From 270572f8e3c9955306681f824673134947adddf3 Mon Sep 17 00:00:00 2001 From: Chris Clements <24415256+ChristopherRC@users.noreply.github.com> Date: Tue, 21 Jan 2025 13:33:57 -0500 Subject: [PATCH 01/50] Clarify the meaning of revocation --- docs/BR.md | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 8af1ad23..95df7096 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1484,10 +1484,9 @@ CAs issuing CA Certificates: 1. MUST update and publish a new CRL at least every twelve (12) months; 2. MUST update and publish a new CRL within twenty-four (24) hours after recording a Certificate as revoked. -CAs MUST continue issuing CRLs until one of the following is true: -- all Subordinate CA Certificates containing the same Subject Public Key are expired or revoked; OR -- the corresponding Subordinate CA Private Key is destroyed. - +CA Certificates MUST continue issuing CRLs until one of the following is true: +- all certificates issued by the CA Certificate(s) are expired; or +- all certificates issued by the CA Certificate(s) are expired or revoked and the corresponding CA Certificate(s) Private Key is destroyed. ### 4.9.8 Maximum latency for CRLs (if applicable) @@ -1555,6 +1554,12 @@ Not applicable. Not applicable. +### 4.9.17 Authoritative certificate status + +Effective 2025-05-15, for a certificate to be considered revoked: +1. If the CA publishes a CRL, the CRL containing the certificate serial number MUST have been published to the Repository and be available for consumption for Relying Parties; and +2. If the certificate contains a HTTP URL of the Issuing CA's OCSP responder, at least one (1) OCSP response containing a `certStatus` value of `revoked` MUST have been published to the Repository and be available for consumption for Relying Parties; + ## 4.10 Certificate status services ### 4.10.1 Operational characteristics From a37126e839c89a0fec942e1a93450588b87869a4 Mon Sep 17 00:00:00 2001 From: Chris Clements <24415256+ChristopherRC@users.noreply.github.com> Date: Tue, 21 Jan 2025 13:35:02 -0500 Subject: [PATCH 02/50] fix typo --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 95df7096..95f6fc4f 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1558,7 +1558,7 @@ Not applicable. Effective 2025-05-15, for a certificate to be considered revoked: 1. If the CA publishes a CRL, the CRL containing the certificate serial number MUST have been published to the Repository and be available for consumption for Relying Parties; and -2. If the certificate contains a HTTP URL of the Issuing CA's OCSP responder, at least one (1) OCSP response containing a `certStatus` value of `revoked` MUST have been published to the Repository and be available for consumption for Relying Parties; +2. If the certificate contains a HTTP URL of the Issuing CA's OCSP responder, at least one (1) OCSP response containing a `certStatus` value of `revoked` MUST have been published to the Repository and be available for consumption for Relying Parties. ## 4.10 Certificate status services From c704cd0af168307179459f413af17ed2d48eb3ed Mon Sep 17 00:00:00 2001 From: Chris Clements <24415256+ChristopherRC@users.noreply.github.com> Date: Tue, 21 Jan 2025 13:57:29 -0500 Subject: [PATCH 03/50] improve the usefulness of CPRs --- docs/BR.md | 41 +++++++++++++++++++++++++++++++++++------ 1 file changed, 35 insertions(+), 6 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 95f6fc4f..d08cb854 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1291,6 +1291,32 @@ No stipulation. No stipulation. +### 4.4.4 Problem reports +Prior to 2025-05-15, the CA SHALL adhere to these Requirements or Version 2.1.1 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. + +The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. + +Within twenty four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." + +A Certificate Problem Report is considered actionable if it includes: +1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA, either directly or transitively (e.g., by attaching a Certificate file); and +2. a description of either: + - how the Certificate(s) in question violates these Requirements or a CA's own policies; or + - a reason for Certificate revocation (e.g., a demonstration of key compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). + +A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. + +Within twenty four (24) hours after determining a Certificate Problem Report is actionable: +1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report. +2. The CA SHOULD provide a report on its findings to Subscriber(s). +3. If the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHALL work with the Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). + +Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA SHALL have evaluated all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). + +Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. + +**Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. + ## 4.5 Key pair and certificate usage ### 4.5.1 Subscriber private key and certificate usage @@ -1440,24 +1466,27 @@ The Issuing CA SHALL revoke a Subordinate CA Certificate within seven (7) days i The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscribers, Relying Parties, Application Software Suppliers, and other third parties may submit Certificate Problem Reports informing the issuing CA of reasonable cause to revoke the certificate. ### 4.9.3 Procedure for revocation request +Prior to 2025-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.1 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. -The CA SHALL provide a process for Subscribers to request revocation of their own Certificates. The process MUST be described in the CA's Certificate Policy or Certification Practice Statement. The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests and Certificate Problem Reports. +The CA’s Certificate Policy or Certification Practice Statement MUST describe: + - a process for Subscribers to request revocation of their own Certificates; and + - when the revocation reason is "Key Compromise", the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key. -The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. +The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests. ### 4.9.4 Revocation request grace period No stipulation. ### 4.9.5 Time within which CA must process the revocation request +Prior to 2025-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.1 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. -Within 24 hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to a Certificate Problem Report and provide a preliminary report on its findings to both the Subscriber and the entity who filed the Certificate Problem Report. -After reviewing the facts and circumstances, the CA SHALL work with the Subscriber and any entity reporting the Certificate Problem Report or other revocation-related notice to establish whether or not the certificate will be revoked, and if so, a date which the CA will revoke the certificate. The period from receipt of the Certificate Problem Report or revocation-related notice to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: +The period from the time from receipt of the revocation request to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: 1. The nature of the alleged problem (scope, context, severity, magnitude, risk of harm); 2. The consequences of revocation (direct and collateral impacts to Subscribers and Relying Parties); -3. The number of Certificate Problem Reports received about a particular Certificate or Subscriber; -4. The entity making the complaint (for example, a complaint from a law enforcement official that a Web site is engaged in illegal activities should carry more weight than a complaint from a consumer alleging that they didn't receive the goods they ordered); and +3. The number of revocation requests or Certificate Problem Reports received about a particular Certificate or Subscriber; +4. The entity making the complaint (for example, a complaint from a law enforcement official that a Web site is engaged in illegal activities should carry more weight than a complaint from a consumer alleging that they didn’t receive the goods they ordered); and 5. Relevant legislation. ### 4.9.6 Revocation checking requirement for relying parties From 4a6b8ceb36d7d96cebc10ee8fa83190a190a2a40 Mon Sep 17 00:00:00 2001 From: Chris Clements <24415256+ChristopherRC@users.noreply.github.com> Date: Tue, 21 Jan 2025 15:22:33 -0500 Subject: [PATCH 04/50] fix smart quote and bump BR version number references --- docs/BR.