[cabfpub] Draft Agenda for CA/Browser Teleconference of Jan. 25, 2018 at 11 am Eastern

Virginia Fournier vfournier at apple.com
Tue Jan 23 02:10:11 UTC 2018


Would it be possible to move the Governance WG to a little later in the agenda in case I’m running a few minutes late?  Thanks.


Best regards,

Virginia Fournier
Senior Standards Counsel
 Apple Inc.
☏ 669-227-9595
✉︎ vmf at apple.com <mailto:vmf at apple.com>






On Jan 22, 2018, at 6:03 PM, public-request at cabforum.org wrote:

Send Public mailing list submissions to
	public at cabforum.org

To subscribe or unsubscribe via the World Wide Web, visit
	https://cabforum.org/mailman/listinfo/public
or, via email, send a message with subject or body 'help' to
	public-request at cabforum.org

You can reach the person managing the list at
	public-owner at cabforum.org

When replying, please edit your Subject line so it is more specific
than "Re: Contents of Public digest..."


Today's Topics:

  1. Re: Revocation as a domain owner (Josh Aas)
  2. Re: Draft Agenda for CA/Browser Teleconference of Jan. 25,
     2018 at 11 am Eastern (Ryan Sleevi)


----------------------------------------------------------------------

Message: 1
Date: Mon, 22 Jan 2018 20:03:11 -0600
From: Josh Aas <josh at letsencrypt.org>
To: Wayne Thayer <wthayer at mozilla.com>,  "CA/Browser Forum Public
	Discussion List" <public at cabforum.org>
Subject: Re: [cabfpub] Revocation as a domain owner
Message-ID:
	<CAJH38kGiAqa2mdND1BaJiA3Py83VR5jw4-DMhiOv=_STpQcRvQ at mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"

It can be very difficult for a CA to determine who is the legal owner
of a domain, thus taking action (e.g. revoking) on that basis creates
significant liability. The BRs should not introduce additional rules
requiring such determinations.

A couple of ideas that don't depend on determining legal ownership:

1) Let anyone revoke a certificate if they can demonstrate control of
the certificate's private key. Let's Encrypt does this, it has worked
out well.

2) Allow people to revoke certificates if they can re-validate for all
of the domains in the cert. The Let's Encrypt API also allows this.

Both of these methods are clearly defined and can be fully automated.

On Wed, Jan 3, 2018 at 10:59 AM, Wayne Thayer via Public
<public at cabforum.org> wrote:
> Matthias,
> 
> I think you've raised a valid point. I'm working on ballot 213 "Revocation
> Timeline Extension" that makes changes to this section of the BRs, and I
> will draft some language to attempt to address this. If you have any ideas
> on how this requirement should be stated, please let me know.
> 
> Thanks,
> 
> Wayne
>> 
>> 
>> I can't propose a ballot as I'm not a CAB member but adding the
>> requirement of having to revoke certificates on the domain owner's request
>> should probably be considered.
>> 
>> 
> 
> 
> 
> _______________________________________________
> Public mailing list
> Public at cabforum.org
> https://cabforum.org/mailman/listinfo/public
> 



-- 
Josh Aas
Executive Director
Internet Security Research Group
Let's Encrypt: A Free, Automated, and Open CA


------------------------------

Message: 2
Date: Mon, 22 Jan 2018 21:03:05 -0500
From: Ryan Sleevi <sleevi at google.com>
To: Kirk Hall <Kirk.Hall at entrustdatacard.com>,  "CA/Browser Forum
	Public Discussion List" <public at cabforum.org>
Subject: Re: [cabfpub] Draft Agenda for CA/Browser Teleconference of
	Jan. 25, 2018 at 11 am Eastern
Message-ID:
	<CACvaWvbAUSN+f=8XkTrw175qJPgMDepxytgiOMoXRKcj+LBqDw at mail.gmail.com>
Content-Type: text/plain; charset="utf-8"

Hi Kirk,

As a possible item, or a consideration in advance, could you make sure the
document status on https://cabforum.org/baseline-requirements-documents/ is
up to date? Your current status appears up to date, but our webpage seems a
bit behind.

Similarly, https://cabforum.org/bylaws/ is not updated with the result of
Ballot 216 - I believe we should have a Version 1.8 of the Bylaws, based on
that?

I note your meeting schedule in the footnotes still lists "June - London".
Is it correct that June 5-7 are the finalized dates for London?

On Mon, Jan 22, 2018 at 8:53 PM, Kirk Hall via Public <public at cabforum.org>
wrote:

> Here is the draft agenda for our teleconference this *Thursday, January
> 25, 2018 at 11:00 am Eastern Time*.  Please suggest any additional topics
> you would like to discuss.
> 
> 
> 
> *Time*
> 
> *Start (ET)*
> 
> *Stop*
> 
> *Item*
> 
> *Description*
> 
> *Presenters*
> 
> *(Thursday) January 25, 2018*
> 
> 0:02
> 
> 11:00
> 
> 11:02
> 
> 1.
> 
> Roll Call
> 
> Kirk
> 
> 0:01
> 
> 11:02
> 
> 11:03
> 
> 2.
> 
> Read Antitrust Statement
> 
> Robin
> 
> 0:01
> 
> 11:03
> 
> 11:04
> 
> 3.
> 
> Review Agenda
> 
> Kirk
> 
> 0:02
> 
> 11:04
> 
> 11:06
> 
> 4.
> 
> Approval of Minutes from teleconference of January 11, 2017
> 
> Emailed and corrected by Kirk Jan. 11
> 
> 0:10
> 
> 11:06
> 
> 11:16
> 
> 5.
> 
> Governance Change Working Group
> 
> Virginia, Dean, Ben
> 
> 0:05
> 
> 11:16
> 
> 11:21
> 
> 6.
> 
> Policy Review Working Group update
> 
> Ben, Dimitris
> 
> 0:05
> 
> 11:21
> 
> 11:26
> 
> 7.
> 
> Network Security Working Group update
> 
> Ben
> 
> 0:10
> 
> 11:26
> 
> 11:36
> 
> 8.
> 
> Validation Working Group update
> 
> Tim
> 
> 0:05
> 
> 11:36
> 
> 11:41
> 
> 9.
> 
> Ballot Status - Discussion of ballots (See Ballot Status table at end of
> Agenda)
> 
> All
> 
> 0:04
> 
> 11:41
> 
> 11:45
> 
> 10.
> 
> Logistics for March F2F meeting ? Amazon, Herndon, VA
> 
> Peter
> 
> 0:05
> 
> 11:45
> 
> 11:50
> 
> 11.
> 
> Possible Topics for March F2F meeting
> 
> All
> 
> 0:05
> 
> 11:50
> 
> 11:55
> 
> 12.
> 
> Any Other Business
> 
> Kirk
> 
> 0:01
> 
> 11:55
> 
> 11:56
> 
> 13.
> 
> Next call: Feb. 8, 2018 at 11:00 am Eastern Time
> 
> Kirk
> 
> 0:01
> 
> 11:56
> 
> 
> 
> 14.
> 
> Adjourn
> 
> Kirk
> 
> 
> 
> *CURRENT STATUS OF BALLOTS (as of Jan. 22, 2018)*
> 
> 
> 
> 1.       *Ballots in Voting Period*
> 
> None
> 
> 
> 
> 2.       *Ballots in Discussion Period*
> 
> a.       Ballot 218 ?  Remove validation methods #1 and #5 (Tim) ?
> revised Jan. 22
> 
> 
> 
> 3.       *Ballots in Review Period*
> 
> a.       Ballot 217 ? Sunset RFC 2527 (Ryan) ? ends Jan. 29
> 
> 
> 
> *4.       **Draft Ballots Under Consideration*
> 
> a.       Ballot 206 - Changes to IPR Policy and Bylaws re Formation of
> Working Groups
> <https://www.cabforum.org/wiki/206%20-%20Changes%20to%20IPR%20Policy%20and%20Bylaws%20re%20Formation%20of%20Working%20Groups>
> (Virginia)
> 
> 
> 
> 
> 
> *F2F Meeting Schedule: *
> 
> 2018: March 6-8 - Herndon, VA (Amazon), June ? London (Comodo), October ?
> Shanghai (CFCA)
> 
> 2019: Feb-March ? Cupertino, CA (Apple), June ? Greece (HARICA,
> tentative), October ? Guangzhou (GDCA)
> 
> 2020: Feb-March [Open], June ? Minneapolis (OATI), October [Open]
> 
> 
> 
> 
> 
> 
> 
> _______________________________________________
> Public mailing list
> Public at cabforum.org
> https://cabforum.org/mailman/listinfo/public
> 
> 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cabforum.org/pipermail/public/attachments/20180122/0c00c6cc/attachment.html>

------------------------------

Subject: Digest Footer

_______________________________________________
Public mailing list
Public at cabforum.org
https://cabforum.org/mailman/listinfo/public


------------------------------

End of Public Digest, Vol 69, Issue 99
**************************************

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/public/attachments/20180122/3f0b6a67/attachment-0003.html>


More information about the Public mailing list