Final Forum Plenary Minutes - July 16, 2026

28 views
Skip to first unread message

Dean Coclin

unread,
Jul 30, 2026, 11:33:20 AM (5 days ago) Jul 30
to 'Nagelkerke, Marijn' via Public (CA/B Forum)

CA/Browser Forum

Forum Plenary Meeting Minutes

July 16, 2026

Roll Call

Dean Coclin chaired the meeting.  The meeting commenced immediately following the Server Certificate Working Group meeting. Recording was already in progress and the Note Well had previously been read. The list of attendees appears below.

Review of Agenda

No changes to the agenda were proposed.

Approval of Minutes

Approval of the July 2, 2026, minutes was deferred because draft minutes were not yet available.

Server Certificate Working Group Update

Dimitris Zacharopoulos summarized the work of the Server Certificate Working Group. He reported that:

  • SC-100 continues to be refined to address mailing list comments, particularly those relating to DNSSEC validation evidence.
  • Rich Smith intends to publish revised language after reviewing Henry Birge-Lee's comments.
  • The Validation Subcommittee continues to examine upcoming work items.

Validation Subcommittee Update

Stephen Davidson reported that the Validation Subcommittee recently discussed:

  • proposed DNS privacy enhancements currently under development within the IETF that may eventually require additional validation methods within the Baseline Requirements;
  • future work relating to greater automation of validation processes; and
  • whether the Authority Information Access (AIA) extension should remain mandatory when none of its currently optional subcomponents are individually required.

Code Signing Working Group Update

Martijn Katerbarg reported:

  • Microsoft's planned presentation on a customer and threat intelligence sharing initiative was postponed because the presenter became unavailable.
  • The Working Group also discussed simplifying the Code Signing Baseline Requirements by moving toward a single certificate profile.

S/MIME Working Group Update

Stephen Davidson reported:

  • the RSA key size ballot remains under IPR review for approximately two more weeks;
  • discussion continues about adopting CCADB language concerning EKUs and cross-signing into the S/MIME Baseline Requirements; and
  • broader discussion continues regarding whether the S/MIME Baseline Requirements should adopt the narrowest interpretation currently imposed by root programs.

Network Security Working Group Update

Clint Wilson reported that NETSEC-010 required procedural correction because the original proposer was ineligible.

The ballot has therefore been republished with a qualified proposer while retaining the same statement and endorsers. The discussion period has restarted and voting is expected to resume the following week.

Definitions and Glossary Working Group Update

Polina Glazyrina reported significant progress on the glossary document and expects to publish the current draft to GitHub early the following week.

Ben Wilson reported reviewing the current draft and identified several definitions that may require future refinement, including:  Application Software Supplier, Baseline Requirements, Certification Authority, Maximum Validity Period, Reliable Data Source, Reliable Method of Communication, and Trustworthy System.

He noted that terminology describing organizations versus certification authorities remains inconsistent across a variety of documents. He also suggested that, where appropriate, future glossary definitions could reference existing IETF RFC definitions rather than duplicating them.

Martijn Katerbarg recommended first completing and publishing the glossary before attempting broader editorial improvements, a suggestion generally supported by the discussion.

Tadahiko Ito raised an additional consistency concern regarding phrases such as "byte-for-byte identical," "character-for-character identical," and similar wording that appears throughout Forum documents. Ben suggested this might eventually be addressed by defining a common term such as "identical" within the glossary.

Forum Infrastructure Update

No update was provided.

IPR Update

Ben Wilson reported that Cisco and Microsoft have now submitted their updated IPR agreements. He also noted that several organizations remaining on the membership lists have not executed the new agreement but have also not been active participants. Dean suggested notifying those organizations as a courtesy before any suspension actions are taken, and Ben agreed to prepare and send those notifications.

Dimitris additionally reported that Microsoft had inadvertently been included in the vote count for a recently completed Server Certificate ballot before its updated IPR agreement had been received. Removing Microsoft's vote would not change the outcome of the ballot. After brief discussion, the consensus was that no correction to the recorded ballot result was necessary now that the updated IPR agreement has been executed.

Any Other Business

Webex Account

Dean thanked Dimitris for successfully renewing the Forum's Webex account, noting that the renewal process had required considerable effort.

Upcoming Elections

Dean reviewed the schedule for the 2026 Forum elections, including:

  • nomination announcements beginning in early August;
  • chair nominations beginning August 17;
  • elections during September; and
  • the expectation that results will be available before the Vienna face-to-face meeting.

Members were encouraged to begin discussing potential candidates within their Working Groups.

Vienna Face-to-Face Meeting

Dean reminded members to register for the September Vienna meeting and noted current attendance figures. Members were encouraged to register promptly, particularly for the evening event because capacity is limited.

Martijn also noted that dates for the 2027 Scottsdale face-to-face meeting have now been confirmed and published on the wiki (Feb 23-25, 2027).

Discussion Regarding Formal Legal Formation of the Forum

Martijn proposed adding a dedicated agenda item to the Vienna face-to-face meeting to discuss whether the CA/Browser Forum should become formally recognized legal entity.

Dean agreed this would be appropriate, observing that Ben Wilson had previously performed substantial research on possible formation models and that those materials could serve as the basis for discussion.

The ensuing discussion focused on both the potential benefits and the practical implications.

Trevoli Ponds-White asked whether the discussion should concentrate primarily on the mechanics of incorporation ("how") or first determine whether incorporation is desirable in principle.

Chris Clements suggested that the Forum should first evaluate whether legal formation is actually necessary before discussing implementation details. While acknowledging the recent administrative challenges associated with renewing the Webex account, he questioned whether those difficulties alone justified creating a formal legal entity. He noted that incorporation would introduce additional legal, administrative, financial, and governance obligations that could outweigh any operational benefits. He also observed that recent experience obtaining updated IPR agreements from all members illustrated the complexity involved in managing organizational processes across a global volunteer forum.

Martijn responded that understanding the available incorporation models and their associated obligations would help members better evaluate whether the anticipated benefits justify the additional overhead, suggesting that the questions of whether and how are closely connected.

Dean noted that legal formation might not be the only possible solution to the Forum's administrative needs. As Ben's prior research indicated, certain existing nonprofit organizations may be willing to sponsor or administer Forum resources without requiring the Forum itself to become incorporated. He suggested that these alternatives should also be considered during the broader discussion.

The meeting concluded that legal formation would be placed on the agenda for discussion during the Vienna face-to-face meeting, where members could more thoroughly examine both the merits of legal formation and the practical options available before deciding whether any future action is warranted.

Next Meeting

The next Plenary meeting will be held on 30 July 2026.

Adjournment

The meeting then adjourned.

Attendees:  Aaron Gable (Let's Encrypt), Aaron Poulsen (SSL.com), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Arman Asemani (Apple), Ben Wilson (Mozilla), Chris Clements (Google), Clint Wilson (Apple), Daryn Wright (Apple), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Dustin Hollenback (Apple), Georgy Sebastian (Amazon), Gurleen Grewal (Google), Hazhar Ismail (MSC Trustgate Sdn Bhd), Inaba Atsushi (GlobalSign), Jaime Hablutzel (OISTE Foundation), Jeanette Snook (Visa), Johnny Reading (GoDaddy), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kateryna Aleksieieva (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lilia Dubko (CPA Canada/WebTrust), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Martijn Katerbarg (Sectigo), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Polina Glazyrina (Sectigo), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Sven Rajala (Keyfactor), Tadahiko Ito (SECOM Trust Systems), Tobias Josefowitz (Opera Software AS), Trevoli Ponds-White (Amazon), Tsung-Min Kuo (Chunghwa Telecom), Wendy Brown (US Federal PKI Management Authority)

 

Reply all
Reply to author
Forward
0 new messages