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index d08cb854..d0606870 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1292,7 +1292,7 @@ No stipulation. No stipulation. ### 4.4.4 Problem reports -Prior to 2025-05-15, the CA SHALL adhere to these Requirements or Version 2.1.1 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. +Prior to 2025-05-15, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. @@ -1466,7 +1466,7 @@ The Issuing CA SHALL revoke a Subordinate CA Certificate within seven (7) days i The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscribers, Relying Parties, Application Software Suppliers, and other third parties may submit Certificate Problem Reports informing the issuing CA of reasonable cause to revoke the certificate. ### 4.9.3 Procedure for revocation request -Prior to 2025-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.1 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. +Prior to 2025-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. The CA’s Certificate Policy or Certification Practice Statement MUST describe: - a process for Subscribers to request revocation of their own Certificates; and @@ -1479,14 +1479,14 @@ The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocat No stipulation. ### 4.9.5 Time within which CA must process the revocation request -Prior to 2025-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.1 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. +Prior to 2025-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. The period from the time from receipt of the revocation request to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: 1. The nature of the alleged problem (scope, context, severity, magnitude, risk of harm); 2. The consequences of revocation (direct and collateral impacts to Subscribers and Relying Parties); 3. The number of revocation requests or Certificate Problem Reports received about a particular Certificate or Subscriber; -4. The entity making the complaint (for example, a complaint from a law enforcement official that a Web site is engaged in illegal activities should carry more weight than a complaint from a consumer alleging that they didn’t receive the goods they ordered); and +4. The entity making the complaint (for example, a complaint from a law enforcement official that a Web site is engaged in illegal activities should carry more weight than a complaint from a consumer alleging that they didn't receive the goods they ordered); and 5. Relevant legislation. ### 4.9.6 Revocation checking requirement for relying parties From ab72e67432c3d86a156d885e27a5edbf9b13f39a Mon Sep 17 00:00:00 2001 From: Chris Clements Date: Fri, 13 Jun 2025 13:23:48 -0400 Subject: [PATCH 05/50] Nit - fix bullet points --- docs/BR.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 4e783fb8..a480afbd 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1513,8 +1513,8 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri Prior to 2025-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. The CA’s Certificate Policy or Certification Practice Statement MUST describe: - - a process for Subscribers to request revocation of their own Certificates; and - - when the revocation reason is "Key Compromise", the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key. +- a process for Subscribers to request revocation of their own Certificates; and +- when the revocation reason is "Key Compromise", the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key. The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests. From 5c813216ea8cb584d2fceefa731224dbaa2f5f22 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Thu, 2 Oct 2025 10:51:05 +0200 Subject: [PATCH 06/50] Update effective dates and add more permissive language --- docs/BR.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 2528253a..3b1e555c 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1383,7 +1383,7 @@ No stipulation. No stipulation. ### 4.4.4 Problem reports -Prior to 2025-05-15, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. +For this section, prior to 2026-05-15, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. @@ -1400,7 +1400,7 @@ A CA MAY take measures to prevent submission of non-actionable Certificate Probl Within twenty four (24) hours after determining a Certificate Problem Report is actionable: 1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report. 2. The CA SHOULD provide a report on its findings to Subscriber(s). -3. If the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHALL work with the Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA SHALL have evaluated all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). @@ -1557,7 +1557,7 @@ The Issuing CA SHALL revoke a Subordinate CA Certificate within seven (7) days i The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscribers, Relying Parties, Application Software Suppliers, and other third parties may submit Certificate Problem Reports informing the issuing CA of reasonable cause to revoke the certificate. ### 4.9.3 Procedure for revocation request -Prior to 2025-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. The CA’s Certificate Policy or Certification Practice Statement MUST describe: - a process for Subscribers to request revocation of their own Certificates; and @@ -1570,7 +1570,7 @@ The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocat No stipulation. ### 4.9.5 Time within which CA must process the revocation request -Prior to 2025-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.3 of the Baseline Requirements for TLS Server Certificates. Effective 2025-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. The period from the time from receipt of the revocation request to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: @@ -1676,7 +1676,7 @@ Not applicable. ### 4.9.17 Authoritative certificate status -Effective 2025-05-15, for a certificate to be considered revoked: +Effective 2026-05-15, for a certificate to be considered revoked: 1. If the CA publishes a CRL, the CRL containing the certificate serial number MUST have been published to the Repository and be available for consumption for Relying Parties; and 2. If the certificate contains a HTTP URL of the Issuing CA's OCSP responder, at least one (1) OCSP response containing a `certStatus` value of `revoked` MUST have been published to the Repository and be available for consumption for Relying Parties. From df072115b376e1bad2b7ee257c13b0430ecb8c5c Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 15 Oct 2025 11:30:53 +0200 Subject: [PATCH 07/50] fix: Utilize "MUST evaluate" Co-authored-by: Aaron Gable --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 3b1e555c..6e009036 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1402,7 +1402,7 @@ Within twenty four (24) hours after determining a Certificate Problem Report is 2. The CA SHOULD provide a report on its findings to Subscriber(s). 