Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

290 views
Skip to first unread message

Wayne Thayer

unread,
May 4, 2026, 11:00:31 AM (4 days ago) May 4
to server...@groups.cabforum.org

Ballot SC-098v2: Process RFC 8657 CAA Parameters

Summary of the Ballot

This ballot adds the requirement that CAs process the Certification Authority Authorization (CAA) parameters defined in RFC 8657. These parameters allow the issuance policy specified by a CAA record to include the account and domain validation methods that may be used to issue a certificate for the subject domain.

The ballot defines a syntax for specifying non-ACME domain validation methods in section 4.2.2.1.3.

CAs supporting non-ACME accounts must document the accepted accounturi format in their CP or CPS.

These requirements take effect on March 15, 2027.

The ballot also consolidates CAA requirements into section 4.2.1.

Summary of Discussion

  • This ballot has undergone extensive discussion in the Validation Working Group dating back to 2024, and in https://github.com/cabforum/servercert/pull/567.
  • The full value of the CAA extensions defined in RFC 8657 will only be realized if CAs process the parameters rather than ignoring them.
  • We originally considered including DNSSEC requirements in this ballot but decided to separate them into ballot SC-085.
  • Consensus formed that Non-ACME validation methods must use a specific syntax to avoid conflicts and provide consistency across CAs.
  • An allowance was added for ACME CAs to recognize “parent” accounts that authorize multiple ACME accounts.

Special thanks to Grace Cimaszewski for helping to move this ballot forward.


The following motion has been proposed by Wayne Thayer (Fastly) and endorsed by Chris Clements (Google) and Ben Wilson (Mozilla).

 

--- Motion Begins ---

This ballot modifies the “Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates” (“Baseline Requirements”), based on Version 2.2.6 

Redline: https://github.com/cabforum/servercert/compare/168e0aa8cafe753c85a94b5a8f28541beda48201..515ba3533a32aca8042f0a72b4c4af3fbb3eaaf9

--- Motion Ends ---


This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows:

 

Discussion (at least 7 days)

  • Start time: 2026-04-27 00:00 UTC

  • End time: 2026-05-04 15:00 UTC

 

Vote for approval (7 days)

  • Start time: 2026-05-04 15:00 UTC

  • End time: no earlier than 2026-05-11 15:00 UTC

Wayne Thayer

unread,
May 5, 2026, 12:05:48 PM (3 days ago) May 5
to Server Certificate WG (CA/B Forum)
Fastly votes Yes to ballot SC-098v2.

- Wayne

Ben Wilson

unread,
May 5, 2026, 1:20:55 PM (3 days ago) May 5
to server...@groups.cabforum.org
Mozilla votes "Yes" on Ballot SC-098v2.

--
You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to servercert-w...@groups.cabforum.org.
To view this discussion visit https://groups.google.com/a/groups.cabforum.org/d/msgid/servercert-wg/e07bd688-34e1-43ac-8a15-37e1d13aafdan%40groups.cabforum.org.

黃晟(orca)

unread,
May 5, 2026, 9:28:20 PM (3 days ago) May 5
to server...@groups.cabforum.org

TWCA votes Yes on Ballot on SC-098v2.

 

 

Best,

 

Sean Huang

Senior PKI Compliance Engineer
TEL
02-2370-8886#728
FAX02-2388-6720
Emailor...@twca.com.tw

10F., No. 85, Yanping South Road,

Taipei, Taiwan (R.O.C.)

--

You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to servercert-w...@groups.cabforum.org.

Hogeun Yoo

unread,
May 6, 2026, 12:43:20 AM (3 days ago) May 6
to server...@groups.cabforum.org
NAVER Cloud Trust Services votes "Yes" on Ballot SC-098v2.

Regards,
Hogeun Yoo
--
You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to servercert-w...@groups.cabforum.org.
To view this discussion visit https://groups.google.com/a/groups.cabforum.org/d/msgid/servercert-wg/CAPh8bk9RPqfW-UPRTmV7xbupKDiXKASgm4Vw0g05ZBEgwq-HYQ%40mail.gmail.com.

