<div dir="ltr"><div dir="ltr">
<p class="MsoNormal" style="margin:0in 0in 8pt;line-height:107%;font-size:11pt;font-family:"Calibri",sans-serif">Tim,</p><p class="MsoNormal" style="margin:0in 0in 8pt;line-height:107%;font-size:11pt;font-family:"Calibri",sans-serif">One problem we're trying to address is the potential for a
great number of “submarine voters”.<span> </span>Such members may remain inactive for extended periods of time and then
surface only to vote for or against something they suddenly are urged to
support or oppose, without being aware of the issues.<span> </span>This will skew and damage
the decision-making process.<span> <br></span></p><p class="MsoNormal" style="margin:0in 0in 8pt;line-height:107%;font-size:11pt;font-family:"Calibri",sans-serif">Another
problem, that I don't think has been mentioned before, is the reliability of
the CA/Browser Forum to adopt well-informed standards going forward. In other words, if something like I suggest happens, then I
can see Certificate Consumers leaving the Forum and unilaterally setting very separate and distinct rules. This will result in fragmentation, inconsistency,
and much more management overhead for CAs than the effort needed to keep track
of attendance, which is already being done by the Forum. (If you'd like, I can share with everyone the list of members who have not voted or attended meetings in over two years.) <br></p><p class="MsoNormal" style="margin:0in 0in 8pt;line-height:107%;font-size:11pt;font-family:"Calibri",sans-serif">Ben<br></p>
</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Jul 24, 2023 at 11:41 AM Tim Hollebeek <<a href="mailto:tim.hollebeek@digicert.com">tim.hollebeek@digicert.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg8579279525768193842">
<div style="overflow-wrap: break-word;" lang="EN-US">
<div class="m_8579279525768193842WordSection1">
<p class="MsoNormal">What is your argument in response to the point that any potential bad actors will be trivially able to satisfy the participation metrics?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I’m very worried we’ll end up doing a lot of management and tracking work, without actually solving the problem.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">-Tim<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div style="border-color:currentcolor currentcolor currentcolor blue;border-style:none none none solid;border-width:medium medium medium 1.5pt;padding:0in 0in 0in 4pt">
<div>
<div style="border-color:rgb(225,225,225) currentcolor currentcolor;border-style:solid none none;border-width:1pt medium medium;padding:3pt 0in 0in">
<p class="MsoNormal"><b>From:</b> Ben Wilson <<a href="mailto:bwilson@mozilla.com" target="_blank">bwilson@mozilla.com</a>> <br>
<b>Sent:</b> Monday, July 24, 2023 10:21 AM<br>
<b>To:</b> Ben Wilson <<a href="mailto:bwilson@mozilla.com" target="_blank">bwilson@mozilla.com</a>>; CA/B Forum Server Certificate WG Public Discussion List <<a href="mailto:servercert-wg@cabforum.org" target="_blank">servercert-wg@cabforum.org</a>><br>
<b>Cc:</b> Tim Hollebeek <<a href="mailto:tim.hollebeek@digicert.com" target="_blank">tim.hollebeek@digicert.com</a>><br>
<b>Subject:</b> Re: [Servercert-wg] Participation Proposal for Revised SCWG Charter<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal" style="margin-bottom:8pt;line-height:106%">All,<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:8pt;line-height:106%">I have thought a lot about this, including various other formulas (e.g. market share) to come up with something reasonable, but I've come back to attendance as the key metric that we need to
focus on. I just think that an attendance metric provides the only workable, measurable, and sound solution for determining the right to vote as a Certificate Consumer because it offers the following three elements:<u></u><u></u></p>
<ul style="margin-top:0in" type="disc">
<li class="MsoNormal" style="margin-bottom:8pt;line-height:106%">
Informed Decision-Making: Voting requires a comprehensive understanding of ongoing discussions and developments. Regular attendance provides members with the necessary context and knowledge to make well-informed decisions.<u></u><u></u></li><li class="MsoNormal">
Commitment: Attendance is a tangible and measurable representation of a member's commitment to the Server Certificate WG and its objectives. It demonstrates a genuine interest in contributing to the development and improvement of the requirements.<u></u><u></u></li><li class="MsoNormal">
Active Involvement: By prioritizing attendance, we encourage active involvement and discourage passive membership. Voting rights should be earned through consistent engagement, as this ensures that decisions are made by those who are genuinely invested in the
outcomes.<u></u><u></u></li></ul>
<div>
<p class="MsoNormal">At this point, I'm going to re-draft a proposal for a revision to the Server Certificate WG Charter and present it on the public list (because an eventual revision of the Charter will have to take place at the Forum level).<u></u><u></u></p>
</div>
<p class="MsoNormal" style="margin-bottom:8pt;line-height:106%">Thanks,<u></u><u></u></p>
<p class="MsoNormal" style="margin-bottom:8pt;line-height:106%">Ben<u></u><u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Thu, Jul 13, 2023 at 9:45 AM Ben Wilson via Servercert-wg <<a href="mailto:servercert-wg@cabforum.org" target="_blank">servercert-wg@cabforum.org</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-color:currentcolor currentcolor currentcolor rgb(204,204,204);border-style:none none none solid;border-width:medium medium medium 1pt;padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal">Thanks, Tim.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">All,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">I will look closer at the distribution and use of software for browsing the internet securely, instead of participation metrics. There is at least one source, StatCounter (<a href="https://gs.statcounter.com/browser-market-share" target="_blank">https://gs.statcounter.com/browser-market-share</a>),
that purports to measure use of browsing software, both globally and regionally. Would it be worthwhile to explore distribution by region and come up with a reasonable threshold? Can we rely on StatCounter, or should we look elsewhere?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Ben<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Wed, Jul 12, 2023 at 9:30 AM Tim Hollebeek via Servercert-wg <<a href="mailto:servercert-wg@cabforum.org" target="_blank">servercert-wg@cabforum.org</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-color:currentcolor currentcolor currentcolor rgb(204,204,204);border-style:none none none solid;border-width:medium medium medium 1pt;padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<div>
<p class="MsoNormal">I have a meaningful comment.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">I don’t want to ever have to discuss or judge whether someone’s comment is “meaningful” or not, and I don’t think incentivizing people to post more comments than they otherwise
would is helpful.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">I also think getting the chairs involved in any way in discussing whether a member representative did or did not have a medical condition during a particular time period is an extremely
bad idea.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">Given that the original issue was trying to determine whether a certificate consumer is in fact a legitimate player in the ecosystem or not, I would suggest that exploring metrics
like market share might be far more useful. Metrics like participation are rather intrusive and onerous, except to those who are trying to game them, and those trying to game such metrics will succeed with little or no effort.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">-Tim<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<div style="border-style:none none none solid;border-width:medium medium medium 1.5pt;padding:0in 0in 0in 4pt;border-color:currentcolor currentcolor currentcolor blue">
<div>
<div style="border-style:solid none none;border-width:1pt medium medium;padding:3pt 0in 0in;border-color:currentcolor">
<p class="MsoNormal"><b>From:</b> Servercert-wg <<a href="mailto:servercert-wg-bounces@cabforum.org" target="_blank">servercert-wg-bounces@cabforum.org</a>>
<b>On Behalf Of </b>Roman Fischer via Servercert-wg<br>
<b>Sent:</b> Wednesday, July 12, 2023 7:23 AM<br>
<b>To:</b> CA/B Forum Server Certificate WG Public Discussion List <<a href="mailto:servercert-wg@cabforum.org" target="_blank">servercert-wg@cabforum.org</a>><br>
<b>Subject:</b> Re: [Servercert-wg] Participation Proposal for Revised SCWG Charter<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal"><span lang="DE">Dear Ben,</span><u></u><u></u></p>
<p class="MsoNormal"><span lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal">Mandatory participation has in my experience never resulted in more or better discussions. People will dial into the telco and let it run in the background to “earn the credits”.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">Also, what would happen after the 90 day suspension? Would the organization be removed as a CA/B member?<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">Rgds<br>
Roman<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<div style="border-style:solid none none;border-width:1pt medium medium;padding:3pt 0in 0in;border-color:currentcolor">
<p class="MsoNormal"><b>From:</b> Servercert-wg <<a href="mailto:servercert-wg-bounces@cabforum.org" target="_blank">servercert-wg-bounces@cabforum.org</a>>
<b>On Behalf Of </b>Ben Wilson via Servercert-wg<br>
<b>Sent:</b> Freitag, 7. Juli 2023 21:59<br>
<b>To:</b> CA/B Forum Server Certificate WG Public Discussion List <<a href="mailto:servercert-wg@cabforum.org" target="_blank">servercert-wg@cabforum.org</a>><br>
<b>Subject:</b> [Servercert-wg] Participation Proposal for Revised SCWG Charter<u></u><u></u></p>
</div>
<p class="MsoNormal"><span lang="DE"> </span><u></u><u></u></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:13.5pt" lang="DE">All,</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span lang="DE"> </span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:13.5pt" lang="DE">Here is a draft participation proposal for the SCWG to consider and discuss for inclusion in a revised SCWG Charter.</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span lang="DE"> </span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-top:9pt;vertical-align:baseline">