3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA SHALL have evaluated all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. From 31a6479129777bb34867b8d3a607786262488a02 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 11 Nov 2025 11:07:38 +0100 Subject: [PATCH 08/50] Update docs/BR.md Co-authored-by: Aaron Gable --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 6e009036..912568f5 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1383,7 +1383,7 @@ No stipulation. No stipulation. ### 4.4.4 Problem reports -For this section, prior to 2026-05-15, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-05-15, the CA SHALL adhere to this section of these Requirements or this section of Version 2.1.7 of these Requirements. Effective 2026-05-15, the CA SHALL adhere to this section of these Requirements. The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. From be40b461de6fe25dbad048fabd3726ca3e8c6468 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 11 Nov 2025 11:10:40 +0100 Subject: [PATCH 09/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 912568f5..d3f4b201 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1399,7 +1399,7 @@ A CA MAY take measures to prevent submission of non-actionable Certificate Probl Within twenty four (24) hours after determining a Certificate Problem Report is actionable: 1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report. -2. The CA SHOULD provide a report on its findings to Subscriber(s). +2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). 3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). From 342ff487812ebdeba836a1e1e5e8f5ff23e26948 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 11 Nov 2025 11:11:42 +0100 Subject: [PATCH 10/50] use "applicable Subscriber" --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index d3f4b201..f5150979 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1400,7 +1400,7 @@ A CA MAY take measures to prevent submission of non-actionable Certificate Probl Within twenty four (24) hours after determining a Certificate Problem Report is actionable: 1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report. 2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). -3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). From 65085bdd1965569b6d9fae10726e90cbe8d06746 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 11 Nov 2025 11:23:17 +0100 Subject: [PATCH 11/50] Linebreak Co-authored-by: Aaron Gable --- docs/BR.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/BR.md b/docs/BR.md index f5150979..c5595f10 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1557,6 +1557,7 @@ The Issuing CA SHALL revoke a Subordinate CA Certificate within seven (7) days i The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscribers, Relying Parties, Application Software Suppliers, and other third parties may submit Certificate Problem Reports informing the issuing CA of reasonable cause to revoke the certificate. ### 4.9.3 Procedure for revocation request + Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. The CA’s Certificate Policy or Certification Practice Statement MUST describe: From 4bb06c1246cafbf50c3a053dfe64a94816b4b1d1 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 11 Nov 2025 11:23:30 +0100 Subject: [PATCH 12/50] Linebreak Co-authored-by: Aaron Gable --- docs/BR.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/BR.md b/docs/BR.md index c5595f10..3486b297 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1571,6 +1571,7 @@ The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocat No stipulation. ### 4.9.5 Time within which CA must process the revocation request + Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. The period from the time from receipt of the revocation request to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: From 594427db2a9fef2e3169f6971284cc3b835136b1 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 11 Nov 2025 11:24:02 +0100 Subject: [PATCH 13/50] Character replacement Co-authored-by: Aaron Gable --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 3486b297..e7a7e6a7 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1560,7 +1560,7 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. -The CA’s Certificate Policy or Certification Practice Statement MUST describe: +The CA's Certificate Policy or Certification Practice Statement MUST describe: - a process for Subscribers to request revocation of their own Certificates; and - when the revocation reason is "Key Compromise", the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key. From 91f8e5e259b74463d03e88c0fc19ce7d6c0c2f1c Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Thu, 13 Nov 2025 09:21:47 +0100 Subject: [PATCH 14/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index e7a7e6a7..2b3630bf 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1385,7 +1385,7 @@ No stipulation. ### 4.4.4 Problem reports Prior to 2026-05-15, the CA SHALL adhere to this section of these Requirements or this section of Version 2.1.7 of these Requirements. Effective 2026-05-15, the CA SHALL adhere to this section of these Requirements. -The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. +The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). Within twenty four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." From 4e43a30f9a4f9512ada306c43d8cf99abe8b2861 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Thu, 13 Nov 2025 09:22:35 +0100 Subject: [PATCH 15/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 2b3630bf..aea82d81 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1398,7 +1398,7 @@ A Certificate Problem Report is considered actionable if it includes: A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. Within twenty four (24) hours after determining a Certificate Problem Report is actionable: -1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report. +1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report, if contact details have been provided. 2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). 3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). From cf05e90a9bfb993e47800f83092b212c1865cd76 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 18 Nov 2025 11:33:22 +0100 Subject: [PATCH 16/50] Use Key Compromise term Co-authored-by: Corey Bonnell --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index aea82d81..439356fc 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1393,7 +1393,7 @@ A Certificate Problem Report is considered actionable if it includes: 1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA, either directly or transitively (e.g., by attaching a Certificate file); and 2. a description of either: - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - - a reason for Certificate revocation (e.g., a demonstration of key compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). + - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. From 332ac9eb2e0bf4ac4fb24c024889d97cc19bbc4e Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 18 Nov 2025 11:35:26 +0100 Subject: [PATCH 17/50] Update docs/BR.md Co-authored-by: Corey Bonnell --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 439356fc..e84814c7 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1608,7 +1608,7 @@ CAs issuing CA Certificates: CA Certificates MUST continue issuing CRLs until one of the following is true: - all certificates issued by the CA Certificate(s) are expired; or -- all certificates