Skip to content

Conversation

@wthayer
Copy link
Owner

@wthayer wthayer commented Feb 28, 2024

No description provided.

wthayer and others added 12 commits February 28, 2024 11:09
…forum#514) (cabforum#543)

* SC-077: Update WebTrust Audit name in Section 8.4 and References (cabforum#514)

* Add updated WebTrust Audit name

Update 8.4 to reference updated WebTrust document names

* Update BR.md

---------

Co-authored-by: Clint Wilson <clintw@apple.com>

* Update BR.md

New TLS BRs version according to ballot SC77

---------

Co-authored-by: Clint Wilson <clint@wilsonovi.com>
Co-authored-by: Clint Wilson <clintw@apple.com>
cabforum#552)

* SC-078 - Subject organizationName alignment for DBA / Assumed Name (cabforum#545)

* Align with EVG and SBRs

* Align IV with OV

* Remove AssumedName Usage

Co-authored-by: Corey Bonnell <corey.j.bonnell@outlook.com>

* Remove AssumedName Usage

Co-authored-by: Corey Bonnell <corey.j.bonnell@outlook.com>

---------

Co-authored-by: Corey Bonnell <corey.j.bonnell@outlook.com>

* Update BR.md

Update of date, version, ...

---------

Co-authored-by: Martijn Katerbarg <martijn.katerbarg@sectigo.com>
Co-authored-by: Corey Bonnell <corey.j.bonnell@outlook.com>
* Ballot SC-XX: Clarify and improve OCSP requirements

This ballot attempts to address three concerns:
- The confusion around "reserved" serials, which do not actually exist because all Precertificate serials are assumed to also exist in corresponding Certificates and are therefore actually "assigned";
- Confusion around whether, and how quickly, OCSP responders must begin providing authoritative responses for Certificates and Precertificates; and
- Confusion around whether and how the OCSP requirements apply to Certificates which do not contain an AIA OCSP URL, but for which the CA's OCSP responder is still willing to provide responses.

Addresses mozilla/pkipolicy#280
Addresses cabforum#422

* Respond to comments, and reorganize further

* Empty line before bullets

* Address comments

* Use singular, use "published or made available"

* Use the singular even more

* Discussion period feedback from Trev

* Update BR.md

---------

Co-authored-by: Iñigo Barreira <92998585+barrini@users.noreply.github.com>
…d Subordinate CA Certificate (cabforum#544)

* Allow more than one Certificate Policy in a Cross-Certified Subordinate CA Certificate

* Add exception Subscriber Certificates that chain up directly to the Certificate issued under this Certificate Profile

* Update policyIdentifier description

* Remove condition, a Cross-Certified Subordinate CA Certificate MUST always contain this extension

Co-authored-by: Corey Bonnell <corey.j.bonnell@outlook.com>

* Update BR.md

---------

Co-authored-by: Corey Bonnell <corey.j.bonnell@outlook.com>
Co-authored-by: Iñigo Barreira <92998585+barrini@users.noreply.github.com>
cabforum#560)

* Ballot SC-080 V3: "Sunset the use of WHOIS to identify Domain Contacts and relying DCV Methods" (cabforum#555)

BRs release version 2.1.2
Rebase to current version of BRs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants