← CABF Ballot Browser
SC-096
passed
Ballot SC096: Carve-out for DNSSEC verification logging requirements
Server Certificate Working Group
Key dates
- Voting opened
- 07 Jan 2026 5 months ago
- Voting closed
- 14 Jan 2026 5 months ago
- IPR review ends
- 14 Feb 2026 4 months ago
- Discussion opened
- 15 Dec 2025 6 months ago
- Discussion closed
- 07 Jan 2026 5 months ago
Resources
GitHub diff
https://github.com/cabforum/servercert/compare/1bfd462460ba1b8068ee926de7bc296871d10013...00aa4ea35372c84d08ef1cbd4fc1bb8d356d6e09
https://github.com/cabforum/servercert/compare/1bfd462460ba1b8068ee926de7bc296871d10013...00aa4ea35372c84d08ef1cbd4fc1bb8d356d6e09
Redline
https://cabforum.org/2026/01/14/ballot-sc096-carve-out-for-dnssec-verification-logging-requirements/BR-SC096-redline.pdf
TBR-SC96-redlined.pdf
Redline
https://cabforum.org/2026/01/14/ballot-sc096-carve-out-for-dnssec-verification-logging-requirements/BR-SC096-redline.docx
TBR-SC96-redlined.docx
Document
https://cabforum.org/2026/01/14/ballot-sc096-carve-out-for-dnssec-verification-logging-requirements/BR-SC096.pdf
TBR-SC96.pdf
Document
https://cabforum.org/2026/01/14/ballot-sc096-carve-out-for-dnssec-verification-logging-requirements/BR-SC096.docx
TBR-SC96.docx
Document
https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf
https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf
AI Summary
Ballot overview
- Ballot SC096 is titled Carve-out for DNSSEC verification logging requirements.
- It proposes a Final Maintenance Guideline modifying the Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, based on Version 2.1.9.
- The ballot says DNSSEC verification logging is not in scope for the logging requirements in Section 5.4.1.
- The ballot also states that DNSSEC validation back to the IANA DNSSEC root trust anchor is outside the scope of self-audits under Section 8.7.
Voting and adoption
- Voting results show 27 Certificate Issuer votes in favor, 0 against, and 0 abstentions.
- Voting results show 2 Certificate Consumer votes in favor, 0 against, and 0 abstentions.
- The ballot page states all Bylaw 2.3 requirements were MET, including quorum.
- The ballot page states the ballot passed the Initial Vote.
Review period
- The review period started on 2026-01-15 18:00:00 UTC.
- The review period ended on 2026-02-14 18:00:00 UTC.
- The page says members with Essential Claims had to submit a Notice to Exclude Essential Claims before the end of the Review Period.
Requirement change
- The redline adds language stating that DNSSEC validation back to the IANA DNSSEC root trust anchor is outside the scope of the logging requirements in Section 5.4.1.
- The ballot text says the change is intended to carve out DNSSEC-specific logging requirements because DNS resolvers are not built for extensive logging.
- The ballot text says change management logging can confirm whether the appropriate controls are in effect for audit purposes.
Dates
- Discussion period: 2025-12-15 12:15 UTC to 2026-01-07 16:15 UTC.
- Voting period: 2026-01-07 16:15 UTC to 2026-01-14 16:15 UTC.
- Review period: 2026-01-15 18:00:00 UTC to 2026-02-14 18:00:00 UTC.
- The supplied evidence does not state a separate compliance effective date for the normative change.
- Voting opened
- 2026-01-07
- Voting closed
- 2026-01-14
- IPR review ends
- 2026-02-14
- Discussion opened
- 2025-12-15
- Discussion closed
- 2026-01-07
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Vote result
Certificate Issuers
27 yes
0 no
0 abstain
Certificate Consumers
2 yes
0 no
0 abstain
29
Yes
0
No
0
Abstain
Proposers
Martijn Katerbarg (Sectigo) and endorsed by Roman Fischer (SwissSign) and Ben Wilson (Mozilla).
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot SC096: Carve-out for DNSSEC verification logging requirementsBallot SC096: Carve-out for DNSSEC verification logging requirementsVoting Results Certificate Issuers 27 votes in total:
View on cabforum.org →
Last fetched 16 hours ago