issued by the CA Certificate(s) are expired or revoked and the corresponding CA Certificate(s) Private Key is destroyed. +- the Private Key for the CA has been destroyed. ### 4.9.8 Maximum latency for CRLs (if applicable) From a2a51e24c03d20c4709565458a106f550320e07d Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 26 Nov 2025 12:40:05 +0100 Subject: [PATCH 18/50] fix: Revert language based on feedback, removing "Subordinate" --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index e84814c7..7f943a99 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1607,7 +1607,7 @@ CAs issuing CA Certificates: 2. MUST update and publish a new CRL within twenty-four (24) hours after recording a Certificate as revoked. CA Certificates MUST continue issuing CRLs until one of the following is true: -- all certificates issued by the CA Certificate(s) are expired; or +- all CA Certificates containing the same Subject Public Key are expired or revoked; OR - the Private Key for the CA has been destroyed. ### 4.9.8 Maximum latency for CRLs (if applicable) From b4bb5c5ee236352e021bc43bcc6478fb9bae8538 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 26 Nov 2025 12:44:18 +0100 Subject: [PATCH 19/50] Utilize Issuing CAs --- docs/BR.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 7f943a99..ac798058 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1606,9 +1606,9 @@ CAs issuing CA Certificates: 1. MUST update and publish a new CRL at least every twelve (12) months; 2. MUST update and publish a new CRL within twenty-four (24) hours after recording a Certificate as revoked. -CA Certificates MUST continue issuing CRLs until one of the following is true: +Issuing CAs MUST continue issuing CRLs until one of the following is true: - all CA Certificates containing the same Subject Public Key are expired or revoked; OR -- the Private Key for the CA has been destroyed. +- the Private Key for the Issuing CA has been destroyed. ### 4.9.8 Maximum latency for CRLs (if applicable) From 9093e46e5e4e33a783e0b854ae261582bebabe54 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 26 Nov 2025 13:29:27 +0100 Subject: [PATCH 20/50] Move 4.4.4 into 4.9.3 --- docs/BR.md | 55 +++++++++++++++++++++++++++--------------------------- 1 file changed, 28 insertions(+), 27 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index ac798058..dd3e5f56 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1382,32 +1382,6 @@ No stipulation. No stipulation. -### 4.4.4 Problem reports -Prior to 2026-05-15, the CA SHALL adhere to this section of these Requirements or this section of Version 2.1.7 of these Requirements. Effective 2026-05-15, the CA SHALL adhere to this section of these Requirements. - -The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). - -Within twenty four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." - -A Certificate Problem Report is considered actionable if it includes: -1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA, either directly or transitively (e.g., by attaching a Certificate file); and -2. a description of either: - - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). - -A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. - -Within twenty four (24) hours after determining a Certificate Problem Report is actionable: -1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report, if contact details have been provided. -2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). -3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). - -Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). - -Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. - -**Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. - ## 4.5 Key pair and certificate usage ### 4.5.1 Subscriber private key and certificate usage @@ -1566,6 +1540,29 @@ The CA's Certificate Policy or Certification Practice Statement MUST describe: The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests. +The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). + +Within twenty four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." + +A Certificate Problem Report is considered actionable if it includes: +1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA, either directly or transitively (e.g., by attaching a Certificate file); and +2. a description of either: + - how the Certificate(s) in question violates these Requirements or a CA's own policies; or + - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). + +A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. + +Within twenty four (24) hours after determining a Certificate Problem Report is actionable: +1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report, if contact details have been provided. +2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). +3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). + +Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). + +Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. + +**Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. + ### 4.9.4 Revocation request grace period No stipulation. @@ -1574,7 +1571,11 @@ No stipulation. Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. -The period from the time from receipt of the revocation request to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: +The period from the time from receipt of a revocation request by the Subscriber to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). + +The period from the time from determining a Certificate Problem Report is actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). + +The date selected by the CA SHOULD consider the following criteria: 1. The nature of the alleged problem (scope, context, severity, magnitude, risk of harm); 2. The consequences of revocation (direct and collateral impacts to Subscribers and Relying Parties); From 9642e7bcdeea342d8dd967dda2bd6a8992015561 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 26 Nov 2025 13:33:17 +0100 Subject: [PATCH 21/50] "Revoked" defined term --- docs/BR.md | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index dd3e5f56..fc1b9bb9 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -502,6 +502,10 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) +**Revoked**: Effective 2026-05-15, a certificate is considered revoked if: +- if the certificate contains a CRL Distribution Point URI, a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI; and +- if the certificate contains an Authority Information Access OCSP URI, an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. + **Root CA**: The top level Certification Authority whose Root Certificate is distributed by Application Software Suppliers and that issues Subordinate CA Certificates. **Root Certificate**: The self-signed Certificate issued by the Root CA to identify itself and to facilitate verification of Certificates issued to its Subordinate CAs. @@ -1677,12 +1681,6 @@ Not applicable. Not applicable. -### 4.9.17 Authoritative certificate status - -Effective 2026-05-15, for a certificate to be considered revoked: -1. If the CA publishes a CRL, the CRL containing the certificate serial number MUST have been published to the Repository and be available for consumption for Relying Parties; and -2. If the certificate contains a HTTP URL of the Issuing CA's OCSP responder, at least one (1) OCSP response containing a `certStatus` value of `revoked` MUST have been published to the Repository and be available for consumption for Relying Parties. - ## 4.10 Certificate status services ### 4.10.1 Operational characteristics From 0b97d0d715b5d16c4ca8ac5558253c4ad90f1508 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 26 Nov 2025 13:49:29 +0100 Subject: [PATCH 22/50] Move Key Compromise language to 4.9.12 --- docs/BR.