← CABF Ballot Browser
SC-073 passed

Ballot SC073: Compromised and weak keys

Server Certificate Working Group

Key dates

Effective date
15 Nov 2024 1 year ago
Voting opened
26 Apr 2024 2 years ago
Voting closed
03 May 2024 2 years ago
IPR review ends
06 Jun 2024 2 years ago
Discussion opened
18 Apr 2024 2 years ago
Discussion closed
26 Apr 2024 2 years ago

Resources

AI Summary

Generated 2026-06-23 21:18 UTC

Ballot overview (SC-073: Compromised and weak keys)

  • The ballot proposes updates to the Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates related to weak and compromised private keys.
  • The changes are primarily in Section 6.1.1.3:
    • 6.1.1.3(4) clarifies that CAs shall be made aware of compromised keys using their existing notification mechanism(s).
    • 6.1.1.3(5) improves guidance for CAs around the detection of weak keys.
  • The ballot page states that if the ballot passes, these changes become effective on November 15, 2024.

Voting and adoption checks

  • Voting Results:
    • 23 Certificate Issuers voted YES; 0 voted NO; 0 abstained.
    • 1 Certificate Consumer voted YES; 0 voted NO; 0 abstained.
  • Bylaws Requirements:
    • Bylaw 2.3(6) requirements were MET (2/3 or more of Voting Members in the Certificate Issuer category in favor; and 50%+1 in the Certificate Consumer category in favor).
    • Bylaw 2.3(7) quorum requirement was MET (quorum was 14 for this ballot).

IPR review period and exclusion notice process

  • Review Notice (Final Maintenance Guideline) states:
    • Start of Review Period: 6 May 2024 at 10:00 UTC
    • End of Review Period: 6 June 2024 at 10:00 UTC
    • Members with Essential Claims to exclude must forward a written Notice to Exclude Essential Claims to the Working Group Chair and also submit a copy to the CA/B Forum public mailing list before the end of the Review Period.

What the redline changes do (as reflected in the provided evidence)

  • The redline updates the Baseline Requirements text related to key compromise and weak keys handling.
  • It changes the condition for rejecting certificate requests based on weak keys and adds specific precautions for requests submitted on or after November 15, 2024, including:
  • The redline also updates how key compromise notifications are handled (e.g., referencing CA revocation request procedures and special requirements for re-key compromise).
Model: gpt-5.4-nano Confidence: 0.86 Result: passed
Effective date
2024-11-15
Voting opened
2024-04-26
Voting closed
2024-05-03
IPR review ends
2024-06-06
Discussion opened
2024-04-18
Discussion closed
2024-04-26
Applicability and conditions

2024-11-15 — CAs must apply the specified weak-key rejection/precaution steps for requests submitted on or after November 15, 2024. For certificate requests submitted on or after November 15, 2024, the redline specifies additional weak-key precautions (Debian weak keys, ROCA, and Close Primes checks) that the CA SHALL implement.

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Vote result

Certificate Issuers 23 yes 0 no 0 abstain
Certificate Consumers 1 yes 0 no 0 abstain

CABF ballot approval depends on both voting classes; CA votes alone are not decisive.

24 Yes
0 No
0 Abstain

100% yes · 0% no

Proposers

Wayne Thayer of Fastly, and endorsed by Brittany Randall of GoDaddy and Bruce Morton of Entrust.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC073: Compromised and weak keysBallot SC073: Compromised and weak keysVoting Results Certificate Issuers 23 votes total, with no abstentions:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action