← CABF Ballot Browser
CSC-11
passed
Ballot CSC-11 – Update to log data retention requirements
Code Signing Certificate Working Group
Key dates
- Effective date
- 03 Nov 2021 4 years ago
- Voting opened
- 03 Nov 2021 4 years ago
Resources
AI Summary
Ballot overview
- Ballot CSC-11 updates log data retention requirements in the Baseline Requirements for the Issuance and Management of Publicly-Trusted Code Signing Certificates v2.5.
- The motion was proposed by Ian McMillan of Microsoft and endorsed by Dimitris Zacharopoulos of HARICA and Bruce Morton of Entrust.
What changes
- Removes references to the SSL/TLS Baseline Requirements from section 15 Data Records.
- Adds section 15.1 Types of Events Recorded, describing requirements for CAs and Third Party Delegates and removing Signing Services.
- Adds section 15.2 Timestamp Authority Data Records.
- Clarifies section 15.1 item 4(f) for security event logging on Timestamp Authority servers.
- Revises section 15.1 item 4(d) so security event logging no longer includes hardware failures.
- Adds section 15.3 Data Retention Period for Audit Logs.
- Revises section 15.2 to stop referencing Baseline Requirements section 5.4.3 and to define a specific retention period of at least 2 years for CA, subscriber certificate, Timestamp Authority, and security event data records.
Outcome
- The ballot passed.
- The review period ended and no exclusion notices were filed.
- The final documents were available with an effective date of 2021-11-03.
Compliance timing
- The effective date for the ballot changes is 2021-11-03.
- Effective date
- 2021-11-03
- Voting opened
- 2021-11-03
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Proposers
Ian McMillan of Microsoft, and endorsed by Dimitris Zacharopoulos (HARICA) and Bruce Morton (Entrust).
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot CSC-11 – Update to log data retention requirementsBallot CSC-11 – Update to log data retention requirementsResults of IPR Review (Mailing list post is available here.)
View on cabforum.org →
Last fetched 15 hours ago