← CABF Ballot Browser
SC-096 passed

Ballot SC096: Carve-out for DNSSEC verification logging requirements

Server Certificate Working Group

Key dates

Voting opened
07 Jan 2026 5 months ago
Voting closed
14 Jan 2026 5 months ago
IPR review ends
14 Feb 2026 4 months ago
Discussion opened
15 Dec 2025 6 months ago
Discussion closed
07 Jan 2026 5 months ago

AI Summary

Generated 2026-06-23 21:11 UTC

Ballot overview

  • Ballot SC096 is titled Carve-out for DNSSEC verification logging requirements.
  • It proposes a Final Maintenance Guideline modifying the Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, based on Version 2.1.9.
  • The ballot says DNSSEC verification logging is not in scope for the logging requirements in Section 5.4.1.
  • The ballot also states that DNSSEC validation back to the IANA DNSSEC root trust anchor is outside the scope of self-audits under Section 8.7.

Voting and adoption

  • Voting results show 27 Certificate Issuer votes in favor, 0 against, and 0 abstentions.
  • Voting results show 2 Certificate Consumer votes in favor, 0 against, and 0 abstentions.
  • The ballot page states all Bylaw 2.3 requirements were MET, including quorum.
  • The ballot page states the ballot passed the Initial Vote.

Review period

  • The review period started on 2026-01-15 18:00:00 UTC.
  • The review period ended on 2026-02-14 18:00:00 UTC.
  • The page says members with Essential Claims had to submit a Notice to Exclude Essential Claims before the end of the Review Period.

Requirement change

  • The redline adds language stating that DNSSEC validation back to the IANA DNSSEC root trust anchor is outside the scope of the logging requirements in Section 5.4.1.
  • The ballot text says the change is intended to carve out DNSSEC-specific logging requirements because DNS resolvers are not built for extensive logging.
  • The ballot text says change management logging can confirm whether the appropriate controls are in effect for audit purposes.

Dates

  • Discussion period: 2025-12-15 12:15 UTC to 2026-01-07 16:15 UTC.
  • Voting period: 2026-01-07 16:15 UTC to 2026-01-14 16:15 UTC.
  • Review period: 2026-01-15 18:00:00 UTC to 2026-02-14 18:00:00 UTC.
  • The supplied evidence does not state a separate compliance effective date for the normative change.
Model: gpt-5.4-mini Revised: 2026-06-23 21:11 UTC Confidence: 0.93 Result: passed
Voting opened
2026-01-07
Voting closed
2026-01-14
IPR review ends
2026-02-14
Discussion opened
2025-12-15
Discussion closed
2026-01-07

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Vote result

Certificate Issuers 27 yes 0 no 0 abstain
Certificate Consumers 2 yes 0 no 0 abstain

CABF ballot approval depends on both voting classes; CA votes alone are not decisive.

29 Yes
0 No
0 Abstain

100% yes · 0% no

Proposers

Martijn Katerbarg (Sectigo) and endorsed by Roman Fischer (SwissSign) and Ben Wilson (Mozilla).

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC096: Carve-out for DNSSEC verification logging requirementsBallot SC096: Carve-out for DNSSEC verification logging requirementsVoting Results Certificate Issuers 27 votes in total:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action