<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
HARICA votes "no" to ballot SC-74.<br>
<br>
Dimitris.<br>
<br>
<div class="moz-cite-prefix">On 5/5/2024 12:06 μ.μ., Dimitris
Zacharopoulos (HARICA) wrote:<br>
</div>
<blockquote type="cite"
cite="mid:029e9f26-167c-4e75-a7af-b4ea0ceeef52@harica.gr">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
HARICA votes "yes" to ballot SC-74.<br>
<br>
<div class="moz-cite-prefix">On 5/5/2024 11:24 π.μ., Dimitris
Zacharopoulos (HARICA) via Servercert-wg wrote:<br>
</div>
<blockquote type="cite"
cite="mid:0100018f47dad47f-921f8eb2-1a17-4b7c-8616-cc734a9cd1c5-000000@email.amazonses.com">
<meta http-equiv="content-type"
content="text/html; charset=UTF-8">
Voting begins for ballot SC-74.<br>
<h1 class="break-text" id="bkmrk-page-title">SC-74 - Clarify
CP/CPS structure according to RFC 3647</h1>
<h2 id="bkmrk-summary">Summary</h2>
<p id="bkmrk-the-tls-baseline-req">The TLS Baseline Requirements
require in section 2.2 that:</p>
<p id="bkmrk-%22the-certificate-pol"><em>"The Certificate Policy
and/or Certification Practice Statement MUST be structured
in accordance with RFC 3647 and MUST include all material
required by RFC 3647."</em></p>
<p id="bkmrk-the-intent-of-this-l">The intent of this language
was to ensure that all CAs' CP and/or CPS documents contain a
similar structure, making it easier to review and compare
against the BRs. However, there was some ambiguity as to the
actual structure that CAs should follow. After several
discussions in the <a
href="https://lists.cabforum.org/pipermail/servercert-wg/2023-November/004070.html"
moz-do-not-send="true">SCWG Public Mailing List</a> and F2F
meetings, it was agreed that more clarity should be added to
the existing requirement, pointing to the outline described in
section 6 of RFC 3647.</p>
<p id="bkmrk-the-following-motion">The following motion has been
proposed by Dimitris Zacharopoulos (HARICA) and endorsed by
Aaron Poulsen (Amazon) and Tim Hollebeek (Digicert). <br>
</p>
<p id="bkmrk-you-can-view-and-com">You can view the github pull
request representing this ballot <a
href="https://github.com/cabforum/servercert/pull/503"
moz-do-not-send="true">here</a>. <br>
</p>
<h2 id="bkmrk-motion-begins">Motion Begins</h2>
<p id="bkmrk-modify-the-%22baseline">MODIFY the "Baseline
Requirements for the Issuance and Management of
Publicly-Trusted TLS Server Certificates" based on Version
2.0.4 as specified in the following redline:<br>
</p>
<ul id="bkmrk-https%3A%2F%2Fgithub.com%2Fc">
<li class="null"><a class="moz-txt-link-freetext"
href="https://github.com/cabforum/servercert/compare/c4a34fe2292022e0a04ba66b5a85df75907ac2a2...f6a90e2a652fbb7a2d62a976b70f4af3adce8dae"
moz-do-not-send="true">https://github.com/cabforum/servercert/compare/c4a34fe2292022e0a04ba66b5a85df75907ac2a2...f6a90e2a652fbb7a2d62a976b70f4af3adce8dae</a>
<br>
</li>
</ul>
<h2 id="bkmrk-motion-ends">Motion Ends</h2>
<p id="bkmrk-this-ballot-proposes">This ballot proposes a Final
Maintenance Guideline. The procedure for approval of this
ballot is as follows:</p>
<h4 id="bkmrk-discussion-%2811%2B-days">Discussion (at least 7
days)</h4>
<ul id="bkmrk-start-time%3A-2024-01-">
<li class="null">Start time: 2024-04-25 16:30:00 UTC</li>
<li class="null">End time: on or after 2024-05-02 16:30:00 UTC</li>
</ul>
<h4 id="bkmrk-vote-for-approval-%287">Vote for approval (7 days)</h4>
<ul id="bkmrk-start-time%3A-tbd-end-">
<li class="null">Start time: 2024-05-05 8:30:00 UTC</li>
<li class="null">End time: 2024-05-12 8:30:00 UTC</li>
</ul>
<br>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<pre class="moz-quote-pre" wrap="">_______________________________________________
Servercert-wg mailing list
<a class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:Servercert-wg@cabforum.org" moz-do-not-send="true">Servercert-wg@cabforum.org</a>
<a class="moz-txt-link-freetext"
href="https://lists.cabforum.org/mailman/listinfo/servercert-wg"
moz-do-not-send="true">https://lists.cabforum.org/mailman/listinfo/servercert-wg</a>
</pre>
</blockquote>
<br>
</blockquote>
<br>
</body>
</html>