← CABF Ballot Browser
Ballot-169 passed

Ballot 169 – Revised Validation Requirements

Server Certificate Working Group

Key dates

Effective date
01 Mar 2017 9 years ago

Resources

AI Summary

Generated 2026-06-23 21:44 UTC

Ballot overview

  • Ballot 169 revised the Baseline Requirements domain validation rules.
  • The stated purpose was to replace the prior open-ended domain validation method with a specific list of approved methods and to tighten and clarify existing methods.
  • The ballot page says voting ended and the ballot passed unanimously.

What changed

  • Section 3.2.2.4 was replaced with a new structure for validation of domain authorization or control.
  • The new text says the CA must confirm, as of certificate issuance, that each FQDN in the certificate has been validated by the CA or a Delegated Third Party using at least one approved method.
  • The ballot adds or clarifies definitions including Authorization Domain Name, Authorized Port, Base Domain Name, Domain Contact, Random Value, Request Token, Required Website Content, and Test Certificate.
  • The approved validation methods include:
    • validating the applicant as a domain contact
    • email, fax, SMS, or postal mail to the domain contact
    • phone contact with the domain contact
    • constructed email to the domain contact
    • domain authorization document
    • agreed-upon change to website
    • DNS change
    • IP address
    • test certificate

Effective date and transition

  • The ballot states that prior to 1 March 2017, CAs may use either the pre-ballot domain validation methods, the methods in this ballot, or both.
  • Effective 1 March 2017, CAs may use only the domain validation methods specified in this ballot, as later amended.

Outcome

  • The ballot passed unanimously.
  • The page states the effective date is March 1, 2017.
Model: gpt-5.4-mini Confidence: 0.99 Result: passed
Effective date
2017-03-01
Applicability and conditions

2017-03-01 — From this date forward, CAs may use only the domain validation methods specified in this ballot, as later amended All CAs transitioning from the prior BR 3.2.2.4 domain validation methods to the revised methods in Ballot 169

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Jeremy Rowley of DigiCert and endorsed by Tim Hollebeek of Trustwave and Doug Beattie of GlobalSign:

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot 169 – Revised Validation RequirementsBallot 169 – Revised Validation RequirementsVoting on Ballot 169, Revised Validation Requirements, has ended. Here are the results:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action