← CABF Ballot Browser
Ballot-164 passed

Ballot 164 – Certificate Serial Number Entropy

Server Certificate Working Group

Key dates

Effective date
30 Sep 2016 9 years ago
Voting opened
01 Jul 2016 10 years ago
Voting closed
08 Jul 2016 10 years ago
Discussion opened
31 Mar 2016 10 years ago
Discussion closed
01 Jul 2016 10 years ago

Resources

AI Summary

Generated 2026-06-23 21:33 UTC

Ballot overview

  • Ballot 164, Certificate Serial Number Entropy, was proposed by Jacob Hoffman-Andrews of Let’s Encrypt and endorsed by Ben Wilson of DigiCert and Tim Hollebeek of Trustwave.
  • The ballot says it makes random serial-number generation a required best practice, replaces entropy with CSPRNG for clarity and auditability, and clarifies that the serial number must be positive.
  • The ballot page states that voting has closed and the ballot passes.

Requirements added to the Baseline Requirements

  • Add a definition for CSPRNG in Section 1.6.1.
  • Replace the existing serial-number guidance in Section 7.1 with a requirement that, effective September 30, 2016, CAs shall generate certificate serial numbers greater than zero containing at least 64 bits of output from a CSPRNG.

Timing stated in the ballot

  • The review period was to commence immediately and close at 2200 UTC on 1 July 2016.
  • The voting period was to start immediately after the review period and close at 2200 UTC on 8 July 2016.

Context given in the statement of intent

  • The ballot cites MD5 collision research and explains that random bits in certificate serial numbers help mitigate collision attacks.
  • It says the Baseline Requirements had already encouraged random serial numbers and that this ballot makes that practice required.
  • It also says the change is intended to make the Web PKI more robust against future weaknesses in hash functions.
Model: gpt-5.4-mini Confidence: 0.98 Result: passed
Effective date
2016-09-30
Voting opened
2016-07-01
Voting closed
2016-07-08
Discussion closed
2016-07-01
Applicability and conditions

2016-09-30 — CAs must generate certificate serial numbers greater than zero containing at least 64 bits of output from a CSPRNG All CAs subject to the Baseline Requirements

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Jacob Hoffman-Andrews of Let’s Encrypt and endorsed by Ben Wilson of DigiCert and Tim Hollebeek of Trustwave:

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot 164 – Certificate Serial Number EntropyBallot 164 – Certificate Serial Number EntropyVoting on Ballot 164, “Certificate Serial Number Entropy” has now closed. The results are as follow:

View on cabforum.org → Last fetched 1 month ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action