← CABF Ballot Browser
Ballot-68
failed
Ballot 68- No Unknown Contents
Server Certificate Working Group
AI Summary
Ballot overview
- Ballot 68, No Unknown Contents, is identified on the CA/Browser Forum site as a ballot page.
- The page states that this ballot lacked two endorsers.
What the ballot says
- The ballot text says it maintains consistency between the S/MIME Baseline Requirements and the TLS Baseline Requirements with changes introduced by Ballots SC096 and SC097.
- It creates a carve-out for DNSSEC logging requirements, stating those requirements are not in scope.
- It says change management logging can confirm whether the appropriate controls are in effect for audit purposes.
- It sunsets all remaining use of SHA-1 signatures in Certificates and CRLs.
- It notes that most uses of SHA-1 signatures are already deprecated by SC097.
- It says all unexpired Subordinate CA Certificates issuing S/MIME containing the SHA-1 signature algorithm must be revoked.
- It states that the proposal does not prohibit use of SHA-1 to generate issuerKeyHash or issuerNameHash values as required by RFC 5019.
- It includes minor formatting corrections.
Dates
- No discussion, voting, IPR, or effective dates are provided in the supplied evidence.
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot 68- No Unknown ContentsBallot 68- No Unknown ContentsThis ballot lacked two (2) endorsers.
View on cabforum.org →
Last fetched 16 hours ago