Final Minutes: Validation Subcommittee - 2026-07-23

30 views
Skip to first unread message

Stephen Davidson

unread,
Aug 6, 2026, 10:04:35 PM (yesterday) Aug 6
to CABF Validation Sub Committee (validation@groups.cabforum.org)

Minutes Validation Subcommittee

Meeting: 2026-07-23 CA/Browser Forum Validation Subcommittee Host: Stephen Davidson Duration: 38 minutes

Attendees:

(Taken from recording) Arman Asemani (Apple), Adriano Santoni (Actalis), Ben Wilson (Mozilla), Dustin Hollenback (Apple), Ethan Davis (Google Trust Services), Georgy Sebastian (Amazon Trust Services), Gurleen Grewal (Google Trust Services), Karolina Ruszczynska (Certum), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Luis Cervantes (SSL.com), Mahua Chaudhuri (Microsoft), Martijn Katerbarg (Sectigo), Michelle Coon (OATI), Nate Smith (GoDaddy), Nome Huang (TrustAsia), ONO Fumiaki (SECOM Trust Systems), Rich Smith (DigiCert), Rob White (GoDaddy), Roman Fischer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera), Wayne Thayer (Fastly)

Note-well:

Note-well read by Stephen Davidson

Minutes:

The minutes from the last teleconference (2026-07-09) by Ryan Dickson have been approved. Today's minutes - transcribed by Tom Zermeno, Roman volunteered as backup.

Agenda for July 23, 2026

  1. Note-Well
  2. Approval of Minutes
  3. Ballot Status
    • NS-0100 v2 - Completed discussion 7/22, pending return to voting status
    • SC-100: DNSSEC Clarification and Consolidation - Discussion period extended through the end of the month; see mailing list for details
    • SC-101v2 ADN Processing Ballot - Passed and is in IPR through 2026-08-06
    • SC-102 EV Domain Ownership Validation - Passed and is in IPR through 2026-08-13
  4. New Topic: Set Presence of AIA extension to SHOULD for Subscriber Certificates
  5. New Topic: High Risk language from TLS BRs and EVG
  6. Time Permitting: Face to Face 68 - Vienna - Potential meeting topics

AIA

The high-level table has a MUST requirement, when all lower options are MAY or SHOULD... There is no MUST requirement in the options, so why is AIA as a whole a MUST? The proposal is to change the table in 7.1.2.7.6 so that the AIA extension presence is a SHOULD (instead of a MUST) and update 7.1.2.7.7 by adding "If present" to the beginning of the explanation sentence. There were no objections to this plan. Ethan will be moving this to a ballot, with Roman and Stephen as endorsers.

High Risk Certificates

Most recently discussed at the Houston F2F; the term is undefinable because it is subjective and references mentioned in the BRs do not exist any longer. The proposal would affect both EVG and BRs by removing the definition. Second step - in section 4.2.1 there are requirements for CAs to have procedures related to the HR certs and impose those procedures on Delegated Third Parties - this would also be removed as per the proposal. Section 4.9.1.1 is proposed to be modified by removing criteria #10 and replacing the statement with "removed" (or something equivalent) to maintain the numbering of items. Additional updates to 3.2.2.7 (2) were also proposed to reduce the burden of reviewing mixed character set domain names with HR domains.

Face-To-Face

  • Dustin - re: SC-102 EVGs are very antiquated. Paring down the EVGs to only unique regulations related to EV Certs would be a good project. Should the Validation Subcommittee spend energy reviewing the BRs and possibly writing the ballot?
  • Scott suggested "how do we define and evaluate Authoritative Sources, especially with regard to Automation?" He intends to be ready with a straw poll by 2026-08-22.

AOB?

None

Close Meeting

Next meeting in 2 weeks 2026-08-06

 

Reply all
Reply to author
Forward
0 new messages