[cabfpub] Background information for ICANN WhoIs data/GDPR discussion on our Thursday CABF call

Francisco Arias francisco.arias at icann.org
Thu Apr 5 17:49:40 UTC 2018

Kirk and other colleagues,

Thank you for having me this morning in the CA/B Forum call. I look forward to work with you in the RDAP pilot and otherwise.



On 4/4/18, 4:45 PM, "Francisco Arias" <francisco.arias at icann.org<mailto:francisco.arias at icann.org>> wrote:


I’ve attached the slides I have prepared for tomorrow’s meeting. I look forward to our conversation in a few hours.


Francisco Arias
Sr. Director, GDD Technical Services
Domain Name Services & Industry Engagement
Global Domains Division
PGP fingerprint: 1FDE 819F 7BEC 1CB2 127E EE54 9A4D 337B D510 E397

On 4/3/18, 4:50 PM, "Public on behalf of Kirk Hall via Public" <public-bounces at cabforum.org<mailto:public-bounces at cabforum.org> on behalf of public at cabforum.org<mailto:public at cabforum.org>> wrote:

As most of you know, the EU’s GDPR privacy regulation takes effect May 25.  This has caused ICANN to reexamine its requirements for registries and registrars on displaying WhoIs domain registration data, which CAs use to validation domain ownership or control by domain owners to issue SSL/TLS certificates.

The subject has been a difficult one, and the deadline is fast approaching.  ICANN has released a Proposed Interim Plan for GDPR Compliance, and is asking for comments: https://www.icann.org/news/blog/data-protection-privacy-update-seeking-input-on-proposed-interim-model-for-gdpr-compliance  Here is the draft interim plan:

I have invited Francisco Arias, Sr. Director, GDD Technical Services for ICANN, to be on our Thursday teleconference call and provide a high level overview of the Interim Plan.  Francisco has told me that the Plan posted to the ICANN website is only a draft and may change.  He also said the Plan includes the concept of allowing certain parties, such as law enforcement and others, to have continued access to WhoIs data after the GDPR takes effect, but the Interim Plan does not yet include specific access to the data for CAs.  Francisco suggested the Forum and its members should post comments (including a request for continued data access in the Interim Plan) to the address for comments on the Interim Plan, gdpr at icann.org<mailto:gdpr at icann.org>.  I will certainly post a request for continued access for the CA/Browser Forum members, but others may also want to do so.

On our call, Francisco will also be asking for CA volunteers to work on a pilot program using RDAP for differentiated access to domain registration data instead of WhoIs, as only RDAP can really provide different levels of access.  I will leave it to Francisco to describe the pilot project and how CAs can volunteer.  Again, the time frame is very short.

I also invited Andrew Sullivan of Oracle/DYN to be on our call, as he has been following these ICANN discussions for many months, and previously briefed us on what was happening.

I should note that I have been participating in an ICANN policy committee GNSO-RDS-PDP-Drafting Team 3 to explain the need for CAs to have continuing access to WhoIs data, and I believe that point of view was included in their report.  Unfortunately, it turns out that Drafting Team 3 is working on part of a long term plan for data access and the Team’s recommendations were not received or considered by the ICANN group that is drafting the Interim Plan – so we need to make the case again.  My basic suggestion was that ICANN should use the list of trusted roots/CAs in CCADB, https://ccadb.org/resources, and instruct registries/registrars to give the CAs on that list continuing access to registration data via whitelist (and then let the CAs themselves sort out how they comply with GDPR rules, which for most will not apply to the majority of their certificate customers who are either outside the EU or not natural persons).

Finally – I include a link to a recent article on this situation.  Note:  I am NOT endorsing the point of view in the article, but it provides a lot of information and may be useful to members.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/public/attachments/20180405/2479a9c0/attachment-0003.html>

More information about the Public mailing list