Standards
Most PKI consultancies read the standards. I write them.
I’ve authored several RFCs at the IETF and proposed or endorsed twenty ballots at the CA/Browser Forum across the Server Certificate, Code Signing, and S/MIME working groups. That’s not a credential I list for decoration: it’s the reason I can tell you what a requirement actually means and why it was written that way.
CA/Browser Forum Ballots
| Date | Ballot | Working Group | Role | Title |
|---|---|---|---|---|
| 2026-06-16 | CSC-32 | Code Signing | Endorser | Make a Reserved Policy OID mandatory |
| 2026-06-03 | SC087v2 | Server Certificate | Proposer | Registration Number Improvement for EV Certificates |
| 2025-11-10 | SC-086v3 | Server Certificate | Proposer | Sunset the Inclusion of IP Reverse Address Domain Names |
| 2025-01-28 | SC084 | Server Certificate | Endorser | DNS Labeled with ACME Account ID Validation Method |
| 2025-01-23 | SC083v3 | Server Certificate | Endorser | Winter 2024–2025 Cleanup Ballot |
| 2024-08-05 | SC075 | Server Certificate | Endorser | Pre-sign linting |
| 2024-07-01 | CSC-25 | Code Signing | Endorser | Import EV Guidelines to CS Baseline Requirements |
| 2024-02-01 | SC068 | Server Certificate | Endorser | Allow VATEL and VATXI for organizationIdentifier |
| 2024-01-08 | SMC05 | S/MIME | Proposer | Adoption of CAA for S/MIME |
| 2023-10-30 | CSC-20 | Code Signing | Proposer | Restore Version Reference to EV Guidelines |
| 2022-11-11 | SC058 | Server Certificate | Endorser | Require distributionPoint in sharded CRLs |
| 2022-10-25 | SC056 | Server Certificate | Proposer | 2022 Cleanup |
| 2022-08-18 | CSC-15 | Code Signing | Proposer | Summer 2022 Cleanup |
| 2022-05-26 | CSC-14 | Code Signing | Proposer | Convert Code Signing Baseline Requirements to RFC 3647 Framework |
| 2022-03-24 | SC054 | Server Certificate | Endorser | Onion Cleanup |
| 2022-01-26 | SC053 | Server Certificate | Proposer | Sunset for SHA-1 OCSP Signing |
| 2021-09-09 | CSC-9 | Code Signing | Endorser | Spring 2021 Cleanup and Clarification |
| 2021-07-22 | SC048v2 | Server Certificate | Proposer | Domain Name and IP Address Encoding |
| 2021-05-01 | SC044 | Server Certificate | Endorser | Clarify Acceptable Status Codes |
| 2018-04-10 | 219 | Forum (pre-WG plenary) | Proposer | Clarify handling of CAA Record Sets with no “issue”/“issuewild” property tag |
IETF RFCs
| RFC | Title | Authors |
|---|---|---|
| 9919 | The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume Environments | T. Ito, C. Wilson, C. Bonnell, S. Turner |
| 10007 | Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) Validation | C. Bonnell, T. Ito, T. Okubo |
| 9598 | Internationalized Email Addresses in X.509 Certificates | A. Melnikov, W. Chuang, C. Bonnell |
| 9500 | Standard Public Key Cryptography (PKC) Test Keys | P. Gutmann, C. Bonnell |
| 9495 | Certification Authority Authorization (CAA) Processing for Email Addresses | C. Bonnell |
What this means for your organization
Requirements don’t surprise you. Ballots go through discussion, revision, and voting before they take effect, and effective dates are often months out. If you’re watching that process (or talking to someone who is watching), a sunset or a new certificate profile requirement becomes a planned project instead of a last-minute fire drill or an incident. I can tell you what’s in flight, what’s likely to pass, and what it will take for your organization to comply.
Ambiguity gets resolved at the source. Baseline Requirements language is dense and occasionally contradictory. A meaningful share of the ballots above exist precisely because something was unclear or wrong and needed fixing. When your team disagrees about what a clause requires, I’ve seen (or participated in) the argument that produced the clause, and where the text is broken. Most importantly, I know how to get it changed rather than working around it forever.
Your position can be represented. If a proposed requirement is unworkable for your infrastructure, that objection carries more weight raised during the ballot discussion than after the effective date. Standards bodies respond to specific, technically grounded feedback from people who have to implement the result.
Start a consulting conversation →