[Discussion] Ballot SMC015: Allow mDL for authentication of individual identity

41 views
Skip to first unread message

Stephen Davidson

unread,
Feb 10, 2026, 3:48:10 PM (4 days ago) Feb 10
to smcwg-...@groups.cabforum.org

Ballot SMC015: Allow mDL for authentication of individual identity


Summary: 

 

This ballot introduces requirements that a CA or RA must follow to rely upon a Mobile Drivers License (mDL) to provide evidence for the authentication of individual identity.  It allows the use of mDL that conform to ISO/IEC 18013-5 and which may be verified by the CA or RA in conformance with ISO/IEC 18013-7.  The CA or RA shall only accept mDL from an Issuing Authority that is legally authorized by the relevant government or jurisdiction to issue driving licenses.

 

The draft also aligns the subsections of 3.2.4.2 (Validation of individual identity) to correspond more closely with those in 3.2.4.1 (Attribute collection of individual identity). It also includes minor editorial corrections.

 

This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Ben Wilson (Mozilla) and Scott Rea (eMudhra).

 

— Motion Begins —

 

This ballot modifies the “Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates” (“S/MIME Baseline Requirements”), based on Version 1.0.12.

 

MODIFY the Baseline Requirements as specified in the following Redline:

 

https://github.com/cabforum/smime/compare/be9a18ab2b48eb0cbff41d3a268202f700c06c05...42b87e06b876e8808d61cd4735c317b1cfa6d363

 

— Motion Ends —

 

This ballot proposes a Final Maintenance Guideline. The procedure for approval of this ballot is as follows:

 

Discussion (at least 7 days)

 

  • Start time: February 10, 2026 at 21:00:00 UTC
  • End time: February 17, 2026 at 21:00:00 UTC

 

Roman Fischer

unread,
Feb 11, 2026, 1:13:17 AM (3 days ago) Feb 11
to smcwg-...@groups.cabforum.org

Dear Stephen,

 

Did you delete the reference of "ETSI EN 319 403" (line 420) on purpose?

 

Rgds
Roman

--
You received this message because you are subscribed to the Google Groups "S/MIME Certificate WG - Public (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to smcwg-public...@groups.cabforum.org.
To view this discussion visit https://groups.google.com/a/groups.cabforum.org/d/msgid/smcwg-public/BL1PR14MB51434C16860B8E0CD91C225FE562A%40BL1PR14MB5143.namprd14.prod.outlook.com.

Stephen Davidson

unread,
Feb 11, 2026, 9:53:53 AM (3 days ago) Feb 11
to smcwg-...@groups.cabforum.org

Yes – it was previously repeated in the text.

Regards, Stephen

Roman Fischer

unread,
Feb 11, 2026, 10:39:37 AM (3 days ago) Feb 11
to smcwg-...@groups.cabforum.org

Hi Stephen,

 

I thought there may have been two standards, ETSI EN 319 403 and ETSI EN 319 403-1. I'm not the expert on this topic.

 

Anyway, bullet 4 in chapter 8.2 needs to be corrected too, right?

Stephen Davidson

unread,
Feb 11, 2026, 12:51:02 PM (3 days ago) Feb 11
to smcwg-...@groups.cabforum.org

Thanks Roman; this is a good catch.  I had not seen the second mention.

 

ETSI EN 319 403 was superceded by ETSI EN 319 403-1 in 2021 and should not appear in current audits.

 

I will restart the ballot and propose a similar update at TLS BR.

Reply all
Reply to author
Forward
0 new messages