← CABF Ballot Browser
SMC-020 discussion

Ballot SMC020: Remove Requirement to Record BR Version of Validation Method

S/MIME Certificate Working Group

Key dates

Effective date
15 Mar 2027 5 months from now
Voting opened
05 Oct 2026 6 days ago
Voting closed
12 Oct 2026 37 minutes from now
Discussion opened
05 Oct 2026 6 days ago
Discussion closed
12 Oct 2026 37 minutes from now

Resources

Affected document sections
S/MIME BR § 3.2.2 Removes the requirement to record the relevant version number of the S/MIME BR with the validation method. S/MIME BR § 5.4.1 Adds required audit log content for verification activities, effective March 15, 2027.
Related ballots

AI Summary

Generated 2026-10-11 04:00 UTC

Ballot overview

  • Ballot SMC020 removes the requirement in S/MIME Baseline Requirements Section 3.2.2 to record the relevant version number of the S/MIME BR with the validation method.
  • It keeps the S/MIME BR aligned with Ballot SC-099, with stated differences for terminology and for allowing the recorded method to reference either the S/MIME BR or the TLS BR.
  • The ballot modifies the Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates, based on Version 1.0.16.

What changes

  • Section 3.2.2 no longer requires CAs to maintain a record of which validation method, including the relevant version number from the TLS Baseline Requirements or S/MIME Baseline Requirements, was used to validate every domain or email address in issued Certificates.
  • Section 5.4.1 is updated so that, effective March 15, 2027, audit logs of verification activities must include:
    • the information being validated, such as the Mailbox Address, domain name, or Organization name
    • the domain name whose control was validated, if applicable and different from the domain portion of the Mailbox Address, such as the Authorization Domain Name or SMTP FQDN
    • the validation method used, such as the section number of the S/MIME BR or TLS BR, or the registered label of an ACME challenge type

Procedure and timing

  • Discussion period: October 5, 2026 at 19:00 UTC through October 12, 2026 at 19:00 UTC
  • Voting for approval: start time TBD; end time TBD
  • The ballot text states that the effective March 15, 2027 logging requirement applies to audit logs of verification activities under Section 5.4.1

Related material

  • The linked redline shows a new S/MIME BR version entry for SMC020 and updates the audit log requirement in Section 5.4.1.
  • The ballot text explicitly says it maintains consistency with the TLS BR following Ballot SC-099.
Model: gpt-5.4-mini Confidence: 0.98 Result: in progress
Effective date
2027-03-15
Discussion opened
2026-10-05
Discussion closed
2026-10-12
Applicability and conditions

2027-03-15 — CAs must ensure audit logs include the information validated, the domain name whose control was validated when applicable and different from the Mailbox Address domain portion, and the validation method used Audit logs of verification activities under S/MIME BR Section 5.4.1

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Pedro Fuentes (OISTE Foundation), and is endorsed by Stephen Davidson (DigiCert) and Dustin Hollenback (Apple).

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SMC020: Remove Requirement to Record BR Version of Validation MethodBallot SMC020: Remove Requirement to Record BR Version of Validation Method[Discussion] Ballot SMC020: Remove Requirement to Record BR Version of Validation MethodSummary: This ballot removes the requirement in Section 3.2.2 to record “relevant version number” of the S/MIME BR with the validation method. The change maintains consistency with the TLS BR following Ballot SC-099.

View on cabforum.org → Last fetched 19 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action