ASE Labs
Welcome Guest. Please register or log in now. There are 77 people online (0 Friends).
  • Home
  • Articles
  • News
  • Forum
  • Register/Login

CA/Browser Forum Approves Baseline Requirements for SSL/TLS Certificates

Poster: SySAdmin
Posted on December 14, 2011 at 7:35:02 AM
CA/Browser Forum Approves Baseline Requirements for SSL/TLS Certificates

First industry-wide standard for the issuance and management of SSL/TLS digital certificates

DALLAS, Dec. 14, 2011 /PRNewswire/ --The CA/Browser Forum has released the "Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates," the first international baseline standard for the operation of Certification Authorities (CAs) issuing SSL/TLS digital certificates natively trusted in browser software.

SSL/TLS digital certificates are used to authenticate the ownership of websites and other online resources, as well as to encrypt information for privacy as it crosses the Internet and other networks.

"SSL/TLS certificates are a critical part of the Internet's security infrastructure, combining proven technical standards with the capability to scale to handle millions of websites and the wide array of user software," said Tim Moses, Chairman of the CA/Browser Forum.  "The new Baseline Requirements will improve the reliability and accountability of SSL/TLS issuance for relying parties by establishing baseline standards for all types of SSL/TLS certificates from all publicly-trusted CAs."

The Baseline Requirements draw upon best practices from across the SSL/TLS sector to provide clear standards for CAs on important subjects including verification of identity, certificate content and profiles, CA security, revocation mechanisms, use of algorithms and key sizes, audit requirements, liability, privacy and confidentiality, and delegation (including external sub-CAs and registration authorities).

The Baseline Requirements become effective on July 1, 2012 allowing CAs time to bring their SSL/TLS policies and practices into compliance with the standard.  The CA/B Forum intends to continue development of the Baseline Requirements to address the evolving risks and threats involving the issuance or use of SSL/TLS certificates.

The CA/Browser Forum was formed in 2006 and previously created the "Extended Validation" (EV) standard for SSL/TLS.  EV was designed for banks and other high profile websites providing enhanced confirmation of the legitimacy of a website and the identity of its owner, consistent across all EV-issuing CAs.

"With the Baseline Requirements, for the first time we will have a consistent international standard for the issuance of all SSL/TLS, including the many variations of Domain Validation and Organisation Validation," said Eddy Nigg of the StartCom CA.  "This has been a multiyear effort involving more than 50 organisations including the major browser suppliers and CAs from around the world, as well as representatives from the Internet standards and audit/legal community along with major relying parties that use SSL/TLS."

Certification Authority members of the CA/Browser Forum range from the large multinational CAs to smaller issuers focused on geographic regions or specific industries.  Major CAs have already voiced their commitment to implement the Baseline Requirements targeting the 2012 effective date.  These include CA/Browser Forum members Symantec, Go Daddy, Comodo, GlobalSign, DigiCert, Entrust, StartCom, TrustWave, QuoVadis, Certum, T?Systems, Izenpe, and BuyPass representing more than 94% of all valid public SSL/TLS according to the independent Netcraft survey.

The CA/Browser Forum has requested that internet browsers and operating systems adopt the Baseline Requirements among their conditions to distribute CA root certificates in their software.

According to Kathleen Wilson of Mozilla, "Four years ago the CA/Browser Forum released the Extended Validation guidelines that established consistent standards for identity validation. The Baseline Requirements provide a foundation for best practices across the industry by defining a single, consolidated set of essential standards for all SSL/TLS certificates for the first time."

The CA/B Forum has also requested that the major audit regimes used by CAs, WebTrust and ETSI, develop audit criteria to assess compliance with the Baseline Requirements.

Further information on the CA/Browser Forum and the Baseline Requirements may be found at http://cabforum.org/

Additional Support for the CAB/Forum Baseline Requirements

"Today marks a big step forward for Internet security," said Fran Rosch, Vice President of Identity and Authentication Services at Symantec. "This new SSL/TLS standard for trusted Certification Authorities is a particularly important development right now considering the increasingly dangerous cyber threat landscape. Symantec is dedicated to supporting this industry effort and we look forward to helping move this initiative to the next level."

"Comodo see the Baseline Requirements as both raising the bar on certification practice and beginning a process of unifying previously disparate policy requirements on Certification Authorities," said Robin Alden, CTO of Comodo CA Ltd.  "When these requirements come into force they will surely simplify the mapping between browser policy and CA policy and also ensure the auditability of the CA's practice in order that auditors may reliably check that the operation of CAs meets the required standards and thereby increase CA integrity and the perception of CA integrity."

"The Baseline Requirements and associated best practices will add new clarity and understanding around SSL/TLS technology and its critical role in modern Internet society," said Steve Roylance, Business Development Director at GlobalSign.

"The Baseline Requirements will provide a consistent security footing for the variety of SSL/TLS products available from different CAs around the world, said Ken Bretschneider, CEO of DigiCert.  "While the Extended Validation standard helped protect the most visible targets of phishing, the ongoing Baseline initiative will benefit all users of SSL/TLS certificates and the https security they provide."

"Prior to the CA/Browser Forum Baseline Requirements, there really was not a common standard for the issuance of SSL certificates," said Entrust Certificate Services general manager David Rockvam. "The Baseline Requirements draw upon years of SSL/TLSE experience, from a wide selection of CAs and other stakeholders, to provide critical guidelines for the secure future of SSL/TLS issuance, verification, and revocation.  It's an instrumental step in ensuring the integrity of the Internet trust infrastructure."

"Previously Certification Authorities had to interpret overlapping standards from different software providers, regulators, and audit regimes," said Roman Brunner, CEO of QuoVadis.  "With the Baseline Requirements the core standards are integrated in one document, clarifying responsibilities and increasing accountability for trusted CAs that issue SSL/TLS digital certificates."

