[cabfpub] Code Signing Baseline Requirements

Dean Coclin Dean_Coclin at symantec.com
Tue Aug 11 13:31:21 MST 2015


The Code Signing Working Group of the CA/Browser Forum is pleased to
announce the release of the final version of the Code Signing Baseline
Requirements. The Working Group has been meeting over the last 2 years to
develop and bring this topic to the Forum for approval. 

 

The Working Group would like to have the Forum approve these Baseline
Requirements by ballot which will be put forth at the next teleconference.
Discussion will start at that time, followed by a formal vote.

 

This Working Group was chartered by the Forum at the Mozilla face to face
meeting in February 2013 and has brought together forum members and outside
participants to craft a document which we believe will help improve the
security of the ecosystem. Forum members in the working group include:
Comodo, Digicert, Entrust, ETSI, Federal PKI, Firmaprofessional,
Globalsign, Izenpe, Microsoft, Starcom, SwissSign, Symantec, Trend Micro,
WoSign as well as non-members: Cacert, Intarsys, OTA, Richter, and
Travelport.

 

The stated goal of the group was to: "Create a set of baseline requirements
for code signing that will reduce the incidence of signed malware". We
strived to work on 3 sub goals, which are by no means 100% solved. However
we feel that the document reflects progress towards these goals which were:

1.       Minimize private key theft by moving toward more secure key storage
(protection of private keys)

2.       Baseline authentication and vetting procedures for all parties

3.       Information sharing (notification/revocation) for fraud detection.
This piece was moved to the Information Sharing Working Group

 

We ask all members to review the document and provide feedback for
discussion to the forum. The guidelines would go into effect one year after
forum approval.

 

Thanks,


Dean Coclin and Jeremy Rowley

 

on behalf of the

Code Signing Working Group

 

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://cabforum.org/pipermail/public/attachments/20150811/a1a78996/attachment-0001.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Baseline requirements for codesigning - July 30 2015.doc
Type: application/msword
Size: 292352 bytes
Desc: not available
Url : https://cabforum.org/pipermail/public/attachments/20150811/a1a78996/attachment-0001.doc 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Baseline requirements for codesigning - July 30 2015.pdf
Type: application/pdf
Size: 797906 bytes
Desc: not available
Url : https://cabforum.org/pipermail/public/attachments/20150811/a1a78996/attachment-0001.pdf 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5747 bytes
Desc: not available
Url : https://cabforum.org/pipermail/public/attachments/20150811/a1a78996/attachment-0001.bin 


More information about the Public mailing list