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index fc1b9bb9..f22a37fb 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1538,9 +1538,7 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. -The CA's Certificate Policy or Certification Practice Statement MUST describe: -- a process for Subscribers to request revocation of their own Certificates; and -- when the revocation reason is "Key Compromise", the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key. +The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests. @@ -1665,6 +1663,8 @@ No Stipulation. See [Section 4.9.1](#491-circumstances-for-revocation). +Effective 2026-05-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key when the revocation reason of a revocation is "Key Compromise", + ### 4.9.13 Circumstances for suspension The Repository MUST NOT include entries that indicate that a Certificate is suspended. From 0f2553bb771410e91466a08544ba12cafbadcc00 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 26 Nov 2025 15:23:41 +0100 Subject: [PATCH 23/50] Don't call out attachments specifically --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index f22a37fb..6bb4fb83 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1547,7 +1547,7 @@ The CA SHALL provide Subscribers, Relying Parties, Application Software Supplier Within twenty four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." A Certificate Problem Report is considered actionable if it includes: -1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA, either directly or transitively (e.g., by attaching a Certificate file); and +1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA; and 2. a description of either: - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). From c32f356eacdd715b169da039d8900e3eb1dace32 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 2 Dec 2025 10:59:39 +0100 Subject: [PATCH 24/50] Remove "revocation requests or" --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 6bb4fb83..c9a12c5f 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1581,7 +1581,7 @@ The date selected by the CA SHOULD consider the following criteria: 1. The nature of the alleged problem (scope, context, severity, magnitude, risk of harm); 2. The consequences of revocation (direct and collateral impacts to Subscribers and Relying Parties); -3. The number of revocation requests or Certificate Problem Reports received about a particular Certificate or Subscriber; +3. The number of Certificate Problem Reports received about a particular Certificate or Subscriber; 4. The entity making the complaint (for example, a complaint from a law enforcement official that a Web site is engaged in illegal activities should carry more weight than a complaint from a consumer alleging that they didn't receive the goods they ordered); and 5. Relevant legislation. From ef4e2017044b75c46591e098e33a497a89ed3db3 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 3 Dec 2025 09:56:17 +0100 Subject: [PATCH 25/50] Simplify the Revoked language --- docs/BR.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index c9a12c5f..12edc495 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -502,9 +502,9 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) -**Revoked**: Effective 2026-05-15, a certificate is considered revoked if: -- if the certificate contains a CRL Distribution Point URI, a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI; and -- if the certificate contains an Authority Information Access OCSP URI, an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. +**Revoked**: Effective 2026-05-15, a Certificate is considered revoked if: +- a CRL Distribution Point URI is present and the referenced CRL contains the Certificate's serial number; and +- an Authority Information Access OCSP URI is present and an OCSP response for the Certificate's serial number indicates a `certStatus` value of `revoked`. **Root CA**: The top level Certification Authority whose Root Certificate is distributed by Application Software Suppliers and that issues Subordinate CA Certificates. From f0b7e46c51b0c1057d837b48703b188ac4cb41d7 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 3 Dec 2025 10:01:14 +0100 Subject: [PATCH 26/50] Simplify the Revoked language --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 12edc495..98e21491 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -503,7 +503,7 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) **Revoked**: Effective 2026-05-15, a Certificate is considered revoked if: -- a CRL Distribution Point URI is present and the referenced CRL contains the Certificate's serial number; and +- a CRL Distribution Point URI is present and the referenced CRL contains the Certificate's serial number; or - an Authority Information Access OCSP URI is present and an OCSP response for the Certificate's serial number indicates a `certStatus` value of `revoked`. **Root CA**: The top level Certification Authority whose Root Certificate is distributed by Application Software Suppliers and that issues Subordinate CA Certificates. From 2ad15820c3bbaba91667b126a0bdf84f87567a7e Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 3 Dec 2025 10:03:56 +0100 Subject: [PATCH 27/50] Update docs/BR.md Co-authored-by: Ryan Dickson --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 98e21491..1a7dd8bf 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1536,7 +1536,7 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri ### 4.9.3 Procedure for revocation request -Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. From f010ab16d0949e25329708e7730839d905853db9 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 3 Dec 2025 10:04:11 +0100 Subject: [PATCH 28/50] Update docs/BR.md Co-authored-by: Ryan Dickson --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 1a7dd8bf..e5be779c 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1544,7 +1544,7 @@ The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocat The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). -Within twenty four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." +Within twenty-four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." A Certificate Problem Report is considered actionable if it includes: 1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA; and From fb938d03e8170e01209f594ae53f2beea711de43 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 3 Dec 2025 10:04:23 +0100 Subject: [PATCH 29/50] Update docs/BR.md Co-authored-by: Ryan Dickson --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index e5be779c..81edd480 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1561,7 +1561,7 @@ Within twenty four (24) hours after determining a Certificate Problem Report is Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. +Within twenty-four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. **Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. From 572ee86f08d3cb3a9702292ef7c94b4b185c60e5 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 3 Dec 2025 10:06:10 +0100 Subject: [PATCH 30/50] Apply suggestions from code review Co-authored-by: Ryan Dickson --- docs/BR.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 81edd480..85ef6c5c 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1554,12 +1554,12 @@ A Certificate Problem Report is considered actionable if it includes: A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. -Within twenty four (24) hours after determining a Certificate Problem Report is actionable: +Within twenty-four (24) hours after determining a Certificate Problem Report is actionable: 1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report, if contact details have been provided. 