About the CA/Browser Forum

The CA/Browser Forum is a voluntary organization of Certification Authorities and suppliers of Internet browser and other software applications that use digital certificates.  CA/Browser Forum membership includes:

Certification Authorities

    --  A-Trust GmbH
    --  AC Camerfirma SA
    --  Buypass AS
    --  Certum
    --  Comodo CA Ltd
    --  Cybertrust
    --  D-TRUST GmbH
    --  DanID A/S
    --  DigiCert, Inc.
    --  Digidentity BV
    --  Echoworx Corporation
    --  Entrust, Inc.
    --  GeoTrust, Inc.
    --  Getronics PinkRoccade
    --  GlobalSign
    --  GoDaddy.com
    --  IdenTrust, Inc.
    --  ipsCA, IPS Certification Authority s.l.
    --  Izenpe S.A.
    --  Japan Certification Services, Inc.
    --  Kamu Sertifikasyon Merkezi
    --  Keynectis
    --  Logius PKIoverheid
    --  Network Solutions, LLC
    --  QuoVadis Limited
    --  RSA Security, Inc.
    --  SECOM Trust Systems CO., Ltd.
    --  Skaitmeninio sertifikavimo centras (SSC)
    --  StartCom Certification Authority
    --  SwissSign AG
    --  Symantec Corporation
    --  T-Systems International GmbH.
    --  TC TrustCenter GmbH
    --  Thawte, Inc.
    --  TURKTRUST
    --  Trustis Limited
    --  Trustwave
    --  TWCA
    --  Verizon
    --  Wells Fargo Bank, N.A.

Relying-Party Application Software Suppliers

    --  Apple
    --  Google Inc.
    --  KDE
    --  Microsoft Corporation
    --  Opera Software ASA
    --  Research in Motion Limited
    --  The Mozilla Foundation

Other groups that have participated in the development of the Baseline Requirements include the AICPA/CICA WebTrust for Certification Authorities task force, the European Telecommunications Standards Institute (ETSI) Electronic Signature Initiative, and t.Scheme (UK).

(Logo:  http://photos.prnewswire.com/prnh/20060720/NYTH074LOGO)

SOURCE  Entrust, Inc.; The CA/Browser Forum

Photo:http://photos.prnewswire.com/prnh/20060720/NYTH074LOGO
http://photoarchive.ap.org/
Entrust, Inc.; The CA/Browser Forum

CONTACT: CONTACT: Lindsey Jones, +1-972-728-0374, lindsey.jones@entrust.com

Web Site: http://www.entrust.com
 
Print This Entry
Tags PR Press Release
Related Articles
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
Login
Welcome Guest. Please register or log in now.
Forgot your password?
Navigation
  • Home
  • Articles
  • News
  • Register/Login
  • Shopping
  • ASE Forums
  • Anime Threads
  • HardwareLogic
  • ASE Adnet
Latest News
  • Kingston HyperX Cloud 2 Pro Gaming Headset Unboxing
  • Synology DS415+ Unboxing
  • D-Link DCS-5020L Wireless IP Pan/Tilt IP Camera
  • Actiontec WiFi Powerline Network Extender Kit Unboxing
  • Durovis Dive Unboxing
  • Bass Egg Verb Unboxing
  • Welcome to the new server
  • Gmail Gets Optional Preview Pane
  • HBO Go on Consoles
  • HP Touchpad Update
Latest Articles
  • D-Link Exo AC2600 Smart Mesh Wi-Fi Router DIR-2660-US
  • HyperX Double Shot PBT Keys
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones
  • ScharkSpark Beginner Drones
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera
  • Contour Unimouse Wireless Ergonomic Mouse
  • HyperX Cloud Alpha Pro Gaming Headset
  • Linksys Wemo Smart Home Suite
  • Fully Jarvis Adjustable Standing Desk
Latest Topics
  • Hello
  • Welcome to the new server at ASE Labs
  • Evercool Royal NP-901 Notebook Cooler at ASE Labs
  • HyperX Double Shot PBT Keys at ASE Labs
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones at ASE Labs
  • ScharkSpark Beginner Drones at ASE Labs
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard at ASE Labs
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera at ASE Labs
  • Kingston SDX10V/128GB SDXC Memory at ASE Labs
  • What are you listening to now?
  • Antec Six Hundred v2 Gaming Case at HardwareLogic
  • Sans Digital TR5UTP 5-Bay RAID Tower at HardwareLogic
  • Crucial Ballistix Smart Tracer 6GB PC3-12800 BL3KIT25664ST1608OB at HardwareLogic
  • Cooler Master Storm Enforcer Mid-Tower Gaming Case at HardwareLogic
  • Arctic M571-L Gaming Laser Mouse at ASE Labs
  • Contour Unimouse Wireless Ergonomic Mouse at ASE Labs
Advertisement
Advertisement
Press Release
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • Fujifilm launches "instax SQUARE SQ6 Taylor Swift Edition", designed by instax global partner Taylor Swift
  • Huawei nova 3 With Best-in-class AI Capabilities Goes on Sale Today
  • Rand McNally Introduces Its Most Advanced Dashboard Camera
  • =?UTF-8?Q?My_Size_to_Showcase_Its_MySizeId=E2=84=A2_Mobil?= =?UTF-8?Q?e_Measurement_Technology_at_CurvyCon_NYC?=
Home - ASE Publishing - About Us
© 2010 Aron Schatz (ASE Publishing) [Queries: 17 (8 Cached)] [Rows: 293 Fetched: 36] [Page Generation time: 0.012810945510864]