[Servercert-wg] [EXTERNAL] VOTING Period Begins - Ballot SC-077: Update WebTrust Audit name in Section 8.4 and References

Bruce Morton Bruce.Morton at entrust.com
Tue Aug 13 19:52:32 UTC 2024


Entrust votes Yes to ballot SC-077.


Bruce.

From: Servercert-wg <servercert-wg-bounces at cabforum.org> On Behalf Of Bruce Morton via Servercert-wg
Sent: Tuesday, August 13, 2024 2:34 PM
To: Clint Wilson <clintw at apple.com>; CA/B Forum Server Certificate WG Public Discussion List <servercert-wg at cabforum.org>
Subject: Re: [Servercert-wg] [EXTERNAL] VOTING Period Begins - Ballot SC-077: Update WebTrust Audit name in Section 8.4 and References

Entrust votes Yes to ballot SC-007. Bruce. From: Servercert-wg <servercert-wg-bounces@ cabforum. org> On Behalf Of Clint Wilson via Servercert-wg Sent: Tuesday, August 13, 2024 1: 05 PM To: ServerCert CA/BF <servercert-wg@ cabforum. org>

Entrust votes Yes to ballot SC-007.


Bruce.

From: Servercert-wg <servercert-wg-bounces at cabforum.org<mailto:servercert-wg-bounces at cabforum.org>> On Behalf Of Clint Wilson via Servercert-wg
Sent: Tuesday, August 13, 2024 1:05 PM
To: ServerCert CA/BF <servercert-wg at cabforum.org<mailto:servercert-wg at cabforum.org>>
Subject: [EXTERNAL] [Servercert-wg] VOTING Period Begins - Ballot SC-077: Update WebTrust Audit name in Section 8.4 and References

Purpose of Ballot

CPA Canada has separated the audit criteria which map to the Network and Certificate System Security Requirements (NCSSRs) from the audit criteria which map to the TLS Baseline Requirements (TBRs). As a result, the requirements in Section 8.4 are out of date for audits which use the updated/separated audit criteria. However, we also need to ensure the combined audit criteria are able to be used until fully deprecated by CPA Canada and/or Root Programs stop accepting them.

This ballot modifies Section 8.4 to allow for a CA to be audited against either:

  *   WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security; or
  *   WebTrust Principles and Criteria for Certification Authorities – SSL Baseline AND WebTrust Principles and Criteria for Certification Authorities – Network Security

Motion

The following motion has been proposed by Clint Wilson (Apple) and endorsed by Dimitris Zacharopoulos (HARICA) and Trevoli Ponds-White (Amazon)

You can view and comment on the Github pull request representing this ballot here<https://urldefense.com/v3/__https:/github.com/cabforum/servercert/pull/514/files__;!!FJ-Y8qCqXTj2!bzoJTDo1gSGYPLMzsie3divH8jpW88qahujxgnfDCdpbEsqEcFm5VqY5KnUwzO41Y3NMpo1ZBDDH3UdC7393exObqVEtfQ$>.

Motion Begins

MODIFY the "Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates" ("TLS Baseline Requirements") based on Version 2.0.5 as specified in the following redline:

  *   https://github.com/cabforum/servercert/compare/20af1b271f2b689344ae353d3e78dc6b772199db...a9d3e3b6e514cf8b4d44ace625a447108c04a91c<https://urldefense.com/v3/__https:/github.com/cabforum/servercert/compare/20af1b271f2b689344ae353d3e78dc6b772199db...a9d3e3b6e514cf8b4d44ace625a447108c04a91c__;!!FJ-Y8qCqXTj2!bzoJTDo1gSGYPLMzsie3divH8jpW88qahujxgnfDCdpbEsqEcFm5VqY5KnUwzO41Y3NMpo1ZBDDH3UdC7393exOOqG-egg$>

Motion Ends

This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows:

Discussion (at least 7 days)

  *   Start time: August 6, 2024 17:00 UTC
  *   End time: on or after August 13, 2024 17:00 UTC

Vote for approval (7 days)

  *   Start time: August 13, 2024 17:00 UTC
  *   End time: August 20, 2024 17:00 UTC
Any email and files/attachments transmitted with it are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/servercert-wg/attachments/20240813/4a8ba007/attachment-0001.html>


More information about the Servercert-wg mailing list