Final Minutes – Server Certificate Working Group Teleconference (28 August 2025)
1. Roll Call
For attendance, see Item 11 below.
2. Note-Well
Dimitris Zacharopoulos reminded participants of the CA/Browser Forum bylaws, including the antitrust policy, code of conduct, and intellectual property rights agreement.
3. Review of Agenda
The agenda was reviewed, and no changes or amendments were proposed.
4. Minutes Approval
The group considered the approval of previous minutes. The minutes from the 17 July 2025 teleconference, prepared by Scott Rea, are nearly complete but pending attendance verification. The minutes from the 31 July 2025 call, prepared by Aaron Gable, appear to have been distributed but had not been reviewed by the Chair. Approval of both sets of minutes was therefore deferred until the next meeting.
5. Membership Applications
The first application was from Baker Tilly in Malaysia, seeking Interested Party status. Discussion clarified that audit firms are not automatically included under the WebTrust associate membership umbrella and may therefore apply independently. Baker Tilly’s application was accepted without objection.
The second application was from Cybertrust Japan, seeking an upgrade from Associate Member to Voting Member status. Having met the necessary requirements, their application was approved by consensus. Their status will be updated, and they will be notified accordingly.
6. DNSSEC Checks for E-Mail Based Domain Validation (Ballot SC-085)
Roman Fischer of SwissSign had raised a question about whether DNSSEC applies to MX record lookups in the context of e-mail domain validation.
The Chair concluded that the discussion should continue on the mailing list. The effective date for DNSSEC enforcement is March 2026, leaving time for clarification.
7. Ballot Status
It was noted that version 2.17 of the TLS Baseline Requirements had been published earlier in the week.
8. Any Other Business
Dimitris noted there was a Bugzilla incident requesting clarification of the definition of “Authorization Domain Name” in Method 3.2.2.4.2. Members agreed that this topic is best suited for the Validation Subcommittee, with potential coordination with the Definitions and Glossary Working Group, as different interpretations of the term could lead to inconsistency.
9. Next Call
The next Server Certificate Working Group call will be held on 11 September 2025.
10. Adjourn
The meeting was adjourned.
11. Attendance
Aaron Gable (Let's Encrypt), Aaron Poulsen (Amazon), Adrian Mueller (SwissSign), Adriano Santoni (Actalis S.p.A.), Alvin Wang (SHECA), Ben Wilson (Mozilla), Brianca Martin (Amazon), Chris Clements (Google), Clint Wilson (Apple), Corey Bonnell (DigiCert), Dean Coclin (DigiCert), Dimitris Zacharopoulos (HARICA), Enrico Entschew (D-TRUST), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Inaba Atsushi (GlobalSign), Iñigo Barreira (Sectigo), Jaime Hablutzel (OISTE Foundation), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Jun Okura (Cybertrust Japan), Karina Sirota (Microsoft), Kateryna Aleksieieva (Asseco Data Systems SA (Certum)), Kate Xu (TrustAsia), Kiran Tummala (Microsoft), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Marco Schambach (IdenTrust), Martijn Katerbarg (Sectigo), Michael Slaughter (Amazon), Michelle Coon (OATI), Miguel Sanchez (Google), Mohd Redha Hamzah (Pos Digicert Sdn. Bhd.), Mrugesh Chandarana (IdenTrust), Nargis Mannan (VikingCloud), Nate Smith (GoDaddy), Nicol So (CommScope), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Roman Fischer (SwissSign), Ryan Dickson (Google), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Tathan Thacker (IdenTrust), Thomas Zermeno (SSL.com), Tim Callan (Sectigo), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Wendy Brown (US Federal PKI Management Authority), Wiktoria Więckowska (Asseco Data Systems SA (Certum)).