#CABForum
Of course, people who haven't experience in this area will now be furiously responding that social media is entirely different etc. Only it really is not.

Very little in the CABForum guidelines relates to cryptography or X.509v3, those are the easy bits.
April 22, 2025 at 5:06 PM
Blue Sky aren't exactly explaining how they are going about it. Seems that most of the accounts are being validated through periodicals journalists work for and such.

There is actually an organization that specializes in this type of concern, CABForum.
April 22, 2025 at 5:06 PM
Journalists writing for a newspaper is easy - authenticate the newspaper. They usually have a better known brand and we have validation criteria for organizations, see CABForum EV guidelines.

The other problems are much harder because names are not as unique as people might expect for a start.
April 22, 2025 at 4:41 AM
Ha. Perfect. So are we opening a naming contest for the CABForum analog yet?

@fugueish.bsky.social suggested TVATPBV Forum when I was joking about is earlier
April 21, 2025 at 11:40 PM
Certs will have 47 days of validity by 2029. lengths get shorter from march 2026. Reuse domain val material will be 10 days.

this is diff to very short validity certs that can be issued now. Lets Encrypt will offer 6 day certs by end of yr
#tls #certificates
github.com/cabforum/ser...
Comparing b7fd69b36171d81930e7758482984ce957a1ce7a...abf6c4e3845040069672d58cd2dd80ede8f42012 · cabforum/servercert
Repository for the CA/Browser Forum Server Certificate Chartered Working Group - Comparing b7fd69b36171d81930e7758482984ce957a1ce7a...abf6c4e3845040069672d58cd2dd80ede8f42012 · cabforum/servercert
github.com
April 21, 2025 at 3:38 AM
#cabforum passed SC-081v3 to shorten public #tls cerficiate validity to a eventual 47 days, creating a market for new jobs like "certificate renew specialist" and "technican for certificate error ignoring".

This also brings light to a world of easier phishing cuz... you know, people don't get […]
Original post on mk.outv.im
mk.outv.im
April 14, 2025 at 1:00 AM
There are two sets of *existing* criteria that would be applicable to verifying names: The CABForum EV criteria for organizations and the EU Qualified Certificates for people.

My proposal is that every name has a canonical form and a presentation form.

3/
November 30, 2024 at 5:04 PM
So there are two parts to issue of a TLS certificate for the devices. First there is a personal PKIX CA operated on behalf of the user at whatever degree of security is appropriate, Second there is a public CA that issues cross certificates to users under a non-CABForum CA.
November 30, 2024 at 4:39 PM
おっと、これは知らなかった。Googleは90日への短縮を提案 www.chromium.org/Home/chromiu... していて、Appleは45日への短縮を提案 github.com/cabforum/ser... しているのね。どっちにしても、自社でウェブサーバを管理しているような弱小独立事業者はとっとと退場しろ、と言いたいのだろうなあ。あまりにも乱暴な意見だと思うけど…
さて、某大学の場合、大多数のウェブサーバはLet's Encryptを使っているので対応可能ですが、UPKIから取得した証明書を使って手動で管理している一部サーバとネットワーク機器が問題になりそう。やれやれ。
October 30, 2024 at 7:17 AM
Really, Apple? Reducing the lifespan of TLS to 10 days is the threat mitigation we need? Sure, you'll force automation in TLS key management, but I can't see the cost / benefit justification for that. #infosec

github.com/cabforum/ser...
github.com
October 23, 2024 at 4:46 PM
The comments on github.com/cabforum/ser... is like a cavalcade of bad takes
October 23, 2024 at 4:01 PM
Nova proposta para reduzir validade máxima de certificados SSL para 45 dias até 2027 🚨

github.com/cabforum/...
October 14, 2024 at 4:00 PM
Nova proposta para reduzir validade máxima de certificados SSL para 45 dias até 2027 🚨

https://github.com/cabforum/servercert/pull/553
October 14, 2024 at 4:00 PM