Skip to content

SC105: Remove High Risk language from TLS BR and EVG - #678

Open
srdavidson wants to merge 7 commits into
cabforum:mainfrom
srdavidson:HIgh-Risk-Language
Open

srdavidson wants to merge 7 commits into
cabforum:mainfrom
srdavidson:HIgh-Risk-Language

Conversation

@srdavidson

Copy link
Copy Markdown

No description provided.

@srdavidson
srdavidson requested a review from a team as a code owner August 19, 2026 19:57
Comment thread docs/EVG.md

##### 3.2.2.12.1 High Risk Status

The High Risk Certificate requirements of Section 4.2.1 of the Baseline Requirements apply equally to EV Certificates.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I propose to remove this chapter and re-number the following chapters.
There seems to be no reference to this or the following chapters in any other CA/B document, so re-numbering would not have side-effects.

I if removal is not desirable, then I would put "No stipulation." as it's done in the TLS BR (e.g. 1.4.2).

Comment thread docs/BR.md
8. The CA is made aware that a Subscriber has violated one or more of its material obligations under the Subscriber Agreement or Terms of Use (CRLReason #9, privilegeWithdrawn);
9. The CA is made aware of any circumstance indicating that use of a Fully-Qualified Domain Name or IP address in the Certificate is no longer legally permitted (e.g. a court or arbitrator has revoked a Domain Name Registrant's right to use the Domain Name) (CRLReason #5, cessationOfOperation);
10. The CA is made aware that a Wildcard Certificate has been used to authenticate a fraudulently misleading subordinate Fully-Qualified Domain Name (CRLReason #9, privilegeWithdrawn);
10. Removed;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I recommend removing reason 10. entirely and re-number the remaining reasons as there are no references to the numbered reasons only Section 4.9.1.1 or exact CRLReason codes.

Comment thread docs/BR.md
8. The CA is made aware that a Subscriber has violated one or more of its material obligations under the Subscriber Agreement or Terms of Use (CRLReason #9, privilegeWithdrawn);
9. The CA is made aware of any circumstance indicating that use of a Fully-Qualified Domain Name or IP address in the Certificate is no longer legally permitted (e.g. a court or arbitrator has revoked a Domain Name Registrant's right to use the Domain Name) (CRLReason #5, cessationOfOperation);
10. The CA is made aware that a Wildcard Certificate has been used to authenticate a fraudulently misleading subordinate Fully-Qualified Domain Name (CRLReason #9, privilegeWithdrawn);
10. Removed;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I recommend removing reason 10. entirely and re-number the remaining reasons as there are no references to the numbered reasons only Section 4.9.1.1 or exact CRLReason codes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants