CA/Browser Forum
Founded | 2005 |
---|---|
Founder | Melih Abdulhayoğlu |
Type | Professional Organization |
Focus | Provide internet security industry standards for browsers and Certificate Authorities |
Location | |
Website |
cabforum |
The Certification Authority Browser Forum, also known as CA/Browser Forum, is a voluntary consortium of certification authorities, vendors of Internet browser software, operating systems, and other PKI-enabled applications that promulgates industry guidelines governing the issuance and management of X.509 v.3 digital certificates that chain to a trust anchor embedded in such applications. Its guidelines cover certificates used for the SSL/TLS protocol and code signing, as well as system and network security of certificate authorities.
As of October 2014, the CA/Browser Forum includes over forty certificate authority members and the following six Internet browser software vendors: Microsoft (Internet Explorer), Apple (Safari), Mozilla (Firefox), Google (Chrome), Opera, and Qihoo 360 (360 Secure Browser).[1]
The CA/Browser Forum maintains “Guidelines For The Issuance And Management Of Extended Validation (EV) Certificates”. The EV SSL standard improves security for Internet transactions and creates a more intuitive method of displaying secure sites to Internet users. In order for certificate authorities to issue EV SSL Certificates, they must be audited for compliance with the Forum's EV Guidelines[2] in accordance with either WebTrust or ETSI audit criteria.
The CA/Browser Forum adopted the "Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates" in 2011. These Guidelines, which are binding on members of the CA/Browser Forum, took effect July 1, 2012. These guidelines cover all CA-issued certificates. Certificates are now classified as "DV" (Domain Validated), "OV" (Organization Validated), "IV" (Individual Validated), and "EV" (Extended Validation), and a method is defined within the specification to distinguish the types of certificates.[3]
History
In 2005, Melih Abdulhayoglu of the Comodo Group organized[4] and arranged the first meeting of CA/Browser Forum. The first meeting was held in New York City. This was followed by a meeting in November 2005 in Kanata, Ontario, and a meeting in December, 2005, in Scottsdale, Arizona with the main objective to enable secure connections between users and websites.
In addition to CA/Browser Forum members, representatives of the Information Security Committee of the American Bar Association Section of Science & Technology, Law and the Canadian Institute of Chartered Accountants participated in developing the standards for issuing and managing Extended Validation SSL certificates.
Version 1.0 of the EV Guidelines was adopted on 7 June 2007.[5]
Version 1.1 was adopted by the CA/Browser Forum on 10 April 2008.[6]
Version 1.2 was adopted by the CA/Browser Forum on 1 Oct 2009.[7]
It is a great step forward in establishing verified identity for websites considers MSDN in its blog post.[8] Also, Microsoft's vision is that the backbone of an Internet identity system is composed of Extended Validation SSL Certificates intimately integrated with the users' browsing experience.[9]
The tougher certificates, coupled with browser developments,[10] could help fight phishing, which threatens the multibillion-dollar online retail market.
In November 2011, the CA/Browser Forum adopted version 1.0 of the "Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates."[3]
In February 2013 a new industry group, the Certificate Authority Security Council (CASC), was formed with a mission that includes promoting CA/Browser Forum standards. Membership requires adherence to CA/Browser Forum standards.[11] The CASC's founding members consist of the 7 largest Certificate Authorities: Comodo,[12][13] Symantec,[14] Trend Micro, DigiCert, Entrust,[15] GlobalSign [16] and GoDaddy.[17][18][18] [19] [20][21]
References
- ↑ "Members of the CA - Browser Forum - Over 30 CAs and All Major Browsers". CA/Browser Forum. Archived from the original on 2015-01-24. Retrieved 23 January 2015.
- ↑ CA/Browser Extended Validation Guidelines
- 1 2 "Baseline Requirements Documents". CA/Browser Forum. Retrieved 2014-10-26.
- ↑ eWeek Article about Origins of CA/Browser Forum and EV SSL
- ↑ "GUIDELINES FOR THE ISSUANCE AND MANAGEMENT OF EXTENDED VALIDATION CERTIFICATE" (PDF). The CA/Browser Forum.
- ↑ "GUIDELINES FOR THE ISSUANCE AND MANAGEMENT OF EXTENDED VALIDATION CERTIFICATES" (PDF). The CA/Browser Forum.
- ↑ "Guidelines For The Issuance And Management Of Extended Validation Certificates". The CA/Browser Forum.
- ↑ Extended Validation Guidelines v1 Released
- ↑ Microsoft information on EV in IE7
- ↑ CNet News - Browsers to get sturdier padlocks
- ↑ https://casecurity.org/casc/
- ↑ SSL Certificate Types, retrieved 2015-07-02
- ↑ SSL Certificate, retrieved 2015-07-02
- ↑ http://www.symantec.com/connect/blogs/let-s-build-more-secure-future
- ↑ http://www.entrust.com/news/2013-02-14-Entrust-Joins-Worlds-Leading-CAs-to-Form-Certificate-Authority-Security