[Servercert-wg] [EXTERNAL] VOTING BEGINS: Ballot SC39v3:
Mike Reilly (SECURITY)
Mike.Reilly at microsoft.com
Tue Feb 2 16:30:07 UTC 2021
Microsoft votes yes. Thanks, Mike
From: Servercert-wg <servercert-wg-bounces at cabforum.org> On Behalf Of Neil Dunbar via Servercert-wg
Sent: Tuesday, February 2, 2021 6:16 AM
To: CA/B Forum Server Certificate WG Public Discussion List <servercert-wg at cabforum.org>
Subject: [EXTERNAL] [Servercert-wg] VOTING BEGINS: Ballot SC39v3:
Colleagues,
This begins the voting period for ballot SC39v3: Definition of Critical Vulnerability.
The following motion has been proposed by Neil Dunbar of TrustCor and endorsed by Ben Wilson (Mozilla) and Corey Bonnell (DigiCert).
-- MOTION BEGINS --
This ballot modifies the "Network and Certificate System Security Requirements" based on Version 1.5.
Under the section "Definitions":
Remove the current definition:
Critical Vulnerability: A system vulnerability that has a CVSS score of 7.0 or higher according to the NVD or an equivalent to such CVSS rating (see http://nvd.nist.gov/home.cfm<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fnvd.nist.gov%2Fhome.cfm&data=04%7C01%7CMike.reilly%40microsoft.com%7C5df72de5fede4f62101f08d8c7850b8b%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637478721538729818%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=ckebDzZjgaTppeSzphkDkcHSNpd8Zey6xe483khXUOI%3D&reserved=0>), or as otherwise designated as a Critical Vulnerability by the CA or the CA/Browser Forum.
Insert a new definition:
Critical Vulnerability: A system vulnerability that has a CVSS v2.0 score of 7.0 or higher according to the NVD or an equivalent to such CVSS rating (see https://nvd.nist.gov/vuln-metrics/cvss<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln-metrics%2Fcvss&data=04%7C01%7CMike.reilly%40microsoft.com%7C5df72de5fede4f62101f08d8c7850b8b%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637478721538729818%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=2xlyO1mOazBieSwJegm6dr7uilLeSXZT1EJwKtjpQvM%3D&reserved=0>), or as otherwise designated as a Critical Vulnerability by the CA or the CA/Browser Forum.
-- MOTION ENDS --
* WARNING *: USE AT YOUR OWN RISK. THE REDLINE BELOW IS NOT THE OFFICIAL VERSION OF THE CHANGES (CABF Bylaws, Section 2.4(a)):
A comparison of the changes can be found at:
https://github.com/cabforum/servercert/compare/2b7720f...neildunbar:61fd381?diff=split<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fcabforum%2Fservercert%2Fcompare%2F2b7720f...neildunbar%3A61fd381%3Fdiff%3Dsplit&data=04%7C01%7CMike.reilly%40microsoft.com%7C5df72de5fede4f62101f08d8c7850b8b%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637478721538739811%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=3dN0T8L6D0p9oMknJXrZVk%2FkD6KzyrBH9CCa8IDzDzY%3D&reserved=0>
This ballot proposes one Final Maintenance Guideline.
The procedure for approval of this ballot is as follows:
Vote for approval (7 days)
Start Time: 2020-02-02 1700 UTC
End Time: 2020-02-09 1700 UTC
Regards,
Neil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/servercert-wg/attachments/20210202/358296fe/attachment.html>
More information about the Servercert-wg
mailing list