← CABF Ballot Browser
SMC-012
passed
Ballot SMC012: Introduce ACME for S/MIME
S/MIME Certificate Working Group
Key dates
- Effective date
- 02 Jul 2025 1 year ago
- Voting opened
- 26 May 2025 1 year ago
- Voting closed
- 02 Jun 2025 1 year ago
- IPR review ends
- 02 Jul 2025 1 year ago
- Discussion opened
- 19 May 2025 1 year ago
- Discussion closed
- 26 May 2025 1 year ago
Resources
GitHub diff
https://github.com/cabforum/smime/compare/8c8fab7993de3c1c423e704947ce880165924abb...4a663e37e70083752c6fa9ae0d4820231cf54217
https://github.com/cabforum/smime/compare/8c8fab7993de3c1c423e704947ce880165924abb...4a663e37e70083752c6fa9ae0d4820231cf54217
Redline
https://cabforum.org/uploads/CA-Browser-Forum-SMIMEBR-1.0.10-Redline.pdf
https://cabforum.org/uploads/CA-Browser-Forum-SMIMEBR-1.0.10-Redline.pdf
Document
https://cabforum.org/uploads/CA-Browser-Forum-SMIMEBR-1.0.10.pdf
https://cabforum.org/uploads/CA-Browser-Forum-SMIMEBR-1.0.10.pdf
Document
https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf
https://cabforum.org/wp-content/uploads/Template-for-Exclusion-Notice.pdf
Affected document sections
S/MIME BR § 1.3.2.1
Updates Enterprise RA requirements to allow mailbox control confirmation under section 3.2.2.2 or the new section 3.2.2.4.
S/MIME BR § 1.6.3
Adds references for RFC 8823, RFC 8555, and RFC 9598 and adjusts reference formatting.
S/MIME BR § 3.2.2.4
Adds a new mailbox control validation method using ACME extensions for S/MIME, including Random Value handling and validity requirements.
S/MIME BR § 6.1.5
Corrects the EdDSA curve name from curve 448 to curve448.
S/MIME BR § 7.1.4.2.1
Clarifies use of directoryName in the SAN extension and the applicable subject DN sections by certificate type.
AI Summary
Overview
- Ballot SMC012 introduces a new method for validation of mailbox control using ACME for S/MIME as defined in RFC 8823.
- The ballot says the new method is separate from the existing mailbox-via-email method so the requirements can better describe how a CA ACME server may respond to a POST request by sending Random Value token components via email and SMTP.
- The ballot also includes minor typographic corrections, including a clarification in section 7.1.4.2.1 regarding use of directoryName in the SAN extension.
- The ballot modifies the Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates based on version 1.0.9.
- The adopted text was published as S/MIME BR version 1.0.10.
Result
- The ballot passed.
- The ballot page states that no IPR Exclusion Notices were filed.
- The ballot page states the ballot is adopted as of 2025-07-02.
- Voting results shown on the page were 15 yes, 0 no, and 1 abstain from Certificate Issuers, and 2 yes, 0 no, and 0 abstain from Certificate Consumers.
- The page states the applicable issuer majority, consumer majority, one-yes-per-category, and quorum requirements were all met.
Key changes
- Adds section 3.2.2.4, Validating control over mailbox using ACME extensions.
- Permits a CA to confirm control over each Mailbox Field using ACME for S/MIME as defined in RFC 8823.
- Permits the CA ACME server to respond to a POST request by sending Random Value token components via email and SMTP and receiving a confirming response using the generated Random Value in accordance with RFC 8823.
- Requires each Mailbox Address to be confirmed using a newly generated Random Value.
- Requires Random Value token components to be shared only in accordance with RFC 8823.
- States that token-part1 shall contain at least 128 bits of entropy and token-part2 should contain at least 128 bits of entropy.
- Prohibits reuse of the Random Value for other Certificate Requests.
- Limits Random Value validity for a confirming response to no more than 24 hours from creation, while allowing a shorter period in the CA CP or CPS.
- States that implementations may use ACME External Account Binding as defined by RFC 8555.
Additional edits
- Updates the Enterprise RA text in section 1.3.2.1 so mailbox control may be confirmed under section 3.2.2.2 or section 3.2.2.4.
- Adds references for RFC 8823, RFC 8555, and RFC 9598, and adjusts punctuation in existing references.
- Corrects curve 448 to curve448 in section 6.1.5.
- In section 7.1.4.2.1, replaces dirName with directoryName and clarifies that directoryName content must comply with sections 7.1.4.2.2 through 7.1.4.2.6 according to certificate type.
Process dates
- Discussion ran from 2025-05-19 17:00:00 UTC to 2025-05-26 17:00:00 UTC.
- Voting ran from 2025-05-26 17:00:00 UTC to 2025-06-02 17:00:00 UTC.
- The IPR review period ran from 2025-06-02 18:00:00 UTC to 2025-07-02 18:00:00 UTC.
- The ballot was adopted on 2025-07-02.
- Effective date
- 2025-07-02
- Voting opened
- 2025-05-26
- Voting closed
- 2025-06-02
- IPR review ends
- 2025-07-02
- Discussion opened
- 2025-05-19
- Discussion closed
- 2025-05-26
AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.
Vote result
Certificate Issuers
15 yes
0 no
1 abstain
Certificate Consumers
2 yes
0 no
0 abstain
17
Yes
0
No
1
Abstain
Proposers
Stephen Davidson (DigiCert) and endorsed by Stefan Selbitschka (rundQuadrat) and Guillaume Amringer (Carillon).
Excerpt
SearchHome » All CA/Browser Forum Posts » Ballot SMC012: Introduce ACME for S/MIMEBallot SMC012: Introduce ACME for S/MIMEThe Intellectual Property Review (IPR) period for Ballot SMC012 (Ballot SMC012: Introduce ACME for S/MIME) has completed.
View on cabforum.org →
Last fetched 1 month ago