[cabfpub] Ballot 185 (Revised) - Limiting the Lifetime of Certificates

Ryan Sleevi sleevi at google.com
Fri Feb 17 08:59:16 MST 2017


For CAs that are voting against this:

Given that should the Baseline Requirements fail to show consensus, the
next step will be to require these changes as part of a browser program -
both as to considering a certificate trusted and to considering a
certificate misissued - in order to ensure security needs are met. As such,
it would helpful that those voting NO provide concrete and actionable
reasons as to the concerns, so as to inform what conditions that the CA
might consider it acceptable. Failure to articulate concerns simply means
that such concerns cannot be given any consideration before taking action.


On Fri, Feb 17, 2017 at 7:13 AM, Enric Castillo via Public <
public at cabforum.org> wrote:

> ANF Autoridad de Certificación votes no.
>
>
> Thanks,
>
> El 13/02/2017 a las 14:18, Ryan Sleevi via Public escribió:
>
> Pursuant to the consensus on https://cabforum.org/pipermail/public/2017-
> February/009530.html about the nature of changes during the discussion
> period, and the request from Gervase on https://cabforum.org/
> pipermail/public/2017-February/009618.html to adjust what represents the
> Baseline agreement, this adjusts the effective date from 1 April to 24
> August. While individual programs may choose to enact or enforce
> requirements prior to that, as the Baseline Requirements capture the
> effective point of common agreement of the bare minimum security levels, it
> seems appropriate that this Ballot accurately reflect that.
>
>
> Ballot 185 - Limiting the Lifetime of Certificates
>
> The following motion has been proposed by Ryan Sleevi of Google, Inc and
> endorsed by Josh Aas of ISRG and Gervase Markham of Mozilla to introduce
> new Final Maintenance Guidelines for the "Baseline Requirements Certificate
> Policy for the Issuance and Management of Publicly-Trusted Certificates"
> and the "Guidelines for the Issuance and Management of Extended Validation
> Certificates"
>
> -- MOTION BEGINS --
> Modify Section 6.3.2 of the "Baseline Requirements Certificate Policy for
> the Issuance and Management of Publicly-Trusted Certificates" as follows:
>
> Replace Section 6.3.2, which reads as follows:
> """
> 6.3.2. Certificate Operational Periods and Key Pair Usage Periods
>
> Subscriber Certificates issued after the Effective Date MUST have a
> Validity Period no greater than 60 months.
> Except as provided for below, Subscriber Certificates issued after 1 April
> 2015 MUST have a Validity Period
> no greater than 39 months.
>
> Until 30 June 2016, CAs MAY continue to issue Subscriber Certificates with
> a Validity Period greater than 39
> months but not greater than 60 months provided that the CA documents that
> the Certificate is for a system or
> software that:
> (a) was in use prior to the Effective Date;
> (b) is currently in use by either the Applicant or a substantial number of
> Relying Parties;
> (c) fails to operate if the Validity Period is shorter than 60 months;
> (d) does not contain known security risks to Relying Parties; and
> (e) is difficult to patch or replace without substantial economic outlay
> """
>
> with the following text:
> """
> 6.3.2. Certificate Operational Periods and Key Pair Usage Periods
>
> Subscriber Certificates issued on or after 24 August 2017 MUST NOT have a
> Validity Period greater than three hundred and ninety-eight (398) days.
>
> Subscriber Certificates issued prior to 24 August 2017 MUST NOT have a
> Validity Period greater than thirty-nine (39) months.
> """
>
> Modify Section 9.4 of the "Guidelines for the Issuance and Management of
> Extended Validation Certificates" as follows:
>
> Replace Section 9.4, which reads as follows:
> """
> 9.4. Maximum Validity Period For EV Certificate
>
> The validity period for an EV Certificate SHALL NOT exceed twenty seven
> months. It is RECOMMENDED that EV
> Subscriber Certificates have a maximum validity period of twelve months.
> """
>
> with the following text:
> """"
> 9.4 Maximum Validity Period for EV Certificate
>
