[cabf_validation] F2F Topics

Peter Bowen pzb at amzn.com
Fri Mar 17 10:51:26 MST 2017


Rick,

For #11, it was already raised on the public list (https://cabforum.org/pipermail/public/2017-February/009807.html) that revocation should be required, based on a conversation I had with Kirk.  At least three CAs (Actalis, Entrust, and WoSign) have expressed support for the idea of requiring "seek out and revoke all such certs”

Thanks,
Peter

> On Mar 17, 2017, at 10:42 AM, Rick Andrews via Validation <validation at cabforum.org> wrote:
> 
> Jeremy, thanks for pulling this together. One nit: It’s ASN.1, not ANS.1. But more substantial: this is a long agenda, I suggest we try to prioritize because we’re unlikely to get through it all.
>  
> The ones of most interest to me are 1, 12, 4 and 6.
>  
> I also want to point out that unlike our biweekly VWG calls, the browsers are likely to be sitting in and listening/participating to our discussions. Caveat emptor. We may want to avoid discussing #11, lest the browsers agree it’s a great idea to force us to seek out and revoke all such certs.
>  
> -Rick
>  
> From: Validation [mailto:validation-bounces at cabforum.org] On Behalf Of Jeremy Rowley via Validation
> Sent: Friday, March 17, 2017 10:09 AM
> To: CA/Browser Forum Validation WG List <validation at cabforum.org>
> Cc: Jeremy Rowley <jeremy.rowley at digicert.com>
> Subject: [cabf_validation] F2F Topics
>  
> Hi all, 
>  
> I’m gathering the topics for the validation WG face to face coming up. Here’s what I have:
>  
> 1.       Ballot 190 – Waiting for one more endorser
> 2.       Ballot 191 – Waiting for endorsers
> 3.       Ballot 192 – Waiting for feedback from Doug
> 4.       Use of RAs in validation
> a.       Translators
> b.      Document providers
> c.       Document verifiers
> d.      Issuance approvers
> 5.       IP Address validation document revision
> 6.       HTTP validation discussion
> 7.       Contents of subordinate certificates (CN field ballot creation)
> 8.       ANS.1 ballot creation
> 9.       Permitting other addresses (such as PO boxes) in certificates
> 10.   Getting rid of address of existence from the BRs.
> 11.   What should we do about old OV certs? 
> 12.   Ballot to add the remaining methods into the BRs (revisions to 169)
>  
> Let me know if there’s anything you’d like to add. Thanks!
>  
> Jeremy
> _______________________________________________
> Validation mailing list
> Validation at cabforum.org
> https://cabforum.org/mailman/listinfo/validation



More information about the Validation mailing list