Skip to content

Conversation

@dzacharo
Copy link
Contributor

No description provided.

@dzacharo dzacharo requested a review from a team as a code owner August 27, 2025 08:58
@dzacharo dzacharo merged commit b6a014d into main Aug 28, 2025
6 checks passed
dzacharo added a commit that referenced this pull request Oct 17, 2025
* SC-081: Introduce Schedule of Reducing Validity and Data Reuse Periods (#553)

* Introduce Schedule of Reducing Validity and Data Reuse Periods

* Expand Section 4.2.1 to detail allowed data reuse periods for validation data (both for domains/IPs and for everything else in 3.2)
 * Overall reduction of non-SAN validation reuse from 825 to 366 days
 * Overall reduction of SAN validation reuse from 398 days to 10 days
* Expand section 6.3.2 to detail schedule of reducing maximum validity periods in coming years
 * Overall reduction of maximum valdiity period from 398 days to 45 days

* Update Table Row header

Fix copy/pasted table row header

* Update SC-081

* Shift dates to March
* Align on 3 dates for changes to take effect (2026, 2027, 2028)
* Address various comments with corrections to wording
* Update table formatting (to hopefully produce better-looking headings in the PDF output)

* Update Tables

* Update Table headings in 4.2.1
* Add "days" to tables for clarity
* Remove 1 September 2020 date to align with table

* Fix capitalization

Remove erroneous capitalization of "Validation Data Reuse Periods"

* Increase SII reuse period

* Update table in Section 3.2.1 for "Subject Identity Information validation data reuse periods" to increase the Maximum data reuse period after March 15, 2026 from 366 days to 398 days.

* Shift timeline of Validity Period

* Move the reduction from 100 days maximum Validity Period to 47 days maximum Validity Period back by 1 year (from March 15, 2028 to March 15, 2029)
  * This change is based on discussion in the Servercert-wg call on Feb 13, 2025 and on-list for ballot SC-081.

* Fix other 47-day timeline dates

* Delay 10 day DCV reuse date

Based on discussion in the Feb 27, 2025 SCWG meeting, this commit pushes the enforcement date for reducing the maximum reuse period of domain validation to 10 days from March 15, 2028 to March 15, 2029 -- aligning with the date for reducing the maximum validity period of certificates to 47 days.

* Fixing workflow file

Updating build-draft-docs.yml to match main

* Introduce Schedule of Reducing Validity and Data Reuse Periods

* Expand Section 4.2.1 to detail allowed data reuse periods for validation data (both for domains/IPs and for everything else in 3.2)
 * Overall reduction of non-SAN validation reuse from 825 to 366 days
 * Overall reduction of SAN validation reuse from 398 days to 10 days
* Expand section 6.3.2 to detail schedule of reducing maximum validity periods in coming years
 * Overall reduction of maximum valdiity period from 398 days to 45 days

* Update Table Row header

Fix copy/pasted table row header

* Update SC-081

* Shift dates to March
* Align on 3 dates for changes to take effect (2026, 2027, 2028)
* Address various comments with corrections to wording
* Update table formatting (to hopefully produce better-looking headings in the PDF output)

* Update Tables

* Update Table headings in 4.2.1
* Add "days" to tables for clarity
* Remove 1 September 2020 date to align with table

* Fix capitalization

Remove erroneous capitalization of "Validation Data Reuse Periods"

* Increase SII reuse period

* Update table in Section 3.2.1 for "Subject Identity Information validation data reuse periods" to increase the Maximum data reuse period after March 15, 2026 from 366 days to 398 days.

* Shift timeline of Validity Period

* Move the reduction from 100 days maximum Validity Period to 47 days maximum Validity Period back by 1 year (from March 15, 2028 to March 15, 2029)
  * This change is based on discussion in the Servercert-wg call on Feb 13, 2025 and on-list for ballot SC-081.

* Fix other 47-day timeline dates

* Delay 10 day DCV reuse date

Based on discussion in the Feb 27, 2025 SCWG meeting, this commit pushes the enforcement date for reducing the maximum reuse period of domain validation to 10 days from March 15, 2028 to March 15, 2029 -- aligning with the date for reducing the maximum validity period of certificates to 47 days.

* Fixing workflow file

Updating build-draft-docs.yml to match main

* Update version number and recent changes.

---------

Co-authored-by: dzacharo <dzacharo@yahoo.com>

* Bump workflow versions (#581)

* Bump workflow versions

* Set fetch-depth for changelog

* Bump action workflow version

* SC-081: Introduce Schedule of Reducing Validity and Data Reuse Periods

Fixed table format

* Fix formatting and effective date in section 1.2.2 (#595)

* Fix formatting in 3.2.2.9

* Fix numbering in 5.4.1

* Fix effective date in 1.2.2

* SC-085: Require Validation of DNSSEC (when present) for CAA and DCV Lookups (#579)

* require DNSSEC

* SHOULD to MAY

Co-authored-by: Dimitris Zacharopoulos <dzacharo@users.noreply.github.com>

* RFCs in sec 1.6.3.

* Improved RFC 6840 reference

* added effective dates and changed other should to may.

* change ICANN DNSSEC root to IANA DNSSEC root

* Added updates in response to CBonnell suggestions.

* states typo fix

* Using dzacharo 's proposed wording for SHOULD EDNS buffer size.

* changed RFC 4035 reference to Section 5.

* wording change

* Updated effective date to March 15th, 2026

* explicitly omit DNSSEC validation from Section 8.7 self audits per @geegeea's proposal

Co-authored-by: Gurleen Grewal <gurleen.grewal@gmail.com>

* add exclusion to self audit for DCV DNSSEC checks

Co-authored-by: Gurleen Grewal <gurleen.grewal@gmail.com>

---------

Co-authored-by: Dimitris Zacharopoulos <dzacharo@users.noreply.github.com>
Co-authored-by: Gurleen Grewal <gurleen.grewal@gmail.com>

* SC085: Require Validation of DNSSEC (when present) for CAA and DCV Lookups (#606)

* Update version number, recent changes and relevant dates

* fix version

* SC-089: Mass Revocation Planning (#611)

* SC-089: Mass Revocation Planning (#610)

* Initial draft of 5.7.1.2

Here is an initial draft of a proposal to add section 5.7.1.2 to the TLS Baseline Requirements.  See Issue #602

* Added CPS Compliance Date

Added a CPS compliance date of Dec. 1, 2025

---------

Co-authored-by: Ben Wilson <63610154+BenWilson-Mozilla@users.noreply.github.com>

* Updated version number and relevant dates.

* Fix formatting

---------

Co-authored-by: Ben Wilson <63610154+BenWilson-Mozilla@users.noreply.github.com>

* Fix formatting in table 1.2.1 (#613)

---------

Co-authored-by: Clint Wilson <clint@wilsonovi.com>
Co-authored-by: Paul van Brouwershaven <vanbroup@users.noreply.github.com>
Co-authored-by: Henry Birge-Lee <henrybirgelee@gmail.com>
Co-authored-by: Gurleen Grewal <gurleen.grewal@gmail.com>
Co-authored-by: Ben Wilson <63610154+BenWilson-Mozilla@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants