← CABF Ballot Browser
SC-053 passed

Ballot SC053: Sunset for SHA-1 OCSP Signing

Server Certificate Working Group

Key dates

Effective date
01 Jun 2022 4 years ago
Voting opened
17 Jan 2022 4 years ago
Voting closed
24 Jan 2022 4 years ago
Discussion opened
10 Jan 2022 4 years ago
Discussion closed
17 Jan 2022 4 years ago

Resources

AI Summary

Generated 2026-06-23 21:41 UTC

Ballot overview

  • Ballot SC053, Sunset for SHA-1 OCSP Signing, was a Server Certificate Working Group ballot.
  • Its purpose was to establish a sunset date prohibiting delegated OCSP signing with the SHA-1 hash algorithm.
  • The ballot modified the Baseline Requirements based on Version 1.8.0 and was incorporated into Baseline Requirements version 1.8.2.

Voting and adoption

  • Voting on ballot SC53 completed and the ballot passed.
  • Certificate Issuers: 21 yes votes, 0 no votes, 0 abstentions.
  • Certificate Consumers: 5 yes votes, 0 no votes, 0 abstentions.
  • Bylaw requirements were met for Certificate Issuers, Certificate Consumers, and quorum.
  • The ballot cleared the IP Rights Review period with no IP Rights issues raised by the community.

Requirement introduced

  • CAs must not sign OCSP responses using the SHA-1 hash algorithm.
  • For OCSP responses using the signatureAlgorithm of a BasicOCSPResponse, the producedAt field value of the ResponseData must be earlier than 2022-06-01 00:00:00 UTC.

Relevant dates

  • Discussion: 2022-01-10 15:00:00 UTC to 2022-01-17 15:00:00 UTC.
  • Vote for approval: 2022-01-17 15:00:00 UTC to 2022-01-24 15:00:00 UTC.
  • The Baseline Requirements table lists 2022-06-01 as the date by which CAs must not sign OCSP responses using SHA-1.
  • The linked BR 1.8.2 PDF shows the same requirement in the relevant dates table and the OCSP profile change.
Model: gpt-5.4-mini Confidence: 0.98 Result: passed
Effective date
2022-06-01
Voting opened
2022-01-17
Voting closed
2022-01-24
Discussion opened
2022-01-10
Discussion closed
2022-01-17
Applicability and conditions

2022-06-01 — CAs must not sign OCSP responses using the SHA-1 hash algorithm; the producedAt field value of the ResponseData must be earlier than this date and time OCSP responses, including delegated OCSP responders and the signatureAlgorithm of a BasicOCSPResponse

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Corey Bonnell of DigiCert and endorsed by Ben Wilson of Mozilla and Bruce Morton of Entrust.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC053: Sunset for SHA-1 OCSP SigningBallot SC053: Sunset for SHA-1 OCSP SigningVoting Results The voting on ballot SC53 has completed, and the ballot has passed.

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action