From jos at melete.org Thu Aug 1 16:48:55 2024 From: jos at melete.org (Jos Purvis) Date: Thu, 01 Aug 2024 12:48:55 -0400 Subject: [Cscwg-public] =?utf-8?q?Test_email_=E2=80=94_please_ignore?= Message-ID: Testing sending to list -------------- next part -------------- An HTML attachment was scrubbed... URL: From dean.coclin at digicert.com Thu Aug 1 20:36:45 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Thu, 1 Aug 2024 20:36:45 +0000 Subject: [Cscwg-public] FW: Mistake in CSBR In-Reply-To: References: <609401dae3ea$f290f6d0$d7b2e470$@microsec.com> <653401dae41e$38492340$a8db69c0$@microsec.com> Message-ID: Forwarding this to the public list with Viktor?s permission. Is there any discussion? I can add it to the agenda for the next call. Dean Coclin CSCWG Chair From: Varga Viktor Sent: Thursday, August 1, 2024 4:15 AM To: Dean Coclin Subject: Mistake in CSBR Dear Dean, I think I found a mistake in the CSBR. Neither in the chapter 7.1.2.1 Root CA Certificate nor in the chapter 7.1.2.2 Subordinate CA Certificate can we found section for the subjectKeyIdentifier (later SKI) extension. But also 7.1.2.4 explicitly denies to use any other extension than listed in these chapter. But the RFC 5280 mandates this. (I added the important chapters to the end of mail) May I ask for correction to add the SKI to the requirements? This extension shall be added to 7.1.2.1 and 7.1.2.2 and optionally in 7.1.2.3. Also I would like to ask: Can we agree in that, if we are issuing CA certificate until the correction, a CA certificate with SKI can be accepted as good because it fits in the term: ?unless the CA is aware of a reason?. Kind regards, Viktor Viktor Varga PKI Architect & Trust Services Manager CSBR 7.1.2.4 All Certificates All other fields and extensions MUST be set in accordance with RFC 5280. The CA SHALL NOT issue a Certificate that contains a keyUsage flag, extKeyUsage value, Certificate extension, or other data not specified in Section 7.1.2.1, Section 7.1.2.2, or Section 7.1.2.3 unless the CA is aware of a reason for including the data in the Certificate. RFC 5280 4.2.1.2. Subject Key Identifier The subject key identifier extension provides a means of identifying certificates that contain a particular public key. To facilitate certification path construction, this extension MUST appear in all conforming CA certificates, that is, all certificates including the basic constraints extension (Section 4.2.1.9) where the value of cA is TRUE. -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: image001.png Type: image/png Size: 5873 bytes Desc: not available URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: From dean.coclin at digicert.com Thu Aug 1 23:56:33 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Thu, 1 Aug 2024 23:56:33 +0000 Subject: [Cscwg-public] ADOPTED: Ballot CSC25: Import EV Guidelines into the Code Signing Baseline Requirements In-Reply-To: <010001906e6103e6-b82bc59e-bb53-4a6a-af68-7d76969e4f4c-000000@email.amazonses.com> References: <010001902fff4bba-31f00113-be4e-4124-9e98-f6b5d00f2cf6-000000@email.amazonses.com> <0100019055d51204-1588ed70-af6c-4504-8e77-fbb3adab4ce0-000000@email.amazonses.com> <010001906e6103e6-b82bc59e-bb53-4a6a-af68-7d76969e4f4c-000000@email.amazonses.com> Message-ID: Ballot CSC 25: Import EV Guidelines into the Code Signing Baseline Requirements The Intellectual Property Review (IPR) period for Ballot CSC25: Import EV Guidelines into the Code Signing Baseline Requirements has completed. No IPR Exclusion Notices were filed, and the ballot is adopted as of Aug 1, 2024. The new Code Signing BRs will be published to the CABF public website in accordance with the Bylaws. Dean Coclin CSCWG Chair From: Cscwg-public On Behalf Of Dean Coclin via Cscwg-public Sent: Monday, July 1, 2024 9:00 AM To: cscwg-public at cabforum.org Subject: [Cscwg-public] NOTICE OF REVIEW PERIOD: CSC-25: Import EV Guidelines into the Code Signing Baseline Requirements NOTICE OF IPR REVIEW PERIOD This Review Notice is sent pursuant to Section 4.1 of the CA/Browser Forum?s Intellectual Property Rights Policy (v1.3). This Review Period of 30 days is for one Final Maintenance Guidelines. The complete Draft Maintenance Guideline that is the subject of this Review Notice is attached to this email, both in red-line and changes-accepted draft format, in PDF version. Summary of Review Ballot for Review: Ballot CSC-25 Start of Review Period: July 1st, 2024 at 2:00 PM UTC End of Review Period: August 1, 2024 at 2:00 PM UTC Members with any Essential Claim(s) to exclude must forward a written Notice to Exclude Essential Claims to the Working Group Chair (email to Dean Coclin < dean.coclin at digicert.com>) and also submit a copy to the CA/B Forum CSCWG public mailing list (email to public at cabforum.org >) before the end of the Review Period. For details, please see the current version of the CA/Browser Forum Intellectual Property Rights Policy. (An optional template for submitting an Exclusion Notice is available at https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf) Dean Coclin CSCWG Chair From: Cscwg-public > On Behalf Of Dean Coclin via Cscwg-public Sent: Wednesday, June 26, 2024 2:36 PM To: cscwg-public at cabforum.org Subject: [Cscwg-public] Ballot results: CSC-25: Import EV Guidelines into the Code Signing Baseline Requirements The voting period has ended on CSC-25 and the ballot has passed. Here are the results: Certificate Issuers voting in favor (6): Certum, DigiCert, Entrust, Harica, Identrust, Sectigo Opposed: None Abstentions: None Certificate Consumers voting in favor (1): Microsoft Opposed: None Abstentions: None Quorom is 5, therefore the ballot passes. Dean Coclin CSCWG Chair From: Cscwg-public < cscwg-public-bounces at cabforum.org> On Behalf Of Dimitris Zacharopoulos (HARICA) via Cscwg-public Sent: Wednesday, June 19, 2024 6:16 AM To: cscwg-public at cabforum.org Subject: [Cscwg-public] [Voting begins] Ballot CSC-25: Import EV Guidelines into the Code Signing Baseline Requirements Voting begins for this ballot. CSC-25 Import EV Guidelines into the Code Signing Baseline Requirements Purpose of the Ballot This ballot updates the ?Baseline Requirements for the Issuance and Management of Publicly?Trusted Code Signing Certificates? version 3.7 in order to clarify language regarding Timestamp Authority Private Key Protection. The main goals of this ballot are to: 1. Import all CSBR references that point to the EV Guidelines with the actual language of corresponding sections of version 1.8.0 of the EV Guidelines, in order to remove external dependencies. 2. The Code Signing Working Group decided not to import rules related to the subject:organizationIdentifier field. The following motion has been proposed by Dimitris Zacharopoulos of HARICA and endorsed by Martijn Katerbarg of Sectigo and Corey Bonnell of Digicert. You can view the github pull request representing this ballot here . Motion Begins MODIFY the ?Baseline Requirements for the Issuance and Management of Publicly?Trusted Code Signing Certificates? ("Code Signing Baseline Requirements") based on version 3.7 as specified in the following redline: * https://url.avanan.click/v2/___https://github.com/cabforum/code-signing/compare/d431d9104094f2b89f35ed4bf1d64b9a844e762b...d5af6d895b3666b5351509ad25d47ac5e87321fc___.YXAzOmRpZ2ljZXJ0OmE6bzoyNmRkOGE3Y2M2NDYyMDI5OTZmM2RlZWMwZTdlMzQzMjo2OjdjNDc6NzllNjY3OWJmMmEyZTUyM2IzMDZhM2M2YWU3MWNmZmU4ZjkwMzFjYTQxNDU5OTdiZTFlMjRjMTc2NGM5YjhiYjp0OkY Motion Ends This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows: Discussion (at least 7 days) * Start time: 2024-06-12 07:00:00 UTC * End time: on or after 2024-06-19 07:00:00 UTC Vote for approval (7 days) * Start time: 2024-06-19 10:15:00 UTC * End time: 2024-06-26 10:15:00 UTC -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: From dean.coclin at digicert.com Thu Aug 1 23:58:00 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Thu, 1 Aug 2024 23:58:00 +0000 Subject: [Cscwg-public] Adopted: CSC-26 Timestamping Private Key Protection Ballot In-Reply-To: <010001906e93c8f5-a3034675-99c9-40c1-90d3-d26b6910cb2d-000000@email.amazonses.com> References: <01000190367c5978-cff932df-76f4-4a29-95ad-fac536cfa2b6-000000@email.amazonses.com> <01000190607d78f8-da3ebe4b-07b3-47e0-a4d3-56746d2e3be3-000000@email.amazonses.com> <010001906e93c8f5-a3034675-99c9-40c1-90d3-d26b6910cb2d-000000@email.amazonses.com> Message-ID: Ballot CSC 26: Timestamping Private Key Protection Ballot The Intellectual Property Review (IPR) period for Ballot CSC26: Timestamping Private Key Protection Ballot has completed. No IPR Exclusion Notices were filed, and the ballot is adopted as of Aug 1, 2024. The new Code Signing BRs will be published to the CABF public website in accordance with the Bylaws. Dean Coclin CSCWG Chair From: Cscwg-public On Behalf Of Dean Coclin via Cscwg-public Sent: Monday, July 1, 2024 9:55 AM To: cscwg-public at cabforum.org Subject: [Cscwg-public] Notice of IPR Review Period: CSC-26 Timestamping Private Key Protection Ballot NOTICE OF IPR REVIEW PERIOD This Review Notice is sent pursuant to Section 4.1 of the CA/Browser Forum?s Intellectual Property Rights Policy (v1.3). This Review Period of 30 days is for one Final Maintenance Guidelines. The complete Draft Maintenance Guideline that is the subject of this Review Notice is attached to this email, both in red-line and changes-accepted draft format, in PDF version. Summary of Review Ballot for Review: See below email Start of Review Period: July 1st, 2024 at 3:00 PM UTC End of Review Period: August 1, 2024 at 3:00 PM UTC Members with any Essential Claim(s) to exclude must forward a written Notice to Exclude Essential Claims to the Working Group Chair (email to Dean Coclin < dean.coclin at digicert.com>) and also submit a copy to the CA/B Forum CSCWG public mailing list (email to public at cabforum.org >) before the end of the Review Period. For details, please see the current version of the CA/Browser Forum Intellectual Property Rights Policy. (An optional template for submitting an Exclusion Notice is available at https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf) Dean Coclin CSCWG Chair From: Cscwg-public > On Behalf Of Dean Coclin via Cscwg-public Sent: Friday, June 28, 2024 4:16 PM To: cscwg-public at cabforum.org Subject: [Cscwg-public] CSC-26 Timestamping Private Key Protection Ballot results Voting on CSC-26 Timestamping Private Key Protection has closed and the ballot has passed. Results are below: Certificate Issuers In Favor: Certum, DigiCert, eMudhra, Entrust, GlobalSign, IdenTrust, Sectigo, SSL.com Opposed: none Abstain: none Certificate Consumers: In Favor: Microsoft Opposed: none Abstain: none Quorum was met at 5, therefore the ballot passes. Dean Coclin CSCWG Chair From: Cscwg-public < cscwg-public-bounces at cabforum.org> On Behalf Of Martijn Katerbarg via Cscwg-public Sent: Thursday, June 20, 2024 12:31 PM To: cscwg-public at cabforum.org Subject: [Cscwg-public] [Voting Period Begins] CSC-26 Timestamping Private Key Protection Purpose of the Ballot This ballot updates the ?Baseline Requirements for the Issuance and Management of Publicly?Trusted Code Signing Certificates? version 3.7 in order to clarify language regarding Timestamp Authority Private Key Protection. The main goals of this ballot are to: 1. Require Timestamp Authority Subordinate CA Private Keys to be stored in offline HSMs 2. Add a requirement to remove Private Keys associated with Timestamp Certificates after a 18 months 3. Add a requirement to reject SHA-1 timestamp requests The following motion has been proposed by Martijn Katerbarg of Sectigo and endorsed by Bruce Morton of Entrust and Ian McMillan of Microsoft. MOTION BEGINS This ballot updates the ?Baseline Requirements for the Issuance and Management of Publicly?Trusted Code Signing Certificates? ("Code Signing Baseline Requirements") based on version 3.7. MODIFY the Code Signing Baseline Requirements as specified in the following redline: https://github.com/cabforum/code-signing/compare/d431d9104094f2b89f35ed4bf1d64b9a844e762b...12130ff7c2b41d795d47925c084780ea0f7328cd MOTION ENDS The procedure for this ballot is as follows: Discussion (7 days) * Start Time: 2024-06-13 16:30 UTC * End Time: 2024-06-20 16:30 UTC Vote for approval (7 days) * Start Time: 2024-06-20 16:30 UTC * End Time: 2024-06-27 16:30 UTC -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: From infra-bot at cabforum.org Sun Aug 4 07:34:49 2024 From: infra-bot at cabforum.org (Infrastructure Bot) Date: Sun, 4 Aug 2024 07:34:49 +0000 Subject: [Cscwg-public] Weekly github digest (Code Signing Certificate Working Group) Message-ID: <010001911c4ffc80-d2e186f4-18b9-4664-80d0-cc50a9040b12-000000@email.amazonses.com> Pull requests ------------- * cabforum/code-signing (+0/-0/?1) 1 pull requests received 1 new comments: - #38 CSC-25: Import EV Guidelines to CS Baseline Requirements (1 by CBonnell) https://github.com/cabforum/code-signing/pull/38 [ballot] Repositories tracked by this digest: ----------------------------------- * https://github.com/cabforum/code-signing -------------- next part -------------- An HTML attachment was scrubbed... URL: From dean.coclin at digicert.com Tue Aug 6 21:04:56 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Tue, 6 Aug 2024 21:04:56 +0000 Subject: [Cscwg-public] CSCWG Agenda Aug 8th, 2024 In-Reply-To: References: <0100018ee7311c62-c29acc48-63bd-4046-ae95-3739ce164d40-000000@email.amazonses.com> <0100018f30ab4130-f2c3d2b7-bd9a-4fda-a0f1-db812db9a8f5-000000@email.amazonses.com> <0100018f77b0804d-acdd8021-f7a0-4d1a-a095-72bddf723bf5-000000@email.amazonses.com> <01000190036a85ba-51d6dc8b-2178-4c49-8abc-e94219910e4c-000000@email.amazonses.com> <0100019055b3e05e-57a5eda1-7d50-488d-824c-7e517dc78080-000000@email.amazonses.com> <01000190dfbb02c6-23f3fa1a-ac45-4b4d-bfaf-d5cfaf2d2086-000000@email.amazonses.com> Message-ID: MINUTE TAKER: NEED A VOLUNTEER, START RECORDING 1. Roll Call 2. Antitrust reminder 3. Approve prior meeting minutes - June 27th (Brianca), July 25th (Scott) 4. IPR review complete: CSC-25 Remove EV Guideline References (Dimitris) 5. IPR review complete: CSC-26 Time-stamp Requirements update (Martijn) 6. Max validity of CS certs (Ian) - proposal? 7. Question from Viktor Varga on SKI requirements in CSRB 8. Simplifying EV (Tim) 9. Fall elections: Bruce nominated for Chair (automatic), Martijn and Dean nominated for Vice Chair. Will coordinate w/Forum 10. Other business 11. Next meeting - Aug 22nd 12. Adjourn Dean Coclin CSCWG Chair -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: From dean.coclin at digicert.com Thu Aug 8 17:47:59 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Thu, 8 Aug 2024 17:47:59 +0000 Subject: [Cscwg-public] Final minutes of CSCWG July 11, 2024 In-Reply-To: <010001910f050a6b-2b263afb-eabf-495f-8bd7-ab2ed38745d7-000000@email.amazonses.com> References: <01000190e01e3337-25ec969f-d10b-49cd-bab7-95b3077181e4-000000@email.amazonses.com> <010001910f050a6b-2b263afb-eabf-495f-8bd7-ab2ed38745d7-000000@email.amazonses.com> Message-ID: Attendees: Wangmo Tenzing Ian McMillan Microsoft Corey Bonnell -DigiCert Atsushi INABA - GlobalSign Inigo Barreira - Sectigo Rebecca Kelley - SSL.com Brian Winters - IdenTrust Bruce Morton - Entrust Thomas Zermeno - SSL.com Tim Crawford - BDO Scott Rea - eMudhra Dean Coclin-DigiCert (checked in to start meeting call) Agenda with notes: 1. Roll Call a. Completed by Bruce 2. Antitrust reminder a. Completed by Bruce 3. Approve prior meeting minutes - June 13th and June 27th (Brianca) a. Minutes are not available for review and approval b. Pushed to next meeting 4. IPR review: CSC-25 Remove EV Guideline References (Dimitris) a. Ballot has passed and IPR period set to complete on August 1, 2024 5. IPR review: CSC-26 Time-stamp Requirements update (Martijn) a. Ballot has passed and IPR period set to complete on August 1, 2024 6. Simplifying EV (Tim) a. Tim was not available on the call (pushing to next meeting) b. No progress has been made currently, but CSC-25 completion will simplify this effort 7. Other business a. Ian volunteered to provide draft language for reducing the signing certificate max validity from 39 months to 15 months as previously discussed by the group b. Draft to be shared in next meeting c. No other business 8. Next meeting - July 25th 9. Adjourn Dean Coclin CSCWG Chair -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: From dean.coclin at digicert.com Thu Aug 8 17:48:25 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Thu, 8 Aug 2024 17:48:25 +0000 Subject: [Cscwg-public] Final minutes of CSCWG meeting July 25, 2024 In-Reply-To: <010001910f008a62-5984f443-8fa6-4338-9c77-dfc64338063f-000000@email.amazonses.com> References: <010001910f008a62-5984f443-8fa6-4338-9c77-dfc64338063f-000000@email.amazonses.com> Message-ID: Final Minutes for CSCWG Call 25 Jul 2024 Agenda: 1. Roll Call 2. Antitrust reminder 3. Approve prior meeting minutes - June 13th, June 27th (Brianca), July 11th (Ian)? 4. IPR review: CSC-25 Remove EV Guideline References (Dimitris) 5. IPR review: CSC-26 Time-stamp Requirements update (Martijn) 6. Simplifying EV (Tim) 7. Fall elections 8. Other business 9. Next meeting - Aug 8th 10. Adjourn Attendees: Brian Winters (Identrust), Brianca Martin (Amazon), Bruce Morton (Entrust), Dean Coclin, (DigiCert), Ian McMillan (Microsoft), Inaba Atsushi (GlobalSign), Mohit Kumar (GlobalSign), Puneet (EncryptionConsulting.com), Rebecca Kelley (SSL.com), Richard Kisley (IBM), Scott Rea (eMudhra), Thomas Zermeno (SSL.com) Minutes: Dean read the note well. Meeting minutes for June 13, 2024 Meeting (Rebecca Kelley) posted - Approved unanimously. Meeting minutes for June 27, 2024 Meeting (Brianca Martin) yet to be posted. Meeting minutes for July 11, 2024 Meeting (Ian McMillan) posted - Approved unanimously. IPR review Ballot CSC-25 is on-going - conclusion date is August 1, 2024. IPR review Ballot CSC-26 is on-going - conclusion date is August 1, 2024. Simplifying EV : Tim H is at IETF (along with a lot of other folks who are normally on this call), so we will return to this item on a future call, when Tim is available. Related question on Microsoft HLK Certification requiring EV cert - posed to Ian for clarification. [Ian] There is a requirement today for registration with EV cert, but the program is reviewing that, and we anticipate an outcome in the August time frame. Elections for chair and vice chair positions will take place in October. Nomination process outlined. Dean is not eligible as Chair again, but Bruce as VC has standing for automatic nomination. Bruce accepts that nomination. Other nominations for Chair will be open in August. VC nominations are open now. Ian nominates Martijn Katerbarg as Vice Chair, seconded by Thomas (SSL.com). Martin was not on call to accept. Bruce nominates Dean as VC. Dean to add the elections process outlined by Dimitris to the agenda for the next meeting and start the formal nomination process in August. Other Business: Ian has created draft of Ballot to change max validity (reduction to 15 months), but just wants to settle on effective date to be mentioned in the ballot. April 30, 2025 effective date was agreed, will post to list after 1 Aug. PCIHSM requirements : Ian said MSFT folks feel using an OR statement (FIPS140-2 level 2 or PCIHSM) doesn't make much sense since all Commerce HSMs already meet FIPS. [Richard] FIPS taking a long time to get certifications approved for HSMs in the transition to FIPS140-3 so FIPS compliance is beginning to become difficult to maintain. [Ian] MSFT is holding firm at this point, and still requiring FIPS. No disagreement on required levels: Subscriber is Level 2, Signing Service or CAs are Level 3. [Puneet] Certification of device is one thing, but it also depends on how it's been implemented as to whether it meets that Level. Meeting adjourned. Next meeting August 8th. Dean Coclin CSCWG Chair -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: From infra-bot at cabforum.org Sun Aug 11 07:34:55 2024 From: infra-bot at cabforum.org (Infrastructure Bot) Date: Sun, 11 Aug 2024 07:34:55 +0000 Subject: [Cscwg-public] Weekly github digest (Code Signing Certificate Working Group) Message-ID: <01000191405c965d-7ead3661-580d-4ccc-8855-c73c07851c3f-000000@email.amazonses.com> Pull requests ------------- * cabforum/code-signing (+1/-3/?0) 1 pull requests submitted: - CSC-26 final adjustments (by CBonnell) https://github.com/cabforum/code-signing/pull/40 3 pull requests merged: - CSC-26 final adjustments https://github.com/cabforum/code-signing/pull/40 - CSC-26: Timestamping Private Key Protection https://github.com/cabforum/code-signing/pull/34 [ballot] - CSC-25: Import EV Guidelines to CS Baseline Requirements https://github.com/cabforum/code-signing/pull/38 [ballot] Repositories tracked by this digest: ----------------------------------- * https://github.com/cabforum/code-signing -------------- next part -------------- An HTML attachment was scrubbed... URL: From Bruce.Morton at entrust.com Mon Aug 19 11:12:26 2024 From: Bruce.Morton at entrust.com (Bruce Morton) Date: Mon, 19 Aug 2024 11:12:26 +0000 Subject: [Cscwg-public] CSCWG Agenda Aug 22nd, 2024 In-Reply-To: References: <0100018ee7311c62-c29acc48-63bd-4046-ae95-3739ce164d40-000000@email.amazonses.com> <0100018f30ab4130-f2c3d2b7-bd9a-4fda-a0f1-db812db9a8f5-000000@email.amazonses.com> <0100018f77b0804d-acdd8021-f7a0-4d1a-a095-72bddf723bf5-000000@email.amazonses.com> <01000190036a85ba-51d6dc8b-2178-4c49-8abc-e94219910e4c-000000@email.amazonses.com> <0100019055b3e05e-57a5eda1-7d50-488d-824c-7e517dc78080-000000@email.amazonses.com> <01000190dfbb02c6-23f3fa1a-ac45-4b4d-bfaf-d5cfaf2d2086-000000@email.amazonses.com> <0100019129827fe3-b9fb7b3a-8833-48c9-8e47-d77671161db4-000000@email.amazonses.com> Message-ID: MINUTE TAKER: NEED A VOLUNTEER, START RECORDING 1. Roll Call 2. Antitrust reminder 3. Approve prior meeting minutes - June 27th (Brianca), August 8th (Dean) 4. Max validity of CS certs (Ian) - proposal? 