22 April 2013

Announcing the formation of the Code Signing Working Group - Call for Participants



The CA/Browser Forum has chartered a Code Signing Working Group, the purpose of which is to come up with Baseline Requirements to reduce the incidences of signed malware. The CA/Browser Forum would like to invite interested third parties to participate. The working group meets bi-weekly by phone and will have its first face to face meeting in Munich on June 13th to coincide with the regular CA/Browser Forum meeting.

Interested parties will need to:

  1. Review the Intellectual Property Rights policy (https://cabforum.org/IPR_Policy_V1.pdf) and complete the IPR agreement which can be found here: https://cabforum.org/IPR_Agreement_V1.pdf
  2. Send an email to questions@cabforum.org with your name, organization (if applicable), contact details and the signed agreement with the subject: Code Signing Working Group Participation

Once the Chair determines all is in order, you will be added to the mailing list and invited to the conference calls.

As the title of this group states, this is a Working Group, meaning everyone is expected to contribute in some fashion. Please do not apply if you can't devote time to attend and participate in the discussion. Although there is no deadline for application, the group has had its first organizational meeting and the sooner you can join the better to get the full context of the discussions.



4 February 2013

Guidance on the Deprecation of Internal Server Names and Reserved IP Addresses



This document explains the changes to Certification Authority support for internal server names and reserved IP dddresses and the reasons behind the new rules that were introduced in the Baseline Requirements for the Issuance and Management of Publicly Trusted Certificates, Version 1.0 that took effect effect on July 1, 2012:
Guidance on the Deprecation of Internal Server Names and Reserved IP Addresses



17 January 2013

CA/Browser Forum adopts Bylaws



In late November, the CA/Browser Forum adopted its first formal bylaws that document and update the forum's rules of governance, including rules for public participation in the forum's activities.



9 August 2012

CA/Browser Forum adopts Intellectual Property Rights (IPR) policy



In order to protect the Intellectual Property of its members, the CA/Browser forum has adopted an IPR policy which has been signed by over 30 companies including the biggest names in the technology industry.
The complete list of current members is here: http://www.cabforum.org/forum.html.
The policy can be found on the documents page: http://www.cabforum.org/documents.html



2 August 2012

Forum Discussions are Now Public



The CA/Browser Forum has created a public mailing list, intended to be used for normal CA/Browser Forum discussions, which can be read (but not posted to) by interested parties. Visit the list's web page to sign up.



5 July 2012

Governance Proposals Published, Advancing Toward Adoption



During last week's meeting in Norway, the CA/Browser Forum agreed to advance four governance proposal through a voting process that will result in the decision to keep the current structire in place, or to adopt one of the four new proposals. The proposals are published here for public review and comment:


Please send comments to public@cabforum.org. Please note that this is a moderated mailing list normally available for posting only to CA/Browser Forum members, but posts on this topic from non-forum members will be manually approved.



15 April 2012

CA/Browser Forum Publishes Submissions



All responses that the CA/Browser Forum received from the call for position papers and statements of interest on organizational reform have been published to the Web site:



28 February 2012

CA/Browser Forum Announces Organizational Reform Working Group



The CA/Browser Forum is a voluntary organization of leading certification authorities (CAs) and vendors of Internet browser software and other applications.


At the twenty fifth face to face meeting of the CA/Browser Forum, held in Santa Clara, California, USA on February 22 and 23rd, 2012, the membership agreed to form a working group on organizational reform. The task of this group will be to develop and present to the full organization, by April 16th, proposals for a new charter and bylaws.


The CA/Browser Forum recognizes the growing importance of the PKI marketplace as a critical piece of Internet infrastructure, and the need to continue to safeguard and advance the public's trust in the Internet as a secure place for communication, socialization and commerce. The goal of the reform will be to evolve the organization into a more mature and capable, multi-stakeholder forum that can promote the growth and maintenance of the public PKI and certificate ecosystem in the interests of Internet security and the broader public good.


Key topics to be addressed by the special working group include:


In support of this process, the special working group is soliciting short (no more than 750 words, please) position papers and statements of interest from organizations and individuals on these topics. We encourage stakeholders to submit their comments to questions@cabforum.org now through March 30, 2012. All submissions will be posted publicly on the CA/Browser Forum website. (www.cabforum.org)



14 December 2011

CA/Browser Forum Approves Baseline Requirements for SSL/TLS Certificates


First industry-wide standard for the issuance and management of SSL/TLS digital certificates

DOWNLOAD THE DOCUMENT


The CA/Browser Forum has released the "Baseline Requirements for the Issuance and Management of Publicly Trusted Certificates," the first international baseline standard for the operation of Certification Authorities (CAs) issuing SSL/TLS digital certificates natively trusted in browser software.


SSL/TLS digital certificates are used to authenticate the ownership of websites and other online resources, as well as to encrypt information for privacy as it crosses the Internet and other networks.


"SSL/TLS certificates are a critical part of the Internet's security infrastructure, combining proven technical standards with the capability to scale to handle millions of websites and the wide array of user software," said Tim Moses, Chairman of the CA/Browser Forum. "The new Baseline Requirements will improve the reliability and accountability of SSL/TLS issuance for relying parties by establishing baseline standards for all types of SSL/TLS certificates from all publicly-trusted CAs."


The Baseline Requirements draw upon best practices from across the SSL/TLS sector to provide clear standards for CAs on important subjects including verification of identity, certificate content and profiles, CA security, revocation mechanisms, use of algorithms and key sizes, audit requirements, liability, privacy and confidentiality, and delegation (including external sub-CAs and registration authorities).


The Baseline Requirements become effective on July 1, 2012 allowing CAs time to bring their SSL/TLS policies and practices into compliance with the standard. The CA/B Forum intends to continue development of the Baseline Requirements to address the evolving risks and threats involving the issuance or use of SSL/TLS certificates.


The CA/Browser Forum was formed in 2006 and previously created the "Extended Validation" (EV) standard for SSL/TLS. EV was designed for banks and other high profile websites providing enhanced confirmation of the legitimacy of a website and the identity of its owner, consistent across all EV-issuing CAs.


"With the Baseline Requirements, for the first time we will have a consistent international standard for the issuance of all SSL/TLS, including the many variations of Domain Validation and Organisation Validation," said Eddy Nigg of the StartCom CA. "This has been a multiyear effort involving more than 50 organisations including the major browser suppliers and CAs from around the world, as well as representatives from the Internet standards and audit/legal community along with major relying parties that use SSL/TLS."


Certification Authority members of the CA/Browser Forum range from the large multinational CAs to smaller issuers focused on geographic regions or specific industries. Major CAs have already voiced their commitment to implement the Baseline Requirements targeting the 2012 effective date. These include CA/Browser Forum members Symantec, Go Daddy, Comodo, GlobalSign, DigiCert, Entrust, StartCom, TrustWave, QuoVadis, Certum, T-Systems, Izenpe, and BuyPass representing more than 94% of all valid public SSL/TLS according to the independent Netcraft survey.


The CA/Browser Forum has requested that internet browsers and operating systems adopt the Baseline Requirements among their conditions to distribute CA root certificates in their software.


According to Kathleen Wilson of Mozilla, "Four years ago the CA/Browser Forum released the Extended Validation guidelines that established consistent standards for identity validation. The Baseline Requirements provide a foundation for best practices across the industry by defining a single, consolidated set of essential standards for all SSL/TLS certificates for the first time."


The CA/B Forum has also requested that the major audit regimes used by CAs, WebTrust and ETSI, develop audit criteria to assess compliance with the Baseline Requirements.