← CABF Ballot Browser
SC-059v2 failed

Ballot SC059v2: Weak key guidance

Server Certificate Working Group

Key dates

Voting opened
06 Jul 2023 2 years ago
Voting closed
13 Jul 2023 2 years ago
Discussion opened
26 Jun 2023 2 years ago
Discussion closed
03 Jul 2023 2 years ago

AI Summary

Generated 2026-06-23 21:40 UTC

Ballot overview

  • Ballot SC059v2: Weak key guidance (Server Certificate Working Group) proposes updates to the Baseline Requirements for issuance and management of publicly-trusted certificates.
  • The updates focus on identifying and revoking certificates whose private keys were generated in ways that may make them susceptible to easy decryption, specifically addressing Debian weak keys, ROCA, and Close Primes Vulnerability.

Key proposed changes (as reflected in the provided redline diff)

  • Revocation trigger wording update: updates the condition describing when the CA is made aware of a demonstrated or proven method that can easily compute a private key based on the public key.
  • Rejection guidance for weak keys:
    • Adds a requirement that for requests submitted on or after November 15, 2023, the CA SHALL implement precautions when the public key corresponds to an industry-demonstrated weak private key.
    • ROCA: the CA SHALL reject keys identified by tools available at https://github.com/crocs-muni/roca or equivalent.
    • Debian weak keys: the CA SHALL reject at least keys generated by the flawed OpenSSL version with specified parameter combinations.
    • Close Primes vulnerability: the CA SHALL reject weak keys that can be factored within 100 rounds using Fermat’s factorization method.
    • Includes a pointer to suggested tools for checking for weak keys at https://cabforum.org/resources/tools/

Voting and adoption status

  • Certificate Issuer category: 4 YES vs 14 NO (2/3 requirement NOT MET), so the ballot was not adopted.
  • Certificate Consumer category: 2 YES vs 0 NO (50%+1 requirement MET).
  • Category participation: at least one voting member in each category voted in favor (requirement MET).
  • The ballot page indicates current_status: failed.
Model: gpt-5.4-nano Confidence: 0.78 Result: failed
Voting opened
2023-07-06
Voting closed
2023-07-13
Discussion opened
2023-06-26
Discussion closed
2023-07-03

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Vote result

Certificate Issuers 4 yes 14 no 1 abstain
Certificate Consumers 2 yes 0 no 1 abstain

CABF ballot approval depends on both voting classes; CA votes alone are not decisive.

6 Yes
14 No
2 Abstain

27% yes · 64% no · 9% abstain

Proposers

Thomas Zermeno of SSL.com and has been endorsed by Martijn Katerbarg of Sectigo and Ben Wilson of Mozilla.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC059v2: Weak key guidanceBallot SC059v2: Weak key guidanceVoting Results Certificate Issuers 19 votes total:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action