Proposed Approach for Phase 1 of Revocation Circumstances Work

68 views
Skip to first unread message

Ben Wilson

unread,
Aug 27, 2026, 1:07:42 AMAug 27
to server...@groups.cabforum.org

Hi all,

Ahead of our Server Certificate Working Group call, I am circulating this proposed approach for Phase 1 of the work on the revocation circumstances in TLS BR §4.9.1.1.

I hope this allows us to use our SCWG time to discuss the approach and identify concerns.

Phase 1 will focus on the underlying revocation circumstances before we attempt to map them to CRL reason codes. In particular, I propose that we:

  1. Develop a taxonomy of the events and conditions that should require revocation.
  2. Evaluate the existing 16 circumstances against that taxonomy to determine whether they are complete, appropriately scoped, and clearly expressed. (I do not see much value in tracing the history of these circumstances. Most were in the original EV Guidelines from two decades ago.)
  3. Identify provisions that either overlap, combine conceptually different circumstances, operate as broad catch-alls, or aim at the wrong target (e.g. the source of the obligation rather than the underlying problem).
  4. Identify circumstances that may be missing or insufficiently explicit.
  5. Test the analysis against actual incidents and hypothetical examples, including circumstances that might be asserted by Subscribers, to determine whether different CAs would classify the same facts consistently.
  6. Once the taxonomy and analysis are reasonably settled, prepare a set of preliminary proposed revisions with sufficient notes and explanatory examples.

Possible initial work products could include:

  • a taxonomy of underlying revocation circumstances;
  • a table comparing that taxonomy with the current provisions;
  • a collection of actual and hypothetical test cases; and
  • an issues list identifying overlaps, ambiguities, gaps, and drafting questions.

I would also like to discuss establishing a publicly readable but privately managed GitHub repository where we can collect research, examples, tables, issues, and draft materials. Write access could be limited to project participants. If needed, we could also use a private Google Drive folder for preliminary collaboration or material not yet ready for public circulation. GitHub should ordinarily serve as the source of truth for non-sensitive materials, and any resulting formal proposal would proceed through the Working Group’s normal repository and ballot processes.

Finally, I would like to learn what level and form of engagement we should expect from the group. I am not proposing the formation of a subcommittee, and I can undertake much of the initial work, but several others have expressed interest in participating. We should consider how best to organize that participation and communicate about the work. For example, should we create a separate mailing list, or should we continue using the Server Certificate WG list with a consistent identifier, such as “[Revocation Circumstances],” in the subject line? My initial inclination is to use this existing list unless the volume of discussion later warrants a separate one. I would also like to determine whether there is general agreement on the scope and sequence of Phase 1, what level of participation others anticipate, and how we should organize the work and communications.

Thanks,

Ben


Reply all
Reply to author
Forward
0 new messages