Ballot 83 – Adopt Network and Certificate System Security Requirements
Server Certificate Working Group
Key dates
- Effective date
- 01 Jan 2013 13 years ago
- Voting opened
- 27 Jul 2012 13 years ago
- Voting closed
- 03 Aug 2012 13 years ago
- Discussion opened
- 20 Jul 2012 13 years ago
- Discussion closed
- 27 Jul 2012 13 years ago
Resources
AI Summary
Ballot overview
- Ballot 83 adopts the Network and Certificate System Security Requirements as Version 1.0.
- The ballot states that it passes with 69% of CAs and 66% of Browsers in favor.
- The motion was endorsed by Ben Wilson, Bill Madell, and Rick Andrews.
Scope and applicability
- The requirements apply to all publicly trusted Certification Authorities.
- The text says CAs and Delegated Third Parties should be audited for conformity as soon as the requirements have been incorporated as mandatory requirements in the relevant root embedding program.
- The ballot also says the requirements are intended to be incorporated into WebTrust, ETSI 101 456, and ETSI TS 102 042 criteria.
Security requirements adopted
- The requirements cover network segmentation, secure zones, high security zones, access control, trusted roles, logging, monitoring, alerting, vulnerability detection, and patch management.
- They require controls such as multi-factor authentication, password and account protections, weekly configuration review, log review, vulnerability scans, penetration tests, and critical vulnerability response within 96 hours.
- The document defines terms including Certificate Systems, Delegated Third Party, Issuing System, Root CA System, Secure Zone, High Security Zone, and Critical Vulnerability.
Timing and implementation
- The ballot page states the review period runs from 20 July 2012 at 2100 UTC to 27 July 2012 at 2100 UTC, and the voting period runs from immediately thereafter until 3 Aug 2012 at 2100 UTC.
- The motion states an Effective Date of 1 January 2013.
- The linked PDF is labeled Forum Guideline Effective on 1/1/2013.
Result
- The ballot passed.
- The evidence does not mention any exclusion notices.
- Effective date
- 2013-01-01
- Voting opened
- 2012-07-27
- Voting closed
- 2012-08-03
- Discussion opened
- 2012-07-20
- Discussion closed
- 2012-07-27
2013-01-01 — CAs must comply with the Network and Certificate System Security Requirements All publicly trusted Certification Authorities; the text also says CAs and Delegated Third Parties should be audited for conformity as soon as the requirements are incorporated as mandatory requirements in the relevant root embedding program
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot 83 – Adopt Network and Certificate System Security RequirementsBallot 83 – Adopt Network and Certificate System Security RequirementsOn Ballot 83, there were “YES” votes from nine CAs and two Browsers. There were “NO” votes from four CAs and one Browser. Three CAs abstained.