<span style="font-size:12pt;color:rgb(17,17,17)" lang="DE">#. Participation Requirements to Maintain Voting Privileges</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black" lang="DE">(a) Attendance. The privilege to vote “Yes” or “No” on ballots is suspended for 90 days if a Voting Member fails to meet the
following attendance requirement over any 365-day period:</span><u></u><u></u></p>
<ul type="disc">
<li class="MsoNormal">
<span style="font-size:12pt;color:black" lang="DE">10% of SCWG meetings for Voting
</span><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE">Members located in time zones offset by UTC +5 through UTC +12</span><span lang="DE">
</span><u></u><u></u></li><li class="MsoNormal">
<span style="font-size:12pt;color:black" lang="DE">30% of SCWG meetings for Voting Members located in all other time zones</span><u></u><u></u></li></ul>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE">(b) Meaningful Comments. Posting a Meaningful Comment is an alternative means of meeting the attendance requirement in subsection
(a). A Voting Member can earn an attendance credit to make up for each missed meeting by posting a Meaningful Comment to the SCWG Public Mail List. Each Meaningful Comment is equal to attending one (1) meeting.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE">A Meaningful Comment is one that follows the Code of Conduct and provides relevant information to the SCWG, such as new information,
an insight, suggestion, or perspective related to the Scope of the SCWG, or that proposes an improvement to the TLS Baseline Requirements or EV Guidelines. It can also be something that responds to or builds on the comments of others in a meaningful way, or
that offers feedback, suggestions, or solutions to the issues or challenges raised by the topic of discussion.
</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE">A Meaningful Comment should be both r</span><span style="font-size:12pt" lang="DE">elevant (within the Scope of the SCWG
or <span style="color:rgb(17,17,17)">related to the discussion that is taking place on the mailing list) and
</span>well-supported (<span style="color:rgb(17,17,17)">clear reasons why the Voting Representative believes what they believe and supported by facts, data, or other information.)
</span></span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:rgb(17,17,17)" lang="DE">(c) A Voting Member that has failed to meet the attendance requirement in subsection (a) above is considered an "Inactive
Member". Any Member who believes that any other Member is an Inactive Member may report that Member on the Forum's Management List by providing specific information about that Member's non-participation, and the
</span><span style="font-size:12pt;color:black" lang="DE">SCWG Chair shall send written notice to the Inactive Member by email within seven (7) calendar days. The notice will include a reminder of the requirement to participate and inform the Inactive Member
of the consequences of not participating.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black" lang="DE">(d) Suspension of Voting Privileges. The Inactive Member's privilege to vote “Yes” or “No” on any ballot shall be temporarily
suspended for a period of 90 days from the date of the notice. During the suspension period, the Inactive Member may vote “Abstain” on ballots.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black" lang="DE">(e) Restoration of Voting Privilege. Voting privileges will be automatically restored to the Inactive Member upon attending
three consecutive meetings. The restoration of voting privileges will be effective on the next ballot that enters the voting period after the Inactive Member meets the reactivation criteria.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt" lang="DE"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt;color:black" lang="DE">(f) Exceptional Circumstances. In cases where an Inactive Member can demonstrate justifiable reasons for their inability to
participate, such as medical conditions or other extenuating circumstances affecting their Voting Representative(s), the SCWG Chair may review and consider reinstating voting privileges on a case-by-case basis.</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span lang="DE"> </span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:13.5pt" lang="DE">Thanks,</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span lang="DE"> </span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:13.5pt" lang="DE">Ben</span><u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
<p class="MsoNormal">_______________________________________________<br>
Servercert-wg mailing list<br>
<a href="mailto:Servercert-wg@cabforum.org" target="_blank">Servercert-wg@cabforum.org</a><br>
<a href="https://lists.cabforum.org/mailman/listinfo/servercert-wg" target="_blank">https://lists.cabforum.org/mailman/listinfo/servercert-wg</a><u></u><u></u></p>
</div>
</blockquote>
</div>
<p class="MsoNormal">_______________________________________________<br>
Servercert-wg mailing list<br>
<a href="mailto:Servercert-wg@cabforum.org" target="_blank">Servercert-wg@cabforum.org</a><br>
<a href="https://lists.cabforum.org/mailman/listinfo/servercert-wg" target="_blank">https://lists.cabforum.org/mailman/listinfo/servercert-wg</a><u></u><u></u></p>
</blockquote>
</div>
</div>
</div>
</div>
</div></blockquote></div></div>