2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). 3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within one hundred and twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +Within one hundred twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). Within twenty-four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. @@ -1571,11 +1571,11 @@ No stipulation. ### 4.9.5 Time within which CA must process the revocation request -Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.7 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. -The period from the time from receipt of a revocation request by the Subscriber to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -The period from the time from determining a Certificate Problem Report is actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +The period between the determination that a Certificate Problem Report is actionable and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: From 9db978c07f419c086b04c385ccfcefd612191d75 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Thu, 4 Dec 2025 14:05:13 +0100 Subject: [PATCH 31/50] Add contact-details carve-out --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 85ef6c5c..71ebb660 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1561,7 +1561,7 @@ Within twenty-four (24) hours after determining a Certificate Problem Report is Within one hundred twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within twenty-four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. +Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. **Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. From 8193abccbcae4f73ea4d345b78d886dce0c9de3e Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Fri, 5 Dec 2025 09:38:11 +0100 Subject: [PATCH 32/50] Use SHA256 fingerprint --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 71ebb660..acbfd9a5 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1547,7 +1547,7 @@ The CA SHALL provide Subscribers, Relying Parties, Application Software Supplier Within twenty-four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." A Certificate Problem Report is considered actionable if it includes: -1. at least one serial number or hash of a time-valid and unrevoked Certificate issued by the CA; and +1. at least one serial number or SHA-256 fingerprint of a time-valid and unrevoked Certificate issued by the CA; and 2. a description of either: - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). From 53df8aad133ddaac0007034ede8c51918791f079 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Mon, 19 Jan 2026 14:31:53 +0100 Subject: [PATCH 33/50] Use "information" --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index acbfd9a5..6bfaae70 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1548,7 +1548,7 @@ Within twenty-four (24) hours after receiving a Certificate Problem Report, the A Certificate Problem Report is considered actionable if it includes: 1. at least one serial number or SHA-256 fingerprint of a time-valid and unrevoked Certificate issued by the CA; and -2. a description of either: +2. information about either: - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). From 339b88d5db561ca25ea26ea32cb62e217d90a399 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Mon, 19 Jan 2026 14:37:08 +0100 Subject: [PATCH 34/50] Add Subscriber revocation requests authentication language --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 6bfaae70..47f3c6c4 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1573,7 +1573,7 @@ No stipulation. Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. -The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). If the request is not authenticated upon receipt, the CA SHALL within 24 hours of receipt work with the requester to authenticate the request, and the period listed above will be measured from the time of authentication. The period between the determination that a Certificate Problem Report is actionable and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). From 2840471bd259076d9fa34027aa1a150f893f1884 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Mon, 19 Jan 2026 16:31:55 +0100 Subject: [PATCH 35/50] Update "Revoked" definition --- docs/BR.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index f5e3d6fe..0016645f 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -517,9 +517,9 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) -**Revoked**: Effective 2026-05-15, a Certificate is considered revoked if: -- a CRL Distribution Point URI is present and the referenced CRL contains the Certificate's serial number; or -- an Authority Information Access OCSP URI is present and an OCSP response for the Certificate's serial number indicates a `certStatus` value of `revoked`. +**Revoked**: Effective 2026-05-15, the following conditions must be met for a Certificate to be considered revoked: +- if the certificate contains a CRL Distribution Point URI: a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI; and +- if the certificate contains an Authority Information Access OCSP URI: an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. **Reverse Zone Domain Name**: the FQDN in the `.arpa` namespace that corresponds to an IP address. This FQDN is constructed by converting the IP address to a sequence of labels followed by the applicable IP Reverse Zone Suffix, as specified in RFC 1035 (for IPv4 addresses) and RFC 3596 (for IPv6 addresses). From d25aa9b021c3adfdb076053075bb1c0544ccb27f Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Mon, 19 Jan 2026 17:09:58 +0100 Subject: [PATCH 36/50] "and" no longer required --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 0016645f..71ee198c 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -518,7 +518,7 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) **Revoked**: Effective 2026-05-15, the following conditions must be met for a Certificate to be considered revoked: -- if the certificate contains a CRL Distribution Point URI: a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI; and +- if the certificate contains a CRL Distribution Point URI: a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI. - if the certificate contains an Authority Information Access OCSP URI: an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. **Reverse Zone Domain Name**: the FQDN in the `.arpa` namespace that corresponds to an IP address. This FQDN is constructed by converting the IP address to a sequence of labels followed by the applicable IP Reverse Zone Suffix, as specified in RFC 1035 (for IPv4 addresses) and RFC 3596 (for IPv6 addresses). From d7c86f88c6f391e7b5c43cfff1729ae8269a8d56 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 24 Feb 2026 17:48:17 +0100 Subject: [PATCH 37/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 71ee198c..74c92430 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1615,7 +1615,7 @@ The CA SHALL provide Subscribers, Relying Parties, Application Software Supplier Within twenty-four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." A Certificate Problem Report is considered actionable if it includes: -1. at least one serial number or SHA-256 fingerprint of a time-valid and unrevoked Certificate issued by the CA; and +1. at least one valid identifier for a time-valid and unrevoked Certificate issued by the CA. The CA MUST support the use of a serial number and SHOULD support the use of a SHA-256 fingerprint of the Certificate and/or Precertificate as an identifier; and" 2. information about either: - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). From 267cdf4ac466239381280acc1118ab8b79980d6d Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Mon, 16 Mar 2026 17:22:58 +0100 Subject: [PATCH 38/50] Update effective date --- docs/BR.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 74c92430..07f5e1e1 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -517,7 +517,7 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) -**Revoked**: Effective 2026-05-15, the following conditions must be met for a Certificate to be considered revoked: +**Revoked**: Effective 2026-09-15, the following conditions must be met for a Certificate to be considered revoked: - if the certificate contains a CRL Distribution Point URI: a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI. - if the certificate contains an Authority Information Access OCSP URI: an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. @@ -1604,7 +1604,7 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri ### 4.9.3 Procedure for revocation request -Prior to 2026-05-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-09-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. @@ -1639,7 +1639,7 @@ No stipulation. ### 4.9.5 Time within which CA must process the revocation request -Prior to 2026-05-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-05-15, the CA SHALL adhere to these Requirements. +Prior to 2026-09-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). If the request is not authenticated upon receipt, the CA SHALL within 24 hours of receipt work with the requester to authenticate the request, and the period listed above will be measured from the time of authentication. @@ -1731,7 +1731,7 @@ No Stipulation. See [Section 4.9.1](#491-circumstances-for-revocation). -Effective 2026-05-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key when the revocation reason of a revocation is "Key Compromise", +Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key when the revocation reason of a revocation is "Key Compromise", ### 4.9.13 Circumstances for suspension From 911294241bc0d57ad96a821d70bfb624148c99e3 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 18 Mar 2026 22:36:02 +0100 Subject: [PATCH 39/50] Update Baseline Requirements version in BR.md --- docs/BR.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 07f5e1e1..e9378f09 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1604,7 +1604,7 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri ### 4.9.3 Procedure for revocation request -Prior to 2026-09-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. +Prior to 2026-09-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. @@ -1639,7 +1639,7 @@ No stipulation. ### 4.9.5 Time within which CA must process the revocation request -Prior to 2026-09-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.1.9 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. +Prior to 2026-09-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). If the request is not authenticated upon receipt, the CA SHALL within 24 hours of receipt work with the requester to authenticate the request, and the period listed above will be measured from the time of authentication. From 6cf96bda56c7354b12bead0dc37bc253759486b7 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 18 Mar 2026 22:42:47 +0100 Subject: [PATCH 40/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index e9378f09..7b8b8096 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1731,7 +1731,7 @@ No Stipulation. See [Section 4.9.1](#491-circumstances-for-revocation). -Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing the same public key and (2) perform a cascading revocation of all time-valid certificates containing the same public key when the revocation reason of a revocation is "Key Compromise", +Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all time-valid certificates containing the same compromised public key when the revocation reason of a revocation is "Key Compromise", ### 4.9.13 Circumstances for suspension From d4df4e71a8abe5edace227629c0892b08fa6398c Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Thu, 21 May 2026 14:22:58 +0200 Subject: [PATCH 41/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 7b8b8096..100d08c4 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1610,7 +1610,7 @@ The CA's Certificate Policy or Certification Practice Statement MUST describe a The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests. -The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). +The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for submitting Certificate Problem Reports. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). Within twenty-four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." From 4751419695482a9e50452e7ebe7193c911f45a8a Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Thu, 21 May 2026 15:10:40 +0200 Subject: [PATCH 42/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 100d08c4..cbff83d1 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1608,7 +1608,7 @@ Prior to 2026-09-15, for Section 4.9.3 of these Requirements, the CA SHALL adher The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. -The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests. +The CA SHALL maintain highly available systems to accept revocation requests and Certificate Problem Reports, and the personnel and procedures to meet the response deadlines specified in these Requirements. The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for submitting Certificate Problem Reports. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). From bcee0b8294c88690a1f9390f798a12fb64daf767 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 25 Aug 2026 12:09:21 +0200 Subject: [PATCH 43/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index cbff83d1..aeb6057d 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1731,7 +1731,7 @@ No Stipulation. See [Section 4.9.1](#491-circumstances-for-revocation). -Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all time-valid certificates containing the same compromised public key when the revocation reason of a revocation is "Key Compromise", +Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all unexpired and unrevoked certificates containing the same compromised public key when the revocation reason of a revocation is "Key Compromise", ### 4.9.13 Circumstances for suspension From a0722b0b0f771d71ee2a597814abf3d086f33fae Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Mon, 31 Aug 2026 12:58:46 +0200 Subject: [PATCH 44/50] Update docs/BR.md Co-authored-by: Dimitris Zacharopoulos --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index aeb6057d..619b6eba 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1731,7 +1731,7 @@ No Stipulation. See [Section 4.9.1](#491-circumstances-for-revocation). -Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all unexpired and unrevoked certificates containing the same compromised public key when the revocation reason of a revocation is "Key Compromise", +Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all unexpired and unrevoked certificates containing the same compromised public key when the revocation reason of a revocation is `keyCompromise`, ### 4.9.13 Circumstances for suspension From ef1dda7b7652d439c3b4b8db2328c4afd4a31ec0 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Tue, 1 Sep 2026 17:11:39 +0200 Subject: [PATCH 45/50] Update docs/BR.md --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 619b6eba..1f2043b1 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1629,7 +1629,7 @@ Within twenty-four (24) hours after determining a Certificate Problem Report is Within one hundred twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report. +Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report, unless the CA can reasonably claim the Certificate Problem Report is unrelated to the compliance or security of certificates it issued. **Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. From a45b4acb20b73f85b1fafa0d20d9b2df82521db4 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 2 Sep 2026 12:13:43 +0200 Subject: [PATCH 46/50] Push out effective date --- docs/BR.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index 1f2043b1..17764846 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -517,7 +517,7 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) -**Revoked**: Effective 2026-09-15, the following conditions must be met for a Certificate to be considered revoked: +**Revoked**: Effective 2027-02-15, the following conditions must be met for a Certificate to be considered revoked: - if the certificate contains a CRL Distribution Point URI: a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI. - if the certificate contains an Authority Information Access OCSP URI: an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. @@ -1604,7 +1604,7 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri ### 4.9.3 Procedure for revocation request -Prior to 2026-09-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. +Prior to 2027-02-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2027-02-15, the CA SHALL adhere to these Requirements. The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. @@ -1639,7 +1639,7 @@ No stipulation. ### 4.9.5 Time within which CA must process the revocation request -Prior to 2026-09-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2026-09-15, the CA SHALL adhere to these Requirements. +Prior to 2027-02-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2027-02-15, the CA SHALL adhere to these Requirements. The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). If the request is not authenticated upon receipt, the CA SHALL within 24 hours of receipt work with the requester to authenticate the request, and the period listed above will be measured from the time of authentication. @@ -1731,7 +1731,7 @@ No Stipulation. See [Section 4.9.1](#491-circumstances-for-revocation). -Effective 2026-09-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all unexpired and unrevoked certificates containing the same compromised public key when the revocation reason of a revocation is `keyCompromise`, +Effective 2027-02-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all unexpired and unrevoked certificates containing the same compromised public key when the revocation reason of a revocation is `keyCompromise`, ### 4.9.13 Circumstances for suspension From c0231eb298e8e473ca5df41c1971dd476f8bd67f Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 16 Sep 2026 12:24:35 +0200 Subject: [PATCH 47/50] Update docs/BR.md Co-authored-by: Chris Clements --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 17764846..2a3e85ef 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1629,7 +1629,7 @@ Within twenty-four (24) hours after determining a Certificate Problem Report is Within one hundred twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within twenty four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report, unless the CA can reasonably claim the Certificate Problem Report is unrelated to the compliance or security of certificates it issued. +Within twenty-four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report, unless the CA can reasonably claim the Certificate Problem Report is unrelated to the compliance or security of certificates it issued. **Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. From 23903978bd40e586e494e2feda39f1ebeb633b55 Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 16 Sep 2026 12:24:56 +0200 Subject: [PATCH 48/50] delete lingering quote Co-authored-by: Ryan Dickson --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 2a3e85ef..1e674a6d 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1615,7 +1615,7 @@ The CA SHALL provide Subscribers, Relying Parties, Application Software Supplier Within twenty-four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." A Certificate Problem Report is considered actionable if it includes: -1. at least one valid identifier for a time-valid and unrevoked Certificate issued by the CA. The CA MUST support the use of a serial number and SHOULD support the use of a SHA-256 fingerprint of the Certificate and/or Precertificate as an identifier; and" +1. at least one valid identifier for a time-valid and unrevoked Certificate issued by the CA. The CA MUST support the use of a serial number and SHOULD support the use of a SHA-256 fingerprint of the Certificate and/or Precertificate as an identifier; and 2. information about either: - how the Certificate(s) in question violates these Requirements or a CA's own policies; or - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). From 9ac300c431db6b4c5defe70f850732756ed4b73f Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 16 Sep 2026 12:25:19 +0200 Subject: [PATCH 49/50] consistency with other numerical spellings Co-authored-by: Ryan Dickson --- docs/BR.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/BR.md b/docs/BR.md index 1e674a6d..c3978b7b 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -1627,7 +1627,7 @@ Within twenty-four (24) hours after determining a Certificate Problem Report is 2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). 3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). -Within one hundred twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). +Within one-hundred-twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). Within twenty-four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report, unless the CA can reasonably claim the Certificate Problem Report is unrelated to the compliance or security of certificates it issued. From 4285aa552ab9d9ff3481836d951349bd207910ad Mon Sep 17 00:00:00 2001 From: Martijn Katerbarg Date: Wed, 16 Sep 2026 12:30:23 +0200 Subject: [PATCH 50/50] Address #252 in regards to distributed edge POPs --- docs/BR.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/BR.md b/docs/BR.md index c3978b7b..e9f63af1 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -518,8 +518,8 @@ The script outputs: [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) **Revoked**: Effective 2027-02-15, the following conditions must be met for a Certificate to be considered revoked: -- if the certificate contains a CRL Distribution Point URI: a CRL containing the certificate serial number is available for consumption by Relying Parties at that URI. -- if the certificate contains an Authority Information Access OCSP URI: an OCSP request to that URI for the certificate serial number results in a response with a `certStatus` value of `revoked`. +- if the Certificate contains a CRL Distribution Point URI: any request to that URI for the CRL (regardless of network perspective or serving endpoint) returns a CRL containing the Certificate's serial number. +- if the Certificate contains an Authority Information Access OCSP URI: any OCSP request to that URI for the Certificate's serial number (regardless of network perspective or serving endpoint) results in a response with a `certStatus` value of `revoked`. **Reverse Zone Domain Name**: the FQDN in the `.arpa` namespace that corresponds to an IP address. This FQDN is constructed by converting the IP address to a sequence of labels followed by the applicable IP Reverse Zone Suffix, as specified in RFC 1035 (for IPv4 addresses) and RFC 3596 (for IPv6 addresses).