← CABF Ballot Browser
SC-059v2
failed
Ballot SC059v2: Weak key guidance
Server Certificate Working Group
Key dates
- Voting opened
- 06 Jul 2023 2 years ago
- Voting closed
- 13 Jul 2023 2 years ago
- Discussion opened
- 26 Jun 2023 2 years ago
- Discussion closed
- 03 Jul 2023 2 years ago
Resources
AI Summary
Ballot overview
- Ballot SC059v2: Weak key guidance (Server Certificate Working Group) proposes updates to the Baseline Requirements for issuance and management of publicly-trusted certificates.
- The updates focus on identifying and revoking certificates whose private keys were generated in ways that may make them susceptible to easy decryption, specifically addressing Debian weak keys, ROCA, and Close Primes Vulnerability.
Key proposed changes (as reflected in the provided redline diff)
- Revocation trigger wording update: updates the condition describing when the CA is made aware of a demonstrated or proven method that can easily compute a private key based on the public key.
- Rejection guidance for weak keys:
- Adds a requirement that for requests submitted on or after November 15, 2023, the CA SHALL implement precautions when the public key corresponds to an industry-demonstrated weak private key.
- ROCA: the CA SHALL reject keys identified by tools available at https://github.com/crocs-muni/roca or equivalent.
- Debian weak keys: the CA SHALL reject at least keys generated by the flawed OpenSSL version with specified parameter combinations.
- Close Primes vulnerability: the CA SHALL reject weak keys that can be factored within 100 rounds using Fermat’s factorization method.
- Includes a pointer to suggested tools for checking for weak keys at https://cabforum.org/resources/tools/
Voting and adoption status
- Certificate Issuer category: 4 YES vs 14 NO (2/3 requirement NOT MET), so the ballot was not adopted.
- Certificate Consumer category: 2 YES vs 0 NO (50%+1 requirement MET).
- Category participation: at least one voting member in each category voted in favor (requirement MET).
- The ballot page indicates current_status: failed.
- Voting opened
- 2023-07-06
- Voting closed
- 2023-07-13
- Discussion opened
- 2023-06-26
- Discussion closed
- 2023-07-03
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Vote result
Certificate Issuers
4 yes
14 no
1 abstain
Certificate Consumers
2 yes
0 no
1 abstain
6
Yes
14
No
2
Abstain
Proposers
Thomas Zermeno of SSL.com and has been endorsed by Martijn Katerbarg of Sectigo and Ben Wilson of Mozilla.
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot SC059v2: Weak key guidanceBallot SC059v2: Weak key guidanceVoting Results Certificate Issuers 19 votes total:
View on cabforum.org →
Last fetched 16 hours ago