← CABF Ballot Browser
SMC-014 passed

Ballot SMC014: DNSSEC for CAA

S/MIME Certificate Working Group

Key dates

Effective date
15 Mar 2026 3 months ago
Voting opened
03 Sep 2025 9 months ago
Voting closed
10 Sep 2025 9 months ago
IPR review ends
10 Oct 2025 8 months ago
Discussion opened
27 Aug 2025 9 months ago
Discussion closed
03 Sep 2025 9 months ago

Resources

AI Summary

Generated 2026-06-23 21:39 UTC

Result and adoption

  • The ballot SMC014: DNSSEC for CAA is marked as PASSED.
  • The ballot is adopted as of October 13, 2025.
  • The page states that no IPR Exclusion Notices were filed.

What the ballot changes

  • The ballot modifies the S/MIME Baseline Requirements (based on Version 1.0.10) by introducing a Final Maintenance Guideline.
  • It introduces requirements that a Certificate Issuer MUST deploy DNSSEC validation back to the IANA DNSSEC root trust anchor on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.
  • The effective date for this DNSSEC validation requirement is stated as effective March 15, 2026.
  • The draft also includes minor corrections to web links in the text.

DNSSEC validation requirements (as described in the evidence)

  • Effective March 15, 2026, DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.
  • Effective March 15, 2026, CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with CAA record lookups.
  • Effective March 15, 2026, DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.
  • DNSSEC validation back to the IANA DNSSEC root trust anchor MAY be performed on all DNS queries associated with CAA record lookups performed by Remote Network Perspectives as part of Multi-Perspective Issuance Corroboration.

Ballot procedure dates shown in the evidence

  • Discussion start time: August 27, 2025 at 17:00:00 UTC
  • Discussion end time: September 3, 2025 at 17:00:00 UTC
  • Voting start time: September 3, 2025 at 17:00:00 UTC
  • Voting end time: September 10, 2025 at 17:00:00 UTC
  • IPR review start time: 2025-09-10 18:00:00 UTC
  • IPR review end time: 2025-10-10 18:00:00 UTC
Model: gpt-5.4-nano Confidence: 0.86 Result: passed
Effective date
2026-03-15
Voting opened
2025-09-03
Voting closed
2025-09-10
IPR review ends
2025-10-10
Discussion opened
2025-08-27
Discussion closed
2025-09-03
Applicability and conditions

2026-03-15 — DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed, CAs MUST NOT disable DNSSEC validation via local policy, and DNSSEC-validation errors observed by the Primary Network Perspective MUST NOT be treated as permission to issue. Applies to DNS queries associated with CAA record lookups performed by the Primary Network Perspective

2026-03-15 — DNSSEC validation back to the IANA DNSSEC root trust anchor MAY be performed. Applies to DNS queries associated with CAA record lookups performed by Remote Network Perspectives as part of Multi-Perspective Issuance Corroboration

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Vote result

Certificate Issuers 15 yes 0 no 1 abstain
Certificate Consumers 3 yes 0 no 0 abstain

CABF ballot approval depends on both voting classes; CA votes alone are not decisive.

18 Yes
0 No
1 Abstain

95% yes · 0% no · 5% abstain

Proposers

Stephen Davidson (DigiCert) and endorsed by Client Wilson (Apple) and Ashish Dhiman (GlobalSign).

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SMC014: DNSSEC for CAABallot SMC014: DNSSEC for CAABallot SMC014: DNSSEC for CAAThe Intellectual Property Review (IPR) period for Ballot SMC014 (DNSSEC for CAA) has completed.

View on cabforum.org → Last fetched 15 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action