← CABF Ballot Browser
Ballot-164 passed

Ballot 164 – Certificate Serial Number Entropy

Server Certificate Working Group

Key dates

Effective date
30 Sep 2016 9 years ago
Voting opened
01 Jul 2016 9 years ago
Voting closed
08 Jul 2016 9 years ago
Discussion opened
31 Mar 2016 10 years ago
Discussion closed
01 Jul 2016 9 years ago

Resources

AI Summary

Generated 2026-06-23 21:33 UTC

Ballot overview

  • Ballot 164, Certificate Serial Number Entropy, was proposed by Jacob Hoffman-Andrews of Let’s Encrypt and endorsed by Ben Wilson of DigiCert and Tim Hollebeek of Trustwave.
  • The ballot says it makes random serial-number generation a required best practice, replaces entropy with CSPRNG for clarity and auditability, and clarifies that the serial number must be positive.
  • The ballot page states that voting has closed and the ballot passes.

Requirements added to the Baseline Requirements

  • Add a definition for CSPRNG in Section 1.6.1.
  • Replace the existing serial-number guidance in Section 7.1 with a requirement that, effective September 30, 2016, CAs shall generate certificate serial numbers greater than zero containing at least 64 bits of output from a CSPRNG.

Timing stated in the ballot

  • The review period was to commence immediately and close at 2200 UTC on 1 July 2016.
  • The voting period was to start immediately after the review period and close at 2200 UTC on 8 July 2016.

Context given in the statement of intent

  • The ballot cites MD5 collision research and explains that random bits in certificate serial numbers help mitigate collision attacks.
  • It says the Baseline Requirements had already encouraged random serial numbers and that this ballot makes that practice required.
  • It also says the change is intended to make the Web PKI more robust against future weaknesses in hash functions.
Model: gpt-5.4-mini Confidence: 0.98 Result: passed
Effective date
2016-09-30
Voting opened
2016-07-01
Voting closed
2016-07-08
Discussion closed
2016-07-01
Applicability and conditions

2016-09-30 — CAs must generate certificate serial numbers greater than zero containing at least 64 bits of output from a CSPRNG All CAs subject to the Baseline Requirements

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Jacob Hoffman-Andrews of Let’s Encrypt and endorsed by Ben Wilson of DigiCert and Tim Hollebeek of Trustwave:

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot 164 – Certificate Serial Number EntropyBallot 164 – Certificate Serial Number EntropyVoting on Ballot 164, “Certificate Serial Number Entropy” has now closed. The results are as follow:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action