[Servercert-wg] Discussion Period Begins - Ballot SC-077: Update WebTrust Audit name in Section 8.4 and References
Clint Wilson
clintw at apple.com
Tue Aug 6 16:55:32 UTC 2024
Purpose of Ballot
CPA Canada has separated the audit criteria which map to the Network and Certificate System Security Requirements (NCSSRs) from the audit criteria which map to the TLS Baseline Requirements (TBRs). As a result, the requirements in Section 8.4 are out of date for audits which use the updated/separated audit criteria. However, we also need to ensure the combined audit criteria are able to be used until fully deprecated by CPA Canada and/or Root Programs stop accepting them.
This ballot modifies Section 8.4 to allow for a CA to be audited against either:
WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security; or
WebTrust Principles and Criteria for Certification Authorities – SSL Baseline AND WebTrust Principles and Criteria for Certification Authorities – Network Security
Motion
The following motion has been proposed by Clint Wilson (Apple) and endorsed by Dimitris Zacharopoulos (HARICA) and Trevoli Ponds-White (Amazon)
You can view and comment on the Github pull request representing this ballot here <https://github.com/cabforum/servercert/pull/514/files>.
Motion Begins
MODIFY the "Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates" ("TLS Baseline Requirements") based on Version 2.0.5 as specified in the following redline:
https://github.com/cabforum/servercert/compare/20af1b271f2b689344ae353d3e78dc6b772199db...a9d3e3b6e514cf8b4d44ace625a447108c04a91c
Motion Ends
This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows:
Discussion (at least 7 days)
Start time: August 6, 2024 17:00 UTC
End time: on or after August 13, 2024 17:00 UTC
Vote for approval (7 days)
Start time: TBD
End time: TBD
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/servercert-wg/attachments/20240806/e0eb191a/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3621 bytes
Desc: not available
URL: <http://lists.cabforum.org/pipermail/servercert-wg/attachments/20240806/e0eb191a/attachment.p7s>
More information about the Servercert-wg
mailing list