← CABF Ballot Browser
SC-051 passed

Ballot SC051: Reduce and Clarify Audit Log and Records Archival Retention Requirements

Server Certificate Working Group

Key dates

Effective date
15 Apr 2022 4 years ago
Voting opened
18 Feb 2022 4 years ago
Voting closed
25 Feb 2022 4 years ago
IPR review ends
15 Apr 2022 4 years ago
Discussion opened
11 Feb 2022 4 years ago
Discussion closed
18 Feb 2022 4 years ago

Resources

AI Summary

Generated 2026-06-23 21:43 UTC

Ballot overview

  • Ballot SC051 is titled Reduce and Clarify Audit Log and Records Archival Retention Requirements.
  • It was proposed as a Final Maintenance Guideline.
  • The stated purpose was to consolidate and clarify audit log and records archival retention expectations and time-periods in section 5.5.2.
  • The ballot also aimed to reduce records archival retention to 2 years, clarify audit log retention, require archival of lifecycle event records, replace OCSP Entries with OCSP Responses, and explicitly apply retention expectations to delegated third parties.

Voting and approval

  • Certificate Issuers: 21 yes votes, 0 no votes, 0 abstentions.
  • Certificate Consumers: 5 yes votes, 0 no votes, 0 abstentions.
  • The bylaw voting requirements were MET for both Certificate Issuers and Certificate Consumers.
  • Quorum was MET.
  • No IP Rights issues were raised during the review period, which concluded 15 April 2022.
  • The ballot was incorporated into version 1.8.3 of the Baseline Requirements.

Main requirements introduced or changed

  • CAs and each Delegated Third Party must record events related to the security of their Certificate Systems, Certificate Management Systems, Root CA Systems, and Delegated Third Party Systems.
  • CAs and each Delegated Third Party must record events related to processing certificate requests and issuing certificates, including information generated, documentation received, time and date, and personnel involved.
  • The list of required recorded events includes certificate requests, renewals, re-key requests, revocation, approval and rejection of requests, cryptographic device lifecycle management events, generation of Certificate Revocation Lists, signing of OCSP Responses, and introduction or retirement of Certificate Profiles.
  • Log records must include the date and time of event, identity of the person making the journal record, and description of the event.
  • CAs and each Delegated Third Party must retain audit logs for at least 2 years.
  • Subscriber Certificate lifecycle management event records are retained after expiration of the Subscriber Certificate.
  • CAs and each Delegated Party must archive all audit logs.
  • CAs and each Delegated Party must archive documentation related to the security of their systems and documentation related to verification, issuance, and revocation of certificate requests and certificates.
  • Archived audit logs must be retained for at least 2 years from record creation timestamp, or as long as required under the audit-log retention rule, whichever is longer.
  • Archived documentation related to verification, issuance, and revocation must be retained for at least 2 years after the later of last reliance on the records or expiration of the Subscriber Certificates relying on them.

Scope and clarifications

  • The ballot clarifies that audit log retention and records archival expectations apply to delegated third parties.
  • It clarifies that OCSP Entries should be treated as OCSP Responses.
  • It formalizes incorporation of terms defined in the NCSSRs as also applying to the BRs.
Model: gpt-5.4-mini Confidence: 0.98 Result: passed
Effective date
2022-04-15
Voting opened
2022-02-18
Voting closed
2022-02-25
IPR review ends
2022-04-15
Discussion opened
2022-02-11
Discussion closed
2022-02-18
Applicability and conditions

2022-02-18 — Voting on the ballot begins Vote for approval period begins after the discussion period ends

2022-02-25 — Voting closes Vote for approval period ends

2022-04-15 — Ballot became incorporated into version 1.8.3 of the Baseline Requirements Review period concluded with no IP Rights issues raised

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Clint Wilson of Apple and endorsed by Trevoli Ponds-White of Amazon and Dustin Hollenback of Microsoft.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC051: Reduce and Clarify Audit Log and Records Archival Retention RequirementsBallot SC051: Reduce and Clarify Audit Log and Records Archival Retention RequirementsVoting Results Certificate Issuers 21 votes total, with no abstentions:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action