Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EVGs: Remove references to code signing and focus language on TLS #303

Open
castillar opened this issue Aug 25, 2021 · 4 comments
Open

EVGs: Remove references to code signing and focus language on TLS #303

castillar opened this issue Aug 25, 2021 · 4 comments
Labels
clean-up Items for future clean-up ballot enhancement ev-guidelines Server Certificate CWG - Extended Validation Guidelines

Comments

@castillar
Copy link
Contributor

With the CSCWG's work on the EV code-signing guidelines, we should remove the references to code signing from the EVGs, allowing them to focus solely on TLS usage to match the Baseline Requirements.

@castillar castillar added enhancement ev-guidelines Server Certificate CWG - Extended Validation Guidelines labels Aug 25, 2021
@sleevi
Copy link
Contributor

sleevi commented Aug 25, 2021

@castillar For ease of reference, could you provide an example of what prompted this?

@castillar
Copy link
Contributor Author

Sure! What prompted it was these two lines:

Introduction:

Although initially intended for use in establishing Web-based data communication conduits via TLS/SSL protocols, extensions are envisioned for S/MIME, time-stamping, VoIP, IM, Web services, etc.

§1 Scope:

This version of the Guidelines addresses only requirements for EV Certificates intended to be used for SSL/TLS authentication on the Internet and for code signing. Similar requirements for S/MIME, time-stamping, VoIP, IM, Web services, etc. may be covered in future versions.
(Emphasis added)

We could also consider removing the definition for 'Suspect Code', although that one might be useful at some point if, for instance, the EVGs mandate revocation of certificates for sites found to be distributing Suspect Code.

@castillar
Copy link
Contributor Author

Great point from outside discussion: the SMCWG charter encourages re-use of the EVGs, so we may want to instead modify this language to remove the code-signing line from the scope and instead promote the EVGs as a basis for others.

@castillar
Copy link
Contributor Author

For instance, we could leave the Introduction reference and then change the Scope:

This version of the Guidelines addresses only requirements for EV Certificates intended to be used for SSL/TLS authentication on the Internet and for code-signing. However, the Working Group encourages the re-use of these guidelines as a basis for similar requirements for S/MIME, time-stamping, VoIP, IM, Web services, etc. may be covered in future versions.

@barrini barrini added the clean-up Items for future clean-up ballot label May 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
clean-up Items for future clean-up ballot enhancement ev-guidelines Server Certificate CWG - Extended Validation Guidelines
Projects
None yet
Development

No branches or pull requests

3 participants