[Servercert-wg] TURKTRUST Membership Challenge

Dimitris Zacharopoulos (HARICA) dzacharo at harica.gr
Mon Mar 2 23:36:06 MST 2020



On 2020-02-28 3:01 π.μ., Wayne Thayer via Servercert-wg wrote:
> TURKTRUST is a Certificate Issuer Forum Member that has voted on 
> recent SCWG ballots. However, TURKTRUST's TLS certificates are no 
> longer treated as valid by most browsers, leading me to suspect that 
> TURKTRUST may no longer be eligible to participate as a voting member 
> of the SCWG or Forum. In private correspondence with a TURKTRUST 
> representative, I have not been able to obtain evidence that TURKTRUST 
> remains eligible for membership. Therefore, I am sending this email in 
> accordance with the SCWG charter, which states:
>
>     A Certificate or Root Certificate Issuer Member’s membership may
>     be suspended if any of the following become true:
>
>      *
>
>         it fails to perform and disclose its membership-qualifying
>         audit and fifteen (15) months have elapsed since the end of
>         the audit period of its last successful membership-qualifying
>         audit; or
>
>      *
>
>         its membership-qualifying audit is revoked, rescinded or
>         withdrawn; or
>
>      *
>
>         fifteen (15) months have elapsed since the end of the audit
>         period of its last membership-qualifying audit; or
>
>      *
>
>         it is no longer the case that its currently-issued
>         certificates are treated as valid by at least one (1)
>         Certificate Consumer Member of the Server Certificate Working
>         Group.
>
>     Any Member who believes any of the above circumstances is true of
>     any other Member, that Member may report it on the SCWG Public
>     Mail List. The Chair will then investigate, including asking the
>     reported Member for an explanation or appropriate documentation.
>     If evidence of continued qualification for membership is not
>     forthcoming from the reported Member within five (5) working days,
>     the Chair will announce that such Member is suspended, such
>     announcement to include the clause(s) from the above list under
>     which the suspension has been made.
>
>
> Dimitris, I suspect that TURKTRUST no longer meets the last 
> requirement above. in your role as SCWG Chair, please investigate.

I was able to confirm that TURKTRUST no longer meets the SCWG membership 
criteria. More specifically:

 1. The audit follows a scheme that is incompatible with the SCWG charter
 2. Audit period is more than 27 months
 3. The CA is not currently issuing certificates as valid by at least
    one Certificate Consumer Member of the SCWG.

I had a discussion with TURKTRUST's representative and they wish to 
switch their status to "Interested Party". Since the IPR agreement is 
already signed, I don't think it needs to be re-signed.

Unless there are objections, we will proceed with the necessary changes.


Thank you,
Dimitris.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cabforum.org/pipermail/servercert-wg/attachments/20200303/ebf38854/attachment.html>


More information about the Servercert-wg mailing list