CA/Browser Forum explained

CA/Browser Forum
Type:Professional organization
Founded Date:2005
Focus:Provide internet security industry standards for certificate authorities and certificate consumers such as Internet browsers

The Certification Authority Browser Forum, also known as the CA/Browser Forum, is a voluntary consortium of certification authorities, vendors of Internet browser and secure email software, operating systems, and other PKI-enabled applications that promulgates industry guidelines governing the issuance and management of X.509 v.3 digital certificates that chain to a trust anchor embedded in such applications. Its guidelines cover certificates used for the SSL/TLS protocol and code signing, as well as system and network security of certificate authorities.

, the consortium includes 54 certificate issuers, 11 certificate consumer vendors, and industry standards and audit bodies including the European Accredited Conformity Assessment Bodies’ Council (ACAB’C), the WebTrust Task Force, and the European Telecommunications Standards Institute (ETSI).[1]

Working groups

The CA/Browser Forum has these working groups:

History

In 2005, Melih Abdulhayoglu of the Comodo Group organized[2] the first meeting of CA/Browser Forum. The first meeting was held in New York City. This was followed by a meeting in November 2005 in Kanata, Ontario, and a meeting in December, 2005, in Scottsdale, Arizona with the main objective to enable secure connections between users and websites.

In addition to CA/Browser Forum members, representatives of the Information Security Committee of the American Bar Association Section of Science & Technology, Law and the Canadian Institute of Chartered Accountants participated in developing the standards for issuing and managing Extended Validation SSL/TLS certificates. Version 1.0 of the EV Guidelines was adopted on 7 June 2007.[3]

In November 2011, the CA/Browser Forum adopted version 1.0 of the "Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates" intended to provide minimum security standards for all browser-trusted SSL/TLS certificates. Subsequent versions expanded the Baseline Requirements to directly incorporate requirements from browser root store policy programs such as those of Mozilla and Microsoft.

In January 2013 the CA/Browser Forum's first "Network and Certificate System Security Requirements" took effect defining best practices for the general protection of CA networks and supporting systems.

In February 2013 a new industry group, the Certificate Authority Security Council (CASC), was formed with a mission that includes promoting CA/Browser Forum standards. Membership requires adherence to CA/Browser Forum standards.[4] The CASC's founding members consisted Comodo CA (now Sectigo), Symantec (now DigiCert),[5] Trend Micro (now Entrust), DigiCert, Entrust,[6] GlobalSign[7] and GoDaddy.[8] [9] [10] [11] [12]

In August 2020, the S/MIME Certificate Working Group[13] was chartered to create a baseline requirement applicable to CAs that issue S/MIME certificates used to sign, verify, encrypt, and decrypt email.

In September 2020, the CA/Browser Forum adopted version 2.0 of the "Baseline Requirements for the Issuance and Management of Publicly-Trusted Code Signing Certificates", which had previously been maintained outside the group.

In January 2023, the CA/Browser Forum adopted version 1.0 of the "Baseline Requirements for the Issuance and Management of Publicly‐Trusted S/MIME Certificates", It defined four types of S/MIME certificate standards. Mailbox‐validated, Organization‐validated, Sponsor‐validated and Individual‐validated.[14]

External links

Notes and References

  1. Web site: Members of the CA - Browser Forum - Over 50 CAs and All Major Browsers . CA/Browser Forum . 3 May 2022 . https://web.archive.org/web/20220503124452/https://cabforum.org/members/ . 2022-05-03. live.
  2. Web site: How Can We Improve Code Signing?. 9 May 2008 .
  3. Web site: GUIDELINES FOR THE ISSUANCE AND MANAGEMENT OF EXTENDED VALIDATION CERTIFICATES v1.0. The CA/Browser Forum.
  4. Web site: About the CA Security Council. 27 January 2013. 20 February 2014. 14 July 2017. https://web.archive.org/web/20170714183658/https://casecurity.org/casc/. dead.
  5. Web site: Let's Build a More Secure Future. https://web.archive.org/web/20130217082728/http://www.symantec.com/connect/blogs/let-s-build-more-secure-future. dead. February 17, 2013.
  6. Web site: Entrust Joins World's Leading Certificate Authority.
  7. Web site: GlobalSign joins the Certificate Authority Security Council to upgrade internet security. 2013-04-02. 2015-07-02. https://web.archive.org/web/20150702184430/http://www.thepaypers.com/news/e-identity-security-online-fraud/globalsign-joins-the-certificate-authority-security-council-to-upgrade-internet-security/750211-26. dead.
  8. Web site: Get more done with Microsoft Office 365 from GoDaddy. 2013-04-02. 2013-11-11. https://web.archive.org/web/20131111090725/http://inside.godaddy.com/announcing-certificate-authority-security-council/. dead.
  9. Web site: Authentication Security News, Analysis, Discussion, & Community. dead. https://archive.today/20130410174711/http://www.darkreading.com/authentication/167901072/security/news/240148546/major-certificate-authorities-unite-in-the-name-of-ssl-security.html. 2013-04-10.
  10. Web site: Multivendor power council formed to address digital certificate issues - Network World . 2013-04-02 . dead . https://web.archive.org/web/20130728114851/http://www.networkworld.com/news/2013/021413-council-digital-certificate-266728.html . 2013-07-28 .
  11. Web site: Website Certificate Authorities Set Up Security Council for Advocacy, Research.
  12. Web site: SSL Certificate Authority Security Council Takes Root | Electronic Staff . 2013-04-02 . dead . https://web.archive.org/web/20140714155147/http://electronicstaff.com/2013/ssl-certificate-authority-security-council-takes-root . 2014-07-14 .
  13. CA/Browser Forum S/MIME Certificate Working Group https://cabforum.org/working-groups/smime-certificate-wg/
  14. Web site: CA/Browser Forum S/MIME Baseline Requirements . 4 April 2023 . CA/Browser Forum.