Ballot SC073: Compromised and weak keys
Server Certificate Working Group
Key dates
- Effective date
- 15 Nov 2024 1 year ago
- Voting opened
- 26 Apr 2024 2 years ago
- Voting closed
- 03 May 2024 2 years ago
- IPR review ends
- 06 Jun 2024 2 years ago
- Discussion opened
- 18 Apr 2024 2 years ago
- Discussion closed
- 26 Apr 2024 2 years ago
Resources
AI Summary
Ballot overview (SC-073: Compromised and weak keys)
- The ballot proposes updates to the Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates related to weak and compromised private keys.
- The changes are primarily in Section 6.1.1.3:
- 6.1.1.3(4) clarifies that CAs shall be made aware of compromised keys using their existing notification mechanism(s).
- 6.1.1.3(5) improves guidance for CAs around the detection of weak keys.
- The ballot page states that if the ballot passes, these changes become effective on November 15, 2024.
Voting and adoption checks
- Voting Results:
- 23 Certificate Issuers voted YES; 0 voted NO; 0 abstained.
- 1 Certificate Consumer voted YES; 0 voted NO; 0 abstained.
- Bylaws Requirements:
- Bylaw 2.3(6) requirements were MET (2/3 or more of Voting Members in the Certificate Issuer category in favor; and 50%+1 in the Certificate Consumer category in favor).
- Bylaw 2.3(7) quorum requirement was MET (quorum was 14 for this ballot).
IPR review period and exclusion notice process
- Review Notice (Final Maintenance Guideline) states:
- Start of Review Period: 6 May 2024 at 10:00 UTC
- End of Review Period: 6 June 2024 at 10:00 UTC
- Members with Essential Claims to exclude must forward a written Notice to Exclude Essential Claims to the Working Group Chair and also submit a copy to the CA/B Forum public mailing list before the end of the Review Period.
What the redline changes do (as reflected in the provided evidence)
- The redline updates the Baseline Requirements text related to key compromise and weak keys handling.
- It changes the condition for rejecting certificate requests based on weak keys and adds specific precautions for requests submitted on or after November 15, 2024, including:
- Debian weak keys checks using the repository at https://github.com/cabforum/Debian-weak-keys/ (with additional conditions described in the redline).
- ROCA vulnerability checks using https://github.com/crocs-muni/roca or equivalent.
- Close Primes vulnerability checks using Fermat factorization within 100 rounds.
- The redline also updates how key compromise notifications are handled (e.g., referencing CA revocation request procedures and special requirements for re-key compromise).
- Effective date
- 2024-11-15
- Voting opened
- 2024-04-26
- Voting closed
- 2024-05-03
- IPR review ends
- 2024-06-06
- Discussion opened
- 2024-04-18
- Discussion closed
- 2024-04-26
2024-11-15 — CAs must apply the specified weak-key rejection/precaution steps for requests submitted on or after November 15, 2024. For certificate requests submitted on or after November 15, 2024, the redline specifies additional weak-key precautions (Debian weak keys, ROCA, and Close Primes checks) that the CA SHALL implement.
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Vote result
Proposers
Wayne Thayer of Fastly, and endorsed by Brittany Randall of GoDaddy and Bruce Morton of Entrust.
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot SC073: Compromised and weak keysBallot SC073: Compromised and weak keysVoting Results Certificate Issuers 23 votes total, with no abstentions: