=""><br class="">From: Mike Reilly (GRC) [mailto:Mike.Reilly@microsoft.com] <br class="">Sent: Wednesday, June 27, 2018 4:21 PM<br class="">To: Kirk Hall <Kirk.Hall@entrustdatacard.com <mailto:Kirk.Hall@entrustdatacard.com> >; CA/Browser Forum Public Discussion List <public@cabforum.org <mailto:public@cabforum.org> ><br class="">Subject: RE: [cabfpub] [EXTERNAL]Re: Membership Application of Sony<br class=""><br class=""><br class=""><br class="">It seems like we could eventually end up with a very large number of ?Certificate Consumers? as members of the CABF in pretty short order based on the requirements to qualify for Forum membership. Would every ?Smart Device? manufacturer qualify? Not sure what that would mean for the effectiveness of the forum and WGs going forward. Talk to folks on the call tomorrow. Thanks, Mike<br class=""><br class=""><br class=""><br class="">From: Public <public-bounces@cabforum.org <mailto:public-bounces@cabforum.org> > On Behalf Of Kirk Hall via Public<br class="">Sent: Wednesday, June 27, 2018 10:08 AM<br class="">To: CA/Browser Forum Public Discussion List <public@cabforum.org <mailto:public@cabforum.org> ><br class="">Subject: Re: [cabfpub] [EXTERNAL]Re: Membership Application of Sony<br class=""><br class=""><br class=""><br class="">That is my assumption. First, they want to understand what our Bylaws require for participation as a Certificate Consumer, and whether they would qualify. That?s what tomorrow?s discussion will be about.<br class=""><br class=""><br class=""><br class="">From: Ryan Sleevi [mailto:sleevi@google.com] <br class="">Sent: Wednesday, June 27, 2018 10:05 AM<br class="">To: Kirk Hall <Kirk.Hall@entrustdatacard.com <mailto:Kirk.Hall@entrustdatacard.com> >; CABFPub <public@cabforum.org <mailto:public@cabforum.org> ><br class="">Subject: [EXTERNAL]Re: [cabfpub] Membership Application of Sony<br class=""><br class=""><br class=""><br class="">Kirk,<br class=""><br class=""><br class=""><br class="">Can you clarify - are they applying for membership of a CWG as well?<br class=""><br class=""><br class=""><br class="">On Wed, Jun 27, 2018 at 12:58 PM Kirk Hall via Public <public@cabforum.org <mailto:public@cabforum.org> > wrote:<br class=""><br class="">Sony has contacted the Forum about joining as a browser member. Sony has asked a question about the membership requirements for browsers in our Bylaws. We will discuss on our call tomorrow.<br class=""><br class=""><br class=""><br class="">To assist in our discussion tomorrow, I am sending out the relevant portions of our Bylaws on browser membership requirements along with the existing discussion with Sony. (Browser is now called Certificate Consumer in our most recent update to the Bylaws.)<br class=""><br class=""><br class=""><br class="">Bylaw 2.1 Qualifying for Forum Membership<br class=""><br class=""><br class=""><br class="">(a) All Forum members must *** meet at least one of the following criteria: ***<br class=""><br class=""><br class=""><br class="">(3) Certificate Consumer: The member organization produces a software product, such as a browser, intended for use by the general public for relying upon certificates and is a member of a CWG [Chartered Working Group, such as the new Server Certificate Working Group].<br class=""><br class=""><br class=""><br class="">(b) Applicants should supply the following information:<br class=""><br class="">(1) Confirmation that the applicant satisfies at least one of the membership criteria (and if it satisfies more than one, indication of the single category under which the applicant wishes to apply).<br class=""><br class="">(2) The organization name, as you wish it to appear on the Forum Web site and in official Forum documents.<br class=""><br class="">(3) URL of the applicant's main Web site.<br class=""><br class="">(4) Names and email addresses of employees who will participate in the Forum mail list.<br class=""><br class="">(5) Emergency contact information for security issues related to certificate trust.<br class=""><br class=""><br class=""><br class=""><br class=""><br class="">From: Questions [mailto:questions-bounces@cabforum.org <mailto:questions-bounces@cabforum.org> ] On Behalf Of Adam.Goldberg@sony.com <mailto:Adam.Goldberg@sony.com> <br class="">Sent: Thursday, June 21, 2018 8:59 AM<br class="">To: dean.coclin@digicert.com <mailto:dean.coclin@digicert.com> <br class="">Cc: questions@cabforum.org <mailto:questions@cabforum.org> <br class="">Subject: [EXTERNAL]Re: [cabfquest] Membership Application of Sony<br class=""><br class=""><br class=""><br class="">Hi Dean,<br class=""><br class=""><br class=""><br class="">Thanks for the quick reply. Limiting the discussion to televisions (the question at-hand), they?re based on Android TV then with Sony software on top. So, ?does Sony make the software? is yes and no.