← CABF Ballot Browser
Ballot-118 passed

Ballot 118 – SHA-1 Sunset (passed)

Server Certificate Working Group

Key dates

Effective date
01 Jan 2016 10 years ago
Voting opened
09 Oct 2014 11 years ago
Voting closed
16 Oct 2014 11 years ago
Discussion opened
02 Oct 2014 11 years ago
Discussion closed
09 Oct 2014 11 years ago

AI Summary

Generated 2026-06-23 21:34 UTC

Ballot overview

  • Ballot 118, SHA-1 Sunset, passed.
  • The ballot was in the Server Certificate Working Group.
  • Voting closed on 16 October 2014.
  • The review period ran from 2 October 2014 at 2200 UTC to 9 October 2014 at 2200 UTC, and voting closed at 2200 UTC on Thursday, 16 October 2014.

What the ballot changed

  • The motion added a new Baseline Requirements section 9.4.2, SHA-1 Validity Period.
  • Effective 1 January 2016, CAs must not issue any new Subscriber certificates or Subordinate CA certificates using the SHA-1 hash algorithm.
  • CAs may continue to sign certificates to verify OCSP responses using SHA1 until 1 January 2017.
  • The section does not apply to Root CA or CA cross certificates.
  • CAs may continue to use their existing SHA-1 Root Certificates.
  • SHA-2 Subscriber certificates should not chain up to a SHA-1 Subordinate CA Certificate.
  • Effective 16 January 2015, CAs should not issue Subscriber Certificates using SHA-1 with an expiry date greater than 1 January 2017.
  • The ballot also amended Appendix A notes so that SHA-1 may be used with RSA keys in accordance with section 9.4.2.

Adoption and voting result

  • The chair received yes votes from the listed voting members, no votes from SECOM Trust Systems, and there were no abstentions.
  • Therefore, Ballot 118 passed.

Compliance timing

  • The main compliance date is 1 January 2016 for the prohibition on issuing new SHA-1 Subscriber certificates and Subordinate CA certificates.
  • A separate earlier date, 16 January 2015, applies to the recommendation not to issue SHA-1 Subscriber Certificates with expiry dates beyond 1 January 2017.
  • OCSP signing with SHA1 was allowed until 1 January 2017.
  • The section does not apply to Root CA or CA cross certificates.
Model: gpt-5.4-mini Confidence: 0.98 Result: passed
Effective date
2016-01-01
Voting opened
2014-10-09
Voting closed
2014-10-16
Discussion opened
2014-10-02
Discussion closed
2014-10-09
Applicability and conditions

2015-01-16 — CAs should not issue Subscriber Certificates utilizing SHA-1 with an expiry date greater than 1 January 2017 Subscriber Certificates using SHA-1

2017-01-01 — CAs may continue to sign certificates to verify OCSP responses using SHA1 until this date OCSP response signing using SHA1

2016-01-01 — CAs must not issue these certificates using the SHA-1 hash algorithm New Subscriber certificates and Subordinate CA certificates using SHA-1

2016-01-01 — The section does not apply to Root CA or CA cross certificates; existing SHA-1 Root Certificates may continue to be used Section 9.4.2 applicability

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot 118 – SHA-1 Sunset (passed)Ballot 118 – SHA-1 Sunset (passed)Voting on Ballot 118 – SHA-1 Sunset closed on 16 October 2014.

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action