Backman, Antti

unread,
May 6, 2026, 1:55:07 AM (2 days ago) May 6
to server...@groups.cabforum.org
Hi, 

Telia votes ‘Yes’ on Ballot SC-098v2

//Antti
From: Wayne Thayer <wth...@gmail.com>
Date: Monday, 4. May 2026 at 18.00
To: server...@groups.cabforum.org <server...@groups.cabforum.org>
Subject: [Servercert-wg] Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

--

Adriano Santoni

unread,
May 6, 2026, 2:59:05 AM (2 days ago) May 6
to server...@groups.cabforum.org

Actalis votes 'Yes' to ballot SC-098v2.


Il 04/05/2026 17:00, Wayne Thayer ha scritto:
--

Nome Huang

unread,
May 6, 2026, 4:35:35 AM (2 days ago) May 6
to Server Certificate WG (CA/B Forum), wth...@gmail.com
TrustAsia votes "Yes" on ballot SC-098v2.

Dimitris Zacharopoulos (HARICA)

unread,
May 7, 2026, 1:58:20 AM (yesterday) May 7
to server...@groups.cabforum.org
HARICA votes "no" to ballot SC098v2.

HARICA believes this ballot introduces significant complexity, increasing the likelihood that Domain Owners may be prevented from obtaining certificates if the appropriate DNS values are not configured correctly (similar to the issues previously seen with Public Key Pinning). In addition, CAs would be required to implement a complex and operationally challenging set of rules, including considerations for linked accounts and parent–child organizational relationships. Ultimately, we believe that only a limited number of Domain Owners will make use of such restrictions. As complexity increases, so does the likelihood of configuration errors and operational mistakes.

All Domain Validation methods currently included in the Baseline Requirements are considered secure by the SCWG, and Domain Owners should be able to use any of them at any time without the perception that one method is inherently more secure than another. While certain methods may present higher risks than others, the SCWG has agreed to gradually deprecate those methods over time. This should not be interpreted as meaning that the methods scheduled for deprecation are insecure.

As additional validation methods are introduced, Domain Owners who have configured CAA parameters to permit only specific methods will need to revisit and update their DNS records before they can take advantage of the newly introduced methods. This is an additional barrier which can be avoided.

--

jun....@cybertrust.co.jp

unread,
May 7, 2026, 3:03:23 AM (yesterday) May 7
to server...@groups.cabforum.org
Cybertrust Japan votes ‘Yes’ on Ballot SC-098v2

-----Original Message-----
From: Wayne Thayer <wth...@gmail.com>
Sent: Tuesday, May 5, 2026 12:00 AM
To: server...@groups.cabforum.org
Subject: [Servercert-wg] Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

Ballot SC-098v2: Process RFC 8657 CAA Parameters

Summary of the Ballot

This ballot adds the requirement that CAs process the Certification Authority Authorization (CAA) parameters defined in RFC 8657. These parameters allow the issuance policy specified by a CAA record to include the account and domain validation methods that may be used to issue a certificate for the subject domain.

The ballot defines a syntax for specifying non-ACME domain validation methods in section 4.2.2.1.3.

CAs supporting non-ACME accounts must document the accepted accounturi format in their CP or CPS.

These requirements take effect on March 15, 2027.

The ballot also consolidates CAA requirements into section 4.2.1.

Summary of Discussion

* This ballot has undergone extensive discussion in the Validation Working Group dating back to 2024, and in https://github.com/cabforum/servercert/pull/567.
* The full value of the CAA extensions defined in RFC 8657 will only be realized if CAs process the parameters rather than ignoring them.
* We originally considered including DNSSEC requirements in this ballot but decided to separate them into ballot SC-085.
* Consensus formed that Non-ACME validation methods must use a specific syntax to avoid conflicts and provide consistency across CAs.
* An allowance was added for ACME CAs to recognize “parent” accounts that authorize multiple ACME accounts.

