← CABF Ballot Browser
Ballot-59
cancelled
Ballot 59 – Public Review of v. 30b of the Baseline Requirements
Server Certificate Working Group
AI Summary
Ballot overview
- Ballot 59 was a public review of v. 30b of the Baseline Requirements.
- The ballot page states that this ballot was withdrawn.
What the ballot would have changed
- It would have maintained consistency between the S/MIME Baseline Requirements and the TLS Baseline Requirements with changes introduced by Ballots SC096 and SC097.
- It would have created a carve-out for DNSSEC from the logging requirements, stating those requirements are not in scope.
- It would have clarified that, for audit purposes, change management logging can confirm whether the appropriate controls are in effect.
- It would have sunset all remaining use of SHA-1 signatures in Certificates and CRLs.
- It noted that most uses of SHA-1 signatures were already deprecated by SC097.
- It would have required revocation of all unexpired Subordinate CA Certificates issuing S/MIME containing the SHA-1 signature algorithm.
- It stated that the proposal did not prohibit use of SHA-1 to generate issuerKeyHash or issuerNameHash values as required by RFC 5019.
- It included minor formatting corrections.
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot 59 – Public Review of v. 30b of the Baseline RequirementsBallot 59 – Public Review of v. 30b of the Baseline RequirementsThis ballot was withdrawn.
View on cabforum.org →
Last fetched 16 hours ago