<br class=""><br class=""><br class=""><br class="">But we *do* write the software that does the cryptographic signature validation.<br class=""><br class=""><br class=""><br class="">I hope that answers your question.<br class=""><br class=""><br class=""><br class="">Adam<br class=""><br class=""><br class=""><br class="">Adam Goldberg<br class=""><br class="">Director, Technical Standards<br class=""><br class="">Technology Standards Office<br class=""><br class="">Sony Electronics, Inc.<br class=""><br class="">202-601-4130 (tel)<br class=""><br class="">571-363-9778 (mobile)<br class=""><br class=""><br class=""><br class="">From: Dean Coclin [mailto:dean.coclin@digicert.com] <br class="">Sent: Thursday, June 21, 2018 11:44 AM<br class="">To: Goldberg, Adam <Adam.Goldberg@sony.com <mailto:Adam.Goldberg@sony.com> ><br class="">Cc: questions@cabforum.org <mailto:questions@cabforum.org> <br class="">Subject: RE: Membership Application of Sony<br class=""><br class=""><br class=""><br class="">Hello Adam,<br class=""><br class=""><br class=""><br class="">Thank you for contacting the CA/B Forum. This question will have to be discussed by the members. I will ask the chair to put it on the agenda for the next meeting which is in 1 week.<br class=""><br class="">Perhaps you can help clarify by stating whether or not Sony makes the underlying software that runs in the hardware device made by Sony?<br class=""><br class=""><br class=""><br class="">Best regards,<br class=""><br class=""><br class=""><br class="">Dean Coclin<br class=""><br class="">for the CA/B Forum<br class=""><br class=""><br class=""><br class="">From: Questions [mailto:questions-bounces@cabforum.org] On Behalf Of Adam.Goldberg@sony.com <mailto:Adam.Goldberg@sony.com> <br class="">Sent: Thursday, June 21, 2018 8:10 AM<br class="">To: questions@cabforum.org <mailto:questions@cabforum.org> <br class="">Subject: [cabfquest] Membership Application of Sony<br class=""><br class=""><br class=""><br class="">Hi,<br class=""><br class=""><br class=""><br class="">Can you please describe the bylaw requirement of ?produces a software product, such as a browser, intended for use by the general public for relying upon certificates and is a member of a CWG??<br class=""><br class=""><br class=""><br class="">If we produce a hardware product which includes software which relies upon (public root) certificates, does that meet the definition of ?produces a software product??<br class=""><br class=""><br class=""><br class="">If our situation fits within the definition of a ?Certificate Consumer organization?, I will follow-up with a complete application (following legal review of the IPR documents).<br class=""><br class=""><br class=""><br class="">Thanks.<br class=""><br class=""><br class=""><br class=""><br class=""><br class=""><br class=""><br class="">Adam Goldberg<br class=""><br class="">Director, Technical Standards<br class=""><br class="">Technology Standards Office<br class=""><br class="">Sony Electronics, Inc.<br class=""><br class="">202-601-4130 (tel)<br class=""><br class="">571-363-9778 (mobile)<br class=""><br class=""><br class=""><br class="">_______________________________________________<br class="">Public mailing list<br class="">Public@cabforum.org <mailto:Public@cabforum.org> <br class="">https://cabforum.org/mailman/listinfo/public<br class=""><br class="">-------------- next part --------------<br class="">An HTML attachment was scrubbed...<br class="">URL: <http://cabforum.org/pipermail/public/attachments/20180628/3cba688a/attachment.html><br class=""><br class="">------------------------------<br class=""><br class="">Subject: Digest Footer<br class=""><br class="">_______________________________________________<br class="">Public mailing list<br class="">Public@cabforum.org<br class="">https://cabforum.org/mailman/listinfo/public<br class=""><br class=""><br class="">------------------------------<br class=""><br class="">End of Public Digest, Vol 74, Issue 53<br class="">**************************************<br class=""></div></div></div><br class=""></body></html>