Ballot SC053: Sunset for SHA-1 OCSP Signing
Server Certificate Working Group
Key dates
- Effective date
- 01 Jun 2022 4 years ago
- Voting opened
- 17 Jan 2022 4 years ago
- Voting closed
- 24 Jan 2022 4 years ago
- Discussion opened
- 10 Jan 2022 4 years ago
- Discussion closed
- 17 Jan 2022 4 years ago
Resources
AI Summary
Ballot overview
- Ballot SC053, Sunset for SHA-1 OCSP Signing, was a Server Certificate Working Group ballot.
- Its purpose was to establish a sunset date prohibiting delegated OCSP signing with the SHA-1 hash algorithm.
- The ballot modified the Baseline Requirements based on Version 1.8.0 and was incorporated into Baseline Requirements version 1.8.2.
Voting and adoption
- Voting on ballot SC53 completed and the ballot passed.
- Certificate Issuers: 21 yes votes, 0 no votes, 0 abstentions.
- Certificate Consumers: 5 yes votes, 0 no votes, 0 abstentions.
- Bylaw requirements were met for Certificate Issuers, Certificate Consumers, and quorum.
- The ballot cleared the IP Rights Review period with no IP Rights issues raised by the community.
Requirement introduced
- CAs must not sign OCSP responses using the SHA-1 hash algorithm.
- For OCSP responses using the signatureAlgorithm of a BasicOCSPResponse, the producedAt field value of the ResponseData must be earlier than 2022-06-01 00:00:00 UTC.
Relevant dates
- Discussion: 2022-01-10 15:00:00 UTC to 2022-01-17 15:00:00 UTC.
- Vote for approval: 2022-01-17 15:00:00 UTC to 2022-01-24 15:00:00 UTC.
- The Baseline Requirements table lists 2022-06-01 as the date by which CAs must not sign OCSP responses using SHA-1.
- The linked BR 1.8.2 PDF shows the same requirement in the relevant dates table and the OCSP profile change.
- Effective date
- 2022-06-01
- Voting opened
- 2022-01-17
- Voting closed
- 2022-01-24
- Discussion opened
- 2022-01-10
- Discussion closed
- 2022-01-17
2022-06-01 — CAs must not sign OCSP responses using the SHA-1 hash algorithm; the producedAt field value of the ResponseData must be earlier than this date and time OCSP responses, including delegated OCSP responders and the signatureAlgorithm of a BasicOCSPResponse
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Proposers
Corey Bonnell of DigiCert and endorsed by Ben Wilson of Mozilla and Bruce Morton of Entrust.
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot SC053: Sunset for SHA-1 OCSP SigningBallot SC053: Sunset for SHA-1 OCSP SigningVoting Results The voting on ballot SC53 has completed, and the ballot has passed.