← CABF Ballot Browser
SC-020 failed

Ballot SC020: System Configuration Management

Server Certificate Working Group

Key dates

Voting opened
16 Mar 2020 6 years ago
Voting closed
23 Mar 2020 6 years ago
Discussion opened
09 Mar 2020 6 years ago
Discussion closed
16 Mar 2020 6 years ago

Resources

AI Summary

Generated 2026-06-23 21:41 UTC

Ballot overview

  • Ballot SC020: System Configuration Management in the Server Certificate Working Group.
  • The ballot failed.
  • It was intended to revise Section 1(h) of the Network and Certificate System Security Requirements.

Purpose and proposed changes

  • The ballot says Section 1(h) required CAs to review configurations of Issuing Systems, Certificate Management Systems, Security Support Systems, and Front-End / Internal-Support Systems on at least a weekly basis.
  • It cites feedback that weekly review almost always includes automated monitoring plus human review, and that systems are too complex for meaningful human review of configuration changes alone.
  • The proposal would replace review with a requirement to systematically enforce and monitor system configurations.
  • CAs would identify which configurations are security relevant based on a documented assessment.
  • Security-relevant configurations would need to be aligned with the CA’s security policies and standards.
  • Policy and standard violations would need to be detected within at most seven days.
  • Follow-up action would need to be instigated under the CA’s incident response procedures.
  • For systems operated offline and air-gapped, detection should occur at least every thirty days or when the system is powered on.
  • The ballot lists examples of security-relevant configurations, including user databases, administrative access channels, configuration management channels, network settings, host-local firewall, host-local IDP/IDS settings, package repositories and other update sources, and operating system logging service or its equivalent.

Approval schedule

  • Discussion period: 2020-03-09 17:00:00 UTC to 2020-03-16 17:00:00 UTC.
  • Vote period: 2020-03-16 17:00:00 UTC to 2020-03-23 17:00:00 UTC.
Model: gpt-5.4-mini Confidence: 0.99 Result: failed
Voting opened
2020-03-16
Voting closed
2020-03-23
Discussion opened
2020-03-09
Discussion closed
2020-03-16

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Neil Dunbar of Google Trust Services and endorsed by Tobias Josefowitz of OPERA and Dustin Hollenback of Microsoft.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC020: System Configuration ManagementBallot SC020: System Configuration ManagementThis ballot failed.

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action