[Cscwg-public] CSCWG Final Minutes November 17, 2022

Dean Coclin dean.coclin at digicert.com
Thu Dec 1 18:37:12 UTC 2022


Here are the final minutes of the November 17, 2022 call:

 

1.                   Roll Call - Bruce Morton (Entrust), Atsushi Inaba
(GobalSign), Corey Bonnell (DigiCert), Dimitris Zacharopoulos (HARICA), Ian
McMillan (Microsoft), Martijn Katerberg (Sectigo), Trevoli Ponds-White
(Amazon Trust Services), Tomas Gustavsson, TimCrawford (BDO), Roberto
Quinones (Intel), Joanna Fox (Trustcor)

2.                   Antitrust statement was read.

3.                   Minutes from 25 October are not yet available. Minutes
from 3 November were approved. 

4.                   Ballot: Signing Service Update - The draft text has
been recirculated. Dimitris has some comments on the ETSI Time-stamping
audit requirements. The Signing Service audit requirements were fine.
Discussed allowing a Signing Service to be audited to a SANs standard; this
would require more discussion. Ian plans to endorse. Ian would like to
address FIPS 140-2 Level 3 requirement date for the Signing Service. Bruce
reviewed the NetSec audit requirements and most appear they could apply to a
Signing Service, if CA was replaced with Signing Service and other minor
adjustments.

5.                   Ballot: Malware base revocation - A number of comments
have been added and have been addressed. Martijn will push the changes to
GitHub and will push the ballot forward in the next few days.

6.                   Other business - Dimitris has not received any other
feedback on moving away from the SSL BRs. The direction is to try to replace
references with text from the SSL BRs. Martijn will plan to put sometime to
this over the next week. Bruce stated the plan was also to try to
rationalize if the changes do not make sense for Code Signing. 

7.                   Next Meeting - 1 December

8.                   Adjourn   

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/cscwg-public/attachments/20221201/395fe18d/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4916 bytes
Desc: not available
URL: <http://lists.cabforum.org/pipermail/cscwg-public/attachments/20221201/395fe18d/attachment.p7s>


More information about the Cscwg-public mailing list