[Cscwg-public] Final Minutes of CSCWG December 15, 2022

Dean Coclin dean.coclin at digicert.com
Thu Jan 12 17:12:31 UTC 2023


FINAL MINUTES

 

Code Signing Working Group: 15-Dec-2022

 

Attendees:

Andrea Holland, , Brianca Martin, , Bruce Morton, Corey Bonnell, Dean
Coclin, Dimitris Zacharopoulos, Inigo Barreira, Michael Sykes Mohit Kumar,
Rollin Yu, Tim Crawford, Trevoli Ponds-White

 

Antitrust statement was read.

Minutes approved for last meeting 1-Dec-22 and F2F.

There was discussion on how we can make minutes more effective - in general
with a suggestion on recapping along discussion by chair or minute taker for
summary.

 

Ballot around Malware protection:

Updates made to draft to suggest that subscriber can provide a different
date based on impact. And also, software application provider can check for
possible impact. Based on these 2, CA can decide on revocation date. 

 

It was mentioned that section 4 is confusing and not clear. 

Clarification provided that if CA receives a report of malware being signed,
they will report it to subscriber. If subscriber reports within 72 hours,
CAs can do impact assessment else they have to revoke in 24 hours. In any
case, CA has to revoke in 7 days

 

Alternate proposal was presented that if subscriber or Software application
asks CA to revoke, it should be revoked in 24 hours else in 7 days.

The critical element of the actual process is deciding what will be the
revocation date i.e. the back date from which we expect malware to be
signed. For this reason, we had procedure for impact analysis.

CA should have date of previously signed suspected code or evidence to show
that private key was compromised. That way we can backdate the revocation 

If we go to the back date of issue of certificate, then it impacts all the
drivers signed till date so CA need a different timestamp. 

 

Need to be improved and discussion to be kept in progress. 

 

Signing Service:

No updates

 

Removing SSL BRs references:

Concerns highlighted in redline in Github. Pull request to be shared with
the group.

 

Next meeting will be on 12-Jan-23

 

 

Dean Coclin

CSCWG Chair

 

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/cscwg-public/attachments/20230112/0d1cc0d3/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4916 bytes
Desc: not available
URL: <http://lists.cabforum.org/pipermail/cscwg-public/attachments/20230112/0d1cc0d3/attachment.p7s>


More information about the Cscwg-public mailing list