5. Simplifying EV (Tim) 6. Fall elections: Bruce nominated for Chair (automatic), Martijn and Dean nominated for Vice Chair. Will coordinate w/Forum 7. Other business 8. Next meeting - Sept 5th 9. Adjourn Bruce. -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4933 bytes Desc: not available URL: From martijn.katerbarg at sectigo.com Tue Aug 20 14:19:54 2024 From: martijn.katerbarg at sectigo.com (Martijn Katerbarg) Date: Tue, 20 Aug 2024 14:19:54 +0000 Subject: [Cscwg-public] Code Signing mailing list migration Message-ID: ?All, Please take notice that I plan on migrating the Code Signing WG public and management mailing lists from Mailman to Google Groups on Wednesday August 21st. Estimated time is around 09:00 UTC. As a result, cscwg-management at cabforum.org will no longer be accepting incoming emails after that time. The new email address for the management list will be cscwg-management at groups.cabforum.org . Likewise, cscwg-public at cabforum.org will no longer be accepting incoming emails after that time. The new email address for the public list will be cscwg-public at groups.cabforum.org . All existing emails previously sent to the mailing list, will be migrated to the new Google Groups list. All existing subscribers of the existing mailing list will be made a member of the new Google Groups list. For questions, please reach out. Regards, Martijn -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 8254 bytes Desc: not available URL: From dean.coclin at digicert.com Tue Aug 20 14:53:37 2024 From: dean.coclin at digicert.com (Dean Coclin) Date: Tue, 20 Aug 2024 14:53:37 +0000 Subject: [Cscwg-public] FW: [management] Nomination period for Chair of CABF, SCWG, CSCWG, SMCWG and NetSec ends on Monday, August 26 at 11:00 am Eastern Time In-Reply-To: References: <30a12eeb-5834-4fb4-aada-492b27428fa5@harica.gr> Message-ID: I?d like to nominate Martijn Karterbarg for CSCWG chair. I?ve added his name to the wiki. Dean From: 'Dimitris Zacharopoulos (HARICA)' via Management (CA/B Forum) > Sent: Monday, July 29, 2024 2:09 AM To: management at groups.cabforum.org ; netsec-management at groups.cabforum.org ; smcwg-management at groups.cabforum.org ; cscwg-management at groups.cabforum.org Subject: [management] Nomination period for Chair of CABF, SCWG, CSCWG, SMCWG and NetSec ends on Monday, August 26 at 11:00 am Eastern Time Dear Members, Nominations for the offices of: 1. Chair of the CA/Browser Forum 2. Chair of the Server Certificate Working Group 3. Chair of the Code Signing Certificate Working Group 4. Chair of the S/MIME Certificate Working Group 5. Chair of the Network Security Working Group OPEN on July 29 at 11:00 am Eastern Time. Nominations can be posted here: * https://wiki.cabforum.org/books/forum/page/elections-of-cab-forum-and-chartered-working-group-officers-2024-2026 Nominations will remain open through August 26 at 11:00 Eastern Time. Here is a brief calendar of how we will be running Chair elections: Summary of Chair Officer Election Dates July 29 Nominations open Aug. 26 Nominations close. Candidates may prepare statements for posting on Management list Sept. 9 or earlier Sept. 2 Start of Ballot for election of Chair ? one week for discussion (if multiple candidates). Candidates may post statements to Management List. Sept. 9 Discussion period ends, voting period starts Sept. 16 Voting period ends Sept. 30 Results announced to the Public Mailing Lists -- You received this message because you are subscribed to the Google Groups "Management (CA/B Forum)" group. To unsubscribe from this group and stop receiving emails from it, send an email to management+unsubscribe at groups.cabforum.org . To view this discussion on the web visit https://groups.google.com/a/groups.cabforum.org/d/msgid/management/30a12eeb-5834-4fb4-aada-492b27428fa5%40harica.gr . -------------- next part -------------- An HTML attachment was scrubbed... URL: -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4542 bytes Desc: not available URL: