[cabfpub] Draft Ballot 186 - Limiting the Reuse of Validation Information

Ryan Sleevi sleevi at google.com
Wed Feb 1 11:43:52 MST 2017


On Wed, Feb 1, 2017 at 8:33 AM, Peter Bowen <pzb at amzn.com> wrote:
>
> (excerpting to focus on data)
>
> I ran some numbers this morning about EV validity periods.
>
> There are about 337,000 unexpired certs in CT logs that appear to be
> intended to be EV certs.  The duration between notBefore and notAfter
> breaks down as:
>
> Less than about one year: 1.24%
> About a year: 18.3%
> About 13 months: 6.03%
> About 14-15 months: 5.93%
> About 16-18 months: 1.08%
> About 19-24 months: 50.9%
> About 25-27 months: 16.5%
> Longer than about 27 months: 0.06%
>
> The numbers are “about” because the definition of month is not clear, so I
> rounded things.
>

Thanks for running this data, Peter. It seems CAs have been ignoring the
RECOMMENDED portion of the EV Guidelines for some time, but that
unfortunately comes as no surprise. It highlights the necessity that the
only way to ensure RECOMMENDED practices are followed are to make them
MANDATORY.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cabforum.org/pipermail/public/attachments/20170201/a68a51c6/attachment-0001.html>


More information about the Public mailing list