> EV Certificates issued on or after 24 August 2017 MUST NOT have a Validity
> Period greater than three hundred and ninety-eight (398) days.
>
> EV Certificates issued prior to 24 August 2017 MUST NOT have a Validity
> Period greater than twenty seven (27) months.
> """
> -- MOTION ENDS --
>
> Ballot 185 - Limiting the Lifetime of Certificates
> Status: Final Maintenance Guideline
>
> Review Period:
> Start Time: 2017-02-10 00:00:00 UTC
> End Time: 2017-02-17 00:00:00 UTC
>
> Vote for Approval:
> Start Time: 2017-02-17 00:00:00 UTC
> End Time: 2017-02-24 00:00:00 UTC
>
> Votes must be cast by posting an on-list reply to this thread on the
> Public Mail List.
>
> A vote in favor of the ballot must indicate a clear 'yes' in the response.
> A vote against must indicate a clear 'no' in the response. A vote to
> abstain must indicate a clear 'abstain' in the response. Unclear responses
> will not be counted. The latest vote received from any representative of a
> voting Member before the close of the voting period will be counted. Voting
> Members are listed here: https://cabforum.org/members/
>
> In order for the ballot to be adopted, two thirds or more of the votes
> cast by Members in the CA category and greater than 50% of the votes cast
> by members in the browser category must be in favor.
>
>
> _______________________________________________
> Public mailing listPublic at cabforum.orghttps://cabforum.org/mailman/listinfo/public
>
>
> --
> [image: ANF AC - Autoridad de certificación] * Enric Castillo *
> * Gerente Región LATAM *
> ANF Autoridad de Certificación
> +34 626818285 <+34%20626%2081%2082%2085> *(Celular)*
> Gran Vía de Les Corts Catalanes 996, Barcelona
> +593 0 996483798 <+593%2099%20648%203798> *(Celular)*
> +593 2 2550002 <+593%202-255-0002>
> Av. 12 de Octubre N24-562 y Luis Cordero, Edif. World Trade Center, Torre
> A, Piso 11, Ofi. 1102, Quito
> castillo.enric
> enric.castillo at anf.es
> www.anf.es
>
> *AVISO*
> Este mensaje se dirige exclusivamente a su destinatario y puede contener
> información privilegiada o confidencial y/o datos de carácter personal,
> cuya difusión está regulada por la Ley Orgánica de Protección de Datos y la
> Ley de Servicios de la Sociedad de la Información. Si usted no es el
> destinatario indicado (o el responsable de la entrega al mismo), no debe
> copiar o entregar este mensaje a terceros bajo ningún concepto. Si ha
> recibido este mensaje por error o lo ha conseguido por otros medios, le
> rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a
> su eliminación irreversible. Las opiniones, conclusiones y demás
> informaciones incluidas en este mensaje que no estén relacionadas con
> asuntos profesionales de ANF Autoridad de Certificación no están
> respaldadas por la empresa.
>
> _______________________________________________
> Public mailing list
> Public at cabforum.org
> https://cabforum.org/mailman/listinfo/public
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: gcpjnjfdbhmmdaeo.png
Type: image/png
Size: 4746 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0007.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: odbieeibibenppnp.png
Type: image/png
Size: 3873 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0008.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: bkhblocikjnbdoob.png
Type: image/png
Size: 3311 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0009.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: pnppfnmebhojladm.png
Type: image/png
Size: 21794 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0010.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: bhkcdebdkdcmlpin.png
Type: image/png
Size: 1822 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0011.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: bfbndfhbbfemhhon.png
Type: image/png
Size: 3246 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0012.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: onjnjnbohgoldgid.png
Type: image/png
Size: 3712 bytes
Desc: not available
URL: <http://cabforum.org/pipermail/public/attachments/20170217/35bef4e6/attachment-0013.png>


More information about the Public mailing list