<div dir="ltr"><div dir="ltr">Firmaprofesional votes YES on Ballot SC46: Sunset the CAA exception for DNS Operator<br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><font face="Tahoma, sans-serif"><br></font></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><font face="Tahoma, sans-serif"><br></font></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><font face="Tahoma, sans-serif"><b>Chema López</b></font></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><span style="font-family:Tahoma,sans-serif">Director Área Innovación, Cumplimiento y Tecnología</span><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><span style="font-family:Tahoma,sans-serif">+34 666 429 224</span><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><u style="font-family:Tahoma,sans-serif"> </u><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><img src="https://www.firmaprofesional.com/wp-content/uploads/2019/07/Firmaprofesional_Digital_Color_Pequeno.png"><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><span style="color:rgb(102,102,102);font-family:Tahoma,sans-serif"><b>Barcelona </b></span><span style="color:rgb(102,102,102);font-family:Tahoma,sans-serif">Av. Torre Blanca 57, </span><span style="color:rgb(102,102,102);font-family:Tahoma,sans-serif">Edif. Esadecreapolis, Local 3B6 - </span><span style="color:rgb(102,102,102);font-family:Tahoma,sans-serif">08173 Sant Cugat del Vallès | </span><span style="color:rgb(102,102,102);font-family:Tahoma,sans-serif">+34 934 774 245</span></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><font color="#666666" face="Tahoma, sans-serif"><b>Madrid </b>C/ Velázquez 59, 1º Ctro-Izda. - 28001 Madrid | +34 915 762 181</font></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><br></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><span style="font-family:Tahoma,sans-serif"><a href="http://www.firmaprofesional.com/" style="color:rgb(17,85,204)" target="_blank"><font color="#ff0000">www.firmaprofesional.com</font></a><b><font color="#ff0000"></font></b></span></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><b><span style="font-family:Tahoma,sans-serif;color:red"><br></span></b></p><p class="MsoNormal" style="margin-bottom:0.0001pt;line-height:normal"><i><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif;font-size:x-small">El contenido de este correo electrónico y de sus anexos es confidencial. Si usted recibe este mensaje por error, debe saber que está prohibido hacer uso, divulgación y/o copia del mismo. En tal caso le agradeceríamos que advierta de inmediato a su remitente y que proceda a destruir el mensaje.</span><br></i></p><p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;line-height:normal"><font color="#999999" face="tahoma, sans-serif" size="1"><i> </i></font></p><p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;line-height:normal"><i><font size="1"><font color="#999999" face="tahoma, sans-serif">Le informamos que, cumpliendo la normativa en materia de protección de datos, FIRMAPROFESIONAL tratará sus datos con la finalidad de garantizar las relaciones con la empresa, entidad u organización a la que usted representa o en la que trabaja y por el período que dure dicha relación. </font><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif">Podrá ejercer sus derechos de acceso, rectificación, supresión, limitación, portabilidad y oposición al tratamiento ante el Responsable: FIRMAPROFESIONAL, S.A., Av. Torre Blanca, 57, local 3B6 (Edificio Esadecreapolis), 08173 Sant Cugat del Vallès (Barcelona), o bien mediante correo electrónico a: </span><a href="mailto:rgpd@firmaprofesional.com" style="color:rgb(17,85,204);font-family:tahoma,sans-serif" target="_blank">rgpd@firmaprofesional.com</a><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif">, en cualquier caso adjuntando una copia de su D.N.I. o documento equivalente. Asimismo, podrá formular reclamaciones ante la Agencia Española de Protección de Datos. </span></font><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif;font-size:x-small">Para más información puede consultar nuestra </span><a href="https://www.firmaprofesional.com/esp/aviso-legal" style="color:rgb(17,85,204);font-family:tahoma,sans-serif;font-size:x-small" target="_blank">política de privacidad</a><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif;font-size:x-small">.</span></i></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 26 May 2021 at 16:00, Ryan Sleevi via Servercert-wg <<a href="mailto:servercert-wg@cabforum.org">servercert-wg@cabforum.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">This email begins the voting period for Ballot SC46: Sunset the CAA exception for DNS operator<br><br>Purpose of Ballot:<br><br>This Ballot addresses security issues with Section 3.2.2.8 regarding CAA checking.<br><br>Currently, Section 3.2.2.8 permits a CA to bypass CAA checking if the CA or an Affiliate of the CA is the DNS Operator. This term is referred to through RFC 7719, and involves a precise technical definition regarding how a zone's authoritative servers are configured and expressed (e.g. NS records). While this allows a CA to skip looking up the CAA record, it does not absolve them of the need to look up these other records on every issuance.<br><br>As practiced by CAs, this has clearly caused some confusion. For example, some CAs have incorrectly implemented policies that determine they're authoritative based on self-assertion that they are authoritative, which is not consistent with the current requirements.<br><br>To avoid these issues, this sunsets the CAA exception on 2021-07-01 for the DNS Operator, simplifying the requirements and reducing ambiguities for CAs performing validation.<br><br>The following motion has been proposed by Ryan Sleevi of Google and endorsed by Ben Wilson of Mozilla and Jacob Hoffman-Andrews of ISRG/Let's Encrypt.<br><br>It can be viewed on GitHub as <a href="https://github.com/cabforum/servercert/pull/271" target="_blank">https://github.com/cabforum/servercert/pull/271</a><br><br>-- MOTION BEGINS --<br><br>This ballot modifies the “Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates” (“Baseline Requirements”), based on Version 1.7.4:<br><br>MODIFY the Baseline Requirements as specified in the following Redline:<br><br><a href="https://github.com/cabforum/servercert/compare/47248d77d371356780b08cfa971b26d88d704ca8..6d34b1d51f645912d2237d5d4b46f4a49e8352ed" target="_blank">https://github.com/cabforum/servercert/compare/47248d77d371356780b08cfa971b26d88d704ca8..6d34b1d51f645912d2237d5d4b46f4a49e8352ed</a><br><br>-- MOTION ENDS --<br><br>This ballot proposes a Final Maintenance Guideline.<br><br>The procedure for approval of this ballot is as follows:<br><br>Discussion (7+ days)<br><br>Start Time: 2021-05-13 20:00:00 UTC<br>End Time: 2021-05-26 14:00:00 UTC<br><br>Vote for approval (7 days)<br><br>Start Time: 2021-05-26 14:00:00 UTC<br>End Time: TBD<br></div>
_______________________________________________<br>
Servercert-wg mailing list<br>
<a href="mailto:Servercert-wg@cabforum.org" target="_blank">Servercert-wg@cabforum.org</a><br>
<a href="https://lists.cabforum.org/mailman/listinfo/servercert-wg" rel="noreferrer" target="_blank">https://lists.cabforum.org/mailman/listinfo/servercert-wg</a><br>
</blockquote></div></div>