<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
h2
{mso-style-priority:9;
mso-style-link:"Heading 2 Char";
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:18.0pt;
font-family:"Calibri",sans-serif;
color:black;}
h3
{mso-style-priority:9;
mso-style-link:"Heading 3 Char";
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:13.5pt;
font-family:"Calibri",sans-serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.Heading2Char
{mso-style-name:"Heading 2 Char";
mso-style-priority:9;
mso-style-link:"Heading 2";
font-family:"Calibri",sans-serif;
color:black;
font-weight:bold;}
span.Heading3Char
{mso-style-name:"Heading 3 Char";
mso-style-priority:9;
mso-style-link:"Heading 3";
font-family:"Calibri",sans-serif;
color:black;
font-weight:bold;}
span.EmailStyle22
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<h2><a name="_Hlk116919592">Minutes of SMCWG<o:p></o:p></a></h2>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">January 18, 2023<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">These are the </span>
<span style="mso-bookmark:_Hlk116919592"><span style="color:windowtext">Approved</span> Minutes of the Teleconference described in the subject of this message. Corrections and clarifications where needed are encouraged by reply.<o:p></o:p></span></p>
<h3><span style="mso-bookmark:_Hlk116919592">Attendees <o:p></o:p></span></h3>
<h3><span style="mso-bookmark:_Hlk116919592"><span style="font-size:11.0pt;font-weight:normal">Andrea Holland - (SecureTrust), Ashish Dhiman - (GlobalSign), Ben Wilson - (Mozilla), Clint Wilson - (Apple), Corey Bonnell - (DigiCert), Dave Chin - (CPA Canada/WebTrust),
Don Sheehy - (CPA Canada/WebTrust), Enrico Entschew - (D-TRUST), Inaba Atsushi - (GlobalSign), Inigo Barreira - (Sectigo), Jamie Mackey - (US Federal PKI Management Authority), Judith Spencer - (CertiPath (Private Person)), Marco Schambach - (IdenTrust), Martijn
Katerbarg - (Sectigo), Matthias Wiedenhorst - (ACAB Council), Morad Abou Nasser - (TeleTrust), Nome Huang - (TrustAsia Technologies, Inc.), Patrycja Tulinska - (PSW), Rebecca Kelley - (Apple), Renne Rodriguez - (Apple), Russ Housley - (Vigil Security LLC),
Stefan Selbitschka - (rundQuadrat), Tadahiko Ito - (SECOM Trust Systems), Tim Crawford - (CPA Canada/WebTrust), Tsung-Min Kuo - (Chunghwa Telecom), Wendy Brown - (US Federal PKI Management Authority)<o:p></o:p></span></span></h3>
<h3><span style="mso-bookmark:_Hlk116919592">1. Roll Call<o:p></o:p></span></h3>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="mso-bookmark:_Hlk116919592">The Roll Call was taken.<o:p></o:p></span></p>
<h3><span style="mso-bookmark:_Hlk116919592">2. Read Antitrust Statement<o:p></o:p></span></h3>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="mso-bookmark:_Hlk116919592">The Antitrust/Compliance Statement was read.<o:p></o:p></span></p>
<h3><span style="mso-bookmark:_Hlk116919592">3. Review Agenda<o:p></o:p></span></h3>
<h3><span style="mso-bookmark:_Hlk116919592">4. Approval of minutes from last teleconference<o:p></o:p></span></h3>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">The minutes of the January 4 teleconference were approved.<o:p></o:p></span></p>
<h3><span style="mso-bookmark:_Hlk116919592">5. Discussion <o:p></o:p></span></h3>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Martijn Katerbarg chaired the meeting.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">The WG discussed the proposed text written by Stephen Davidson to add CAA to the S/MIME BR. See
</span><a href="https://avanan.url-protection.com/v1/url?o=https%3A//github.com/cabforum/smime/compare/main...srdavidson%3Asmime%3ACAA&g=ZjA0NDViZjhiNGIxMjNlMQ==&h=OGY1OGM5OWRlY2ZkMTNlYTMwMDg4ZjI4NTE4ZmI1YWVmM2U5MjczOThhNDU4Zjg4MzRmOGJhYmU1NTliMDA5YQ==&p=YXAzOmRpZ2ljZXJ0OmE6bzo5YmIzODA5OTVhMzNhYTM5OGNmYWQ3MjI5MzA5NzQyZTp2MTpoOkY=" title="Protected by Avanan: https://github.com/cabforum/smime/compare/main...srdavidson:smime:CAA"><span style="mso-bookmark:_Hlk116919592">https://github.com/cabforum/smime/compare/main...srdavidson:smime:CAA</span><span style="mso-bookmark:_Hlk116919592"></span></a><span style="mso-bookmark:_Hlk116919592"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Martijn noted that the text was quite complete other than the effective date. It was discussed that an effective date should be considered for 2024, in other words after the first effective date
for the S/MIME BR v1.0.0. This would allow time for Certificate Issuers with no previous CAA experience adequate time to implement the standard.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">WG members were invited to consider the text and to contribute to the IETF discussion regarding the CAA Internet-draft at
</span><a href="https://avanan.url-protection.com/v1/url?o=https%3A//mailarchive.ietf.org/arch/msg/spasm/Z8mRKrHgV2hfXY21Sa-6EPL-h9E/&g=MGVlZWRjMDQxYTJmNWIwNQ==&h=ZTMxZDdkZmMwYjlmNDA1YTllMTdhZjczYzY3NTI2OWQyMWJiMTBkNzhlMmMyZmY1YWNkMjE4N2NkMjc3YmY4Yw==&p=YXAzOmRpZ2ljZXJ0OmE6bzo4NDVkOTE5YWY4Yzg5YmU2YjZiYjI5YTY4MjIzZDRiMzp2MTpoOkY=" title="Protected by Avanan: https://mailarchive.ietf.org/arch/msg/spasm/Z8mRKrHgV2hfXY21Sa-6EPL-h9E/"><span style="mso-bookmark:_Hlk116919592">https://mailarchive.ietf.org/arch/msg/spasm/Z8mRKrHgV2hfXY21Sa-6EPL-h9E/</span><span style="mso-bookmark:_Hlk116919592"></span></a><span style="mso-bookmark:_Hlk116919592">
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Ben Wilson noted that a discussion was being started to propose the addition of the S/MIME BR to Sections 2.3 and 3.1.2 of the Mozilla Root Store Policy. This would need to go through community
discussion and review to talk about the Sept 1, 2023 adoption date and potentially a Sept 1, 2024 date by which all CAs would require eligible audits reported in CCADB.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Wendy Brown noted that the timetables described in the S/MIME BR may be sufficiently clear as it described audits being required “For Audit Periods starting after the Effective Date” for v.1.0.0.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Ben noted that the actual title of the TLS Baseline Requirements was obscure and that it would be easier for Certificate Consumers if the Server Certificate WG would update the title of that document
to specifically reference TLS or Server Certificates.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Martijn asked in Mozilla would stipulate any requirements on ICAs that go beyond what is in the S/MIME BR. Ben noted that the overall trend was towards separating activity by EKU, and longer term
this was encouraged even for roots. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">Don Sheehy noted that WebTrust was meeting in the coming weeks to review the proposed criteria. Their goal was to make this available far in advance of the effective date to allow CAs to prepare
or do self-assessments. Ben asked for an update of the ETSI regime. Inigo Barreira noted that Stephen Davidson and Dimitris Zacharopoulos were at the ETSI meeting this week where the topic was on the agenda.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<h3 style="mso-margin-top-alt:1.0pt;margin-right:0in;margin-bottom:1.0pt;margin-left:0in">
<span style="mso-bookmark:_Hlk116919592">6. Any Other Business<o:p></o:p></span></h3>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_Hlk116919592">None<o:p></o:p></span></p>
<h3><span style="mso-bookmark:_Hlk116919592">7. Next call<o:p></o:p></span></h3>
<h3><span style="mso-bookmark:_Hlk116919592"><span style="font-size:11.0pt;font-weight:normal">Next call: tentative Wednesday, February 1, 2023 at 11:00 am Eastern Time<o:p></o:p></span></span></h3>
<h3><span style="mso-bookmark:_Hlk116919592"><span lang="DE">Adjourned</span></span><span style="mso-bookmark:_Hlk116919592"></span><span style="color:windowtext"><o:p></o:p></span></h3>
</div>
</body>
</html>