> Peter - I'm puzzled.  What does your sentence mean?  What problem is it addressing?
> “Additionally, CAs may use any of the domain validation methods allowed in the version of these Requirements in effect at the time the validation data was collected to validate new certificate issuances as long as this section allows reuse of the validation data.”
> Yes, of course CAs may choose to revalidate domains using a new method after it is adopted, if they choose.  Why do you think we need to say that in Section 4.2.1, which is about reuse of previously collected validation data?  BR 4.2.1 is already permissive (“MAY”), not mandatory, so I would not favor adding the sentence you propose unless it is addressing some problem I’m not aware of.
> Sec.4.2.1 Performing Identification and Authentication Functions
> *** Section 6.3.2 limits the validity period of Subscriber Certificates. The CA MAY use the documents and data provided in Section 3.2 to verify certificate information, provided that the CA obtained the data or document from a source specified under Section 3.2 no more than thirty‐nine (39) months [825 days] prior to issuing the Certificate. ***” 


As I understand it you want to be able to issue a new certificate by validating the FQDN in the certificate using data collected a year (or longer) ago and a validation method from a prior version of the BRs.  As a clear example, consider the following:

You have a customer request a certificate for images.example.com <http://images.example.com/>.  Six months prior, you followed the BRs in effect at the time and used a method which sending an email with a random value to an email address, getting a response using the random value, and ensuring that the email address is one of the example.com registrant, technical contact for example.com or administrative contact for example.com based on information provided via WHOIS.  You want to be able to say “no need to send a new email”.

Now imagine that .com rolls out their spiffy new WHOIS replacement called RDAP.  You may recall that ICANN presented this to the CAB Forum about a year ago at a F2F.  Because of this change by .com, the BRs are updated to say “listed in RDAP for the Base Domain” rather than “listed in the WHOIS record for the Base Domain”.  This would mean that the data collected from a whois server is still able to be used but there is no method to which it can be applied.  So the CA would have to consult RDAP to get the contacts, then check that the email confirmation matches one of the current contacts.  While this seems good to me, it is my understanding that your intent is that validation based on WHOIS would be allowed until the data expires.  The only way to make this work is to allow reuse of the _methods_ in addition to the data.

I hope that helps explain the additional sentence.

Looking at the BRs, you could also address this by adding a method to that is something like “Confirming the Applicant's control over the FQDN by verifying the CA has a completed verification of Applicant authority for an Authorization Domain Name that was completed using a method that was acceptable when the verification was completed.”  Note that refinement is needed to ensure verifications completed per cannot be used as verification for an Authorization Domain Name unless the Authorization Domain Name is the name being verified.


> Looking at your changes in 4.2.1, I don’t think they match what you verbally said on the call today was your goal.  Specifically they do not say that validations completed under prior versions of the BRs are acceptable.    To be clear, I don’t support allowing reuse of completed validations that would not be acceptable under the revised methods, but I think it is important that the proposal is unambiguous. 
> I have mostly heard concern over the change to the requirements around demonstration of control via file ( in this ballot).  I looked back and this method has been unmodified for more than year (https://cabforum.org/pipermail/public/2016-April/007459.html <https://cabforum.org/pipermail/public/2016-April/007459.html>).  I also appears that DNS based validation ( has not had changes in the last year.  This would seem to be plenty of notice for CAs to get their systems updated and determine which domains will need new validations.
> That being said, I suggest adding a sentence to the proposal to avoid any ambiguity.  The revised change to 4.2.1 I propose is:
> "After the change to any validation method specified in the Baseline Requirements or EV Guidelines, a CA may continue to reuse validation data collected prior to the change for the period stated in this BR 4.2.1 unless otherwise specifically provided in the ballot that makes the change to the validation method.  Additionally, CAs may use any of the domain validation methods allowed in the version of these Requirements in effect at the time the validation data was collected to validate new certificate issuances as long as this section allows reuse of the validation data.”
> This harmonizes both interpretations on the definition of “validation data”: both those who interpret “validation data” as only include inputs to validation methods and those who interpret “validation data” as also include outputs of validation methods.