Special thanks to Grace Cimaszewski for helping to move this ballot forward.

________________________________

The following motion has been proposed by Wayne Thayer (Fastly) and endorsed by Chris Clements (Google) and Ben Wilson (Mozilla).



--- Motion Begins ---

This ballot modifies the “Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates” (“Baseline Requirements”), based on Version 2.2.6

Redline: https://github.com/cabforum/servercert/compare/168e0aa8cafe753c85a94b5a8f28541beda48201..515ba3533a32aca8042f0a72b4c4af3fbb3eaaf9

--- Motion Ends ---




This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows:



Discussion (at least 7 days)

* Start time: 2026-04-27 00:00 UTC

* End time: 2026-05-04 15:00 UTC



Vote for approval (7 days)

* Start time: 2026-05-04 15:00 UTC

* End time: no earlier than 2026-05-11 15:00 UTC

--
You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to servercert-w...@groups.cabforum.org <mailto:servercert-w...@groups.cabforum.org> .
To view this discussion visit https://groups.google.com/a/groups.cabforum.org/d/msgid/servercert-wg/CAPh8bk9RPqfW-UPRTmV7xbupKDiXKASgm4Vw0g05ZBEgwq-HYQ%40mail.gmail.com <https://groups.google.com/a/groups.cabforum.org/d/msgid/servercert-wg/CAPh8bk9RPqfW-UPRTmV7xbupKDiXKASgm4Vw0g05ZBEgwq-HYQ%40mail.gmail.com?utm_medium=email&utm_source=footer> .

Martijn Katerbarg

unread,
May 7, 2026, 3:26:46 AM (yesterday) May 7
to server...@groups.cabforum.org
Sectigo votes YES to ballot SC-98v2

From: Wayne Thayer <wth...@gmail.com>
Date: Monday, 4 May 2026 at 17:00
To: server...@groups.cabforum.org <server...@groups.cabforum.org>
Subject: [Servercert-wg] Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

This Message Is From an External Sender
This message came from outside your organization.
 
--

You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.

Martijn Katerbarg

unread,
May 7, 2026, 7:44:32 AM (yesterday) May 7
to server...@groups.cabforum.org
Dimitris, I do want to call out specifically here, and mostly to avoid any confusion should this ballot not pass, that any CA included within the Chrome root store, already needs to comply with most of what is outlined in this ballot, as of the same effective date. 

From: 'Dimitris Zacharopoulos (HARICA)' via Server Certificate WG (CA/B Forum) <server...@groups.cabforum.org>
Date: Thursday, 7 May 2026 at 07:58
To: server...@groups.cabforum.org <server...@groups.cabforum.org>
Subject: Re: [Servercert-wg] Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

This Message Is From an External Sender
This message came from outside your organization.
 

Kateryna Aleksieieva

unread,
May 7, 2026, 9:38:27 AM (yesterday) May 7
to server...@groups.cabforum.org

Certum votes YES on Ballot SC-098v2

Kind regards,

Kateryna Aleksieieva

--

郭宗閔

unread,
May 7, 2026, 10:03:01 PM (15 hours ago) May 7
to server...@groups.cabforum.org

Chunghwa Telecom votes YES on Ballot SC-098v2.

 

Regards,

Tsung-Min Kuo

Chunghwa Telecom Co., Ltd., Taiwan (R.O.C.)

 

From: Wayne Thayer <wth...@gmail.com>


Sent: Monday, May 4, 2026 11:00 PM
To: server...@groups.cabforum.org

Subject: [外部郵件][Servercert-wg] Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

--


You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to servercert-w...@groups.cabforum.org.
To view this discussion visit https://groups.google.com/a/groups.cabforum.org/d/msgid/servercert-wg/CAPh8bk9RPqfW-UPRTmV7xbupKDiXKASgm4Vw0g05ZBEgwq-HYQ%40mail.gmail.com.



