Hello all,
The Extended Validation Guidelines (EVGs) currently require CAs to perform a WHOIS check when re‑using previously completed domain‑related identity verification for existing EV Subscribers. This requirement comes from older validation practices that depended on public WHOIS data to confirm registrant identity and detect domain transfers.
Today, authoritative domain registration information is normally obtained through RDAP, registry systems, or registrar‑provided data. In many cases, WHOIS data is redacted, inconsistent, or unavailable. As a result, the EVG requirement to perform a WHOIS check during reuse is outdated, operationally difficult, and inconsistent with how domain registration data is validated under the Baseline Requirements (specifically BR Section 3.2.2.7).
This proposed change updates the EVGs so that reuse of domain‑related identity information relies on domain registration data consistent with EVG Section 3.2.2.7, without introducing any EV‑specific mechanisms beyond what the BRs already require. It also clarifies that the CA must confirm that the Domain Name remains registered to the same Legal Entity previously validated for the EV Certificate.
Draft change for review:
https://github.com/cabforum/servercert/pull/658/changes#diff-f7368cf58de0586cb0ad80e242205ab3272314af71f4115b99187f49521da529
Feedback is appreciated.
Thank you,
Dustin