Ballot SC065v2: Convert EVGs into RFC 3647 format
Server Certificate Working Group
Key dates
- Effective date
- 15 Mar 2024 2 years ago
- Voting opened
- 04 Mar 2024 2 years ago
- Voting closed
- 11 Mar 2024 2 years ago
- IPR review ends
- 15 Apr 2024 2 years ago
- Discussion opened
- 20 Feb 2024 2 years ago
- Discussion closed
- 04 Mar 2024 2 years ago
Resources
AI Summary
Ballot overview
- Ballot SC065v2, Convert EVGs into RFC 3647 format, was a Final Maintenance Guideline for the TLS Baseline Requirements and the EVGs.
- The ballot says it updates the EVGs to follow the RFC 3647 format without changing any content, only moving current sections to the RFC 3647 structure.
- It also updates the Baseline Requirements to point to the new EVG sections.
- The ballot states there are no normative requirements changes.
Voting and adoption
- Voting results were 23 issuer YES, 0 issuer NO, 0 issuer abstain.
- Voting results were 2 consumer YES, 0 consumer NO, 0 consumer abstain.
- The bylaws requirements and quorum were met.
- The page states the ballot result was passed.
Review period and IPR notice
- The review period ran from 15 March 2024 at 10:00 UTC to 15 April 2024 at 10:00 UTC.
- The IPR policy excerpt says exclusion notices must be provided before the end of the review period.
- The supplied evidence does not explicitly state whether any exclusion notices were filed.
Document changes shown in the linked artifacts
- The BR PDF is version 2.0.4 dated 17-April-2024.
- The EVG PDF is version 2.0.0 dated 17 April, 2024.
- The GitHub diff shows updates including:
- BR title changed to Publicly-Trusted TLS Server Certificates and subtitle changed to Version 2.0.3.
- A new relevant date entry of 2024-03-15 for section 4.9.7, stating CAs MUST generate and publish CRLs.
- A new definition for Short-lived Subscriber Certificate with dates of 15 March 2024 and 15 March 2026.
- Other editorial and reference updates.
Compliance timing reflected in the evidence
- The clearest compliance date explicitly shown in the evidence is 2024-03-15 for the requirement that CAs MUST generate and publish CRLs.
- The short-lived subscriber certificate definition also introduces phased dates for certificates issued on or after 15 March 2024 and on or after 15 March 2026.
- Effective date
- 2024-03-15
- Voting opened
- 2024-03-04
- Voting closed
- 2024-03-11
- IPR review ends
- 2024-04-15
- Discussion opened
- 2024-02-20
- Discussion closed
- 2024-03-04
2024-03-15 — CAs MUST generate and publish CRLs Section 4.9.7 applies to CAs issuing publicly-trusted TLS server certificates
2024-03-15 — A Subscriber Certificate is a Short-lived Subscriber Certificate if its validity period is less than or equal to 10 days (864,000 seconds) Certificates issued on or after this date and prior to 15 March 2026
2026-03-15 — A Subscriber Certificate is a Short-lived Subscriber Certificate if its validity period is less than or equal to 7 days (604,800 seconds) Certificates issued on or after this date
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Vote result
Proposers
Iñigo Barreira (Sectigo) and endorsed by Pedro Fuentes (OISTE) and Ben Wilson (Mozilla).
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot SC065v2: Convert EVGs into RFC 3647 formatBallot SC065v2: Convert EVGs into RFC 3647 formatVoting Results Certificate Issuers 23 votes total, with no abstentions: