CA/Browser Forum
Forum Plenary Meeting Minutes
July 16, 2026
Roll Call
Dean Coclin chaired the meeting. The meeting commenced immediately following the Server Certificate Working Group meeting. Recording was already in progress and the Note Well had previously been read. The list of attendees appears below.
Review of Agenda
No changes to the agenda were proposed.
Approval of Minutes
Approval of the July 2, 2026, minutes was deferred because draft minutes were not yet available.
Server Certificate Working Group Update
Dimitris Zacharopoulos summarized the work of the Server Certificate Working Group. He reported that:
Validation Subcommittee Update
Stephen Davidson reported that the Validation Subcommittee recently discussed:
Code Signing Working Group Update
Martijn Katerbarg reported:
S/MIME Working Group Update
Stephen Davidson reported:
Network Security Working Group Update
Clint Wilson reported that NETSEC-010 required procedural correction because the original proposer was ineligible.
The ballot has therefore been republished with a qualified proposer while retaining the same statement and endorsers. The discussion period has restarted and voting is expected to resume the following week.
Definitions and Glossary Working Group Update
Polina Glazyrina reported significant progress on the glossary document and expects to publish the current draft to GitHub early the following week.
Ben Wilson reported reviewing the current draft and identified several definitions that may require future refinement, including: Application Software Supplier, Baseline Requirements, Certification Authority, Maximum Validity Period, Reliable Data Source, Reliable Method of Communication, and Trustworthy System.
He noted that terminology describing organizations versus certification authorities remains inconsistent across a variety of documents. He also suggested that, where appropriate, future glossary definitions could reference existing IETF RFC definitions rather than duplicating them.
Martijn Katerbarg recommended first completing and publishing the glossary before attempting broader editorial improvements, a suggestion generally supported by the discussion.
Tadahiko Ito raised an additional consistency concern regarding phrases such as "byte-for-byte identical," "character-for-character identical," and similar wording that appears throughout Forum documents. Ben suggested this might eventually be addressed by defining a common term such as "identical" within the glossary.
Forum Infrastructure Update
No update was provided.
IPR Update
Ben Wilson reported that Cisco and Microsoft have now submitted their updated IPR agreements. He also noted that several organizations remaining on the membership lists have not executed the new agreement but have also not been active participants. Dean suggested notifying those organizations as a courtesy before any suspension actions are taken, and Ben agreed to prepare and send those notifications.
Dimitris additionally reported that Microsoft had inadvertently been included in the vote count for a recently completed Server Certificate ballot before its updated IPR agreement had been received. Removing Microsoft's vote would not change the outcome of the ballot. After brief discussion, the consensus was that no correction to the recorded ballot result was necessary now that the updated IPR agreement has been executed.
Any Other Business
Webex Account
Dean thanked Dimitris for successfully renewing the Forum's Webex account, noting that the renewal process had required considerable effort.
Upcoming Elections
Dean reviewed the schedule for the 2026 Forum elections, including:
Members were encouraged to begin discussing potential candidates within their Working Groups.
Vienna Face-to-Face Meeting
Dean reminded members to register for the September Vienna meeting and noted current attendance figures. Members were encouraged to register promptly, particularly for the evening event because capacity is limited.
Martijn also noted that dates for the 2027 Scottsdale face-to-face meeting have now been confirmed and published on the wiki (Feb 23-25, 2027).
Discussion Regarding Formal Legal Formation of the Forum
Martijn proposed adding a dedicated agenda item to the Vienna face-to-face meeting to discuss whether the CA/Browser Forum should become formally recognized legal entity.
Dean agreed this would be appropriate, observing that Ben Wilson had previously performed substantial research on possible formation models and that those materials could serve as the basis for discussion.
The ensuing discussion focused on both the potential benefits and the practical implications.
Trevoli Ponds-White asked whether the discussion should concentrate primarily on the mechanics of incorporation ("how") or first determine whether incorporation is desirable in principle.
Chris Clements suggested that the Forum should first evaluate whether legal formation is actually necessary before discussing implementation details. While acknowledging the recent administrative challenges associated with renewing the Webex account, he questioned whether those difficulties alone justified creating a formal legal entity. He noted that incorporation would introduce additional legal, administrative, financial, and governance obligations that could outweigh any operational benefits. He also observed that recent experience obtaining updated IPR agreements from all members illustrated the complexity involved in managing organizational processes across a global volunteer forum.
Martijn responded that understanding the available incorporation models and their associated obligations would help members better evaluate whether the anticipated benefits justify the additional overhead, suggesting that the questions of whether and how are closely connected.
Dean noted that legal formation might not be the only possible solution to the Forum's administrative needs. As Ben's prior research indicated, certain existing nonprofit organizations may be willing to sponsor or administer Forum resources without requiring the Forum itself to become incorporated. He suggested that these alternatives should also be considered during the broader discussion.
The meeting concluded that legal formation would be placed on the agenda for discussion during the Vienna face-to-face meeting, where members could more thoroughly examine both the merits of legal formation and the practical options available before deciding whether any future action is warranted.
Next Meeting
The next Plenary meeting will be held on 30 July 2026.
Adjournment
The meeting then adjourned.
Attendees: Aaron Gable (Let's Encrypt), Aaron Poulsen (SSL.com), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Arman Asemani (Apple), Ben Wilson (Mozilla), Chris Clements (Google), Clint Wilson (Apple), Daryn Wright (Apple), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Dustin Hollenback (Apple), Georgy Sebastian (Amazon), Gurleen Grewal (Google), Hazhar Ismail (MSC Trustgate Sdn Bhd), Inaba Atsushi (GlobalSign), Jaime Hablutzel (OISTE Foundation), Jeanette Snook (Visa), Johnny Reading (GoDaddy), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kateryna Aleksieieva (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lilia Dubko (CPA Canada/WebTrust), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Martijn Katerbarg (Sectigo), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Polina Glazyrina (Sectigo), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Sven Rajala (Keyfactor), Tadahiko Ito (SECOM Trust Systems), Tobias Josefowitz (Opera Software AS), Trevoli Ponds-White (Amazon), Tsung-Min Kuo (Chunghwa Telecom), Wendy Brown (US Federal PKI Management Authority)