本信件可能包含中華電信股份有限公司機密資訊,非指定之收件者,請勿蒐集、處理或利用本信件內容,並請銷毀此信件. 如為指定收件者,應確實保護郵件中本公司之營業機密及個人資料,不得任意傳佈或揭露,並應自行確認本郵件之附檔與超連結之安全性,以共同善盡資訊安全與個資保護責任.
Please be advised that this email message (including any attachments) contains confidential information and may be legally privileged. If you are not the intended recipient, please destroy this message and all attachments from your system and do not further collect, process, or use them. Chunghwa Telecom and all its subsidiaries and associated companies shall not be liable for the improper or incomplete transmission of the information contained in this email nor for any delay in its receipt or damage to your system. If you are the intended recipient, please protect the confidential and/or personal information contained in this email with due care. Any unauthorized use, disclosure or distribution of this message in whole or in part is strictly prohibited. Also, please self-inspect attachments and hyperlinks contained in this email to ensure the information security and to protect personal information.

Michael Guenther

unread,
2:54 AM (10 hours ago) 2:54 AM
to server...@groups.cabforum.org
smime.p7m

Chris Clements

unread,
10:34 AM (2 hours ago) 10:34 AM
to server...@groups.cabforum.org
Google votes Yes on Ballot SC-098v2.

On Fri, May 8, 2026 at 2:54 AM 'Michael Guenther' via Server Certificate WG (CA/B Forum) <server...@groups.cabforum.org> wrote:

SwissSign votes 'yes' on ballot SC-098v2

 

Mike

 

From: Wayne Thayer <wth...@gmail.com>

Sent: Monday, May 4, 2026 5:00 PM
To: server...@groups.cabforum.org

--

Christophe Bonjean

unread,
10:36 AM (2 hours ago) 10:36 AM
to server...@groups.cabforum.org

GlobalSign votes YES on Ballot SC-098v2.

 

Christophe

 

From: Wayne Thayer <wth...@gmail.com>

Sent: 04 May 2026 17:00
To: server...@groups.cabforum.org

--

sde...@godaddy.com

unread,
10:39 AM (2 hours ago) 10:39 AM
to server...@groups.cabforum.org
GoDaddy votes Yes on Ballot SC-098v2. 

Regards, 
Steven Deitte

From: Wayne Thayer <wth...@gmail.com>
Date: Monday, May 4, 2026 at 11:00 AM
To: server...@groups.cabforum.org <server...@groups.cabforum.org>
Subject: [Servercert-wg] Voting Period Begins: Ballot SC-098v2: Process RFC 8657 CAA Parameters

This Message Is From an External Sender
This message came from outside your organization.
 

Ballot SC-098v2: Process RFC 8657 CAA Parameters

--

Pedro FUENTES

unread,
10:42 AM (2 hours ago) 10:42 AM
to server...@groups.cabforum.org
OISTE votes Yes to SC-098v2



WISeKey SA
Pedro Fuentes
CSO - Trust Services Manager

Office: + 41 (0) 22 594 30 00
Mobile: + 41 (0) 
791 274 790
Address: Avenue Louis-Casaï 58 | 1216 Cointrin | Switzerland
Stay connected with WISeKey

THIS IS A TRUSTED MAIL: This message is digitally signed with a WISeKey identity. If you get a mail from WISeKey please check the signature to avoid security risks

CONFIDENTIALITY: This email and any files transmitted with it can be confidential and it’s intended solely for the use of the individual or entity to which they are addressed. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. If you have received this email in error please notify the sender

DISCLAIMER: WISeKey does not warrant the accuracy or completeness of this message and does not accept any liability for any errors or omissions herein as this message has been transmitted over a public network. Internet communications cannot be guaranteed to be secure or error-free as information may be intercepted, corrupted, or contain viruses. Attachments to this e-mail are checked for viruses; however, we do not accept any liability for any damage sustained by viruses and therefore you are kindly requested to check for viruses upon receipt.

Reply all
Reply to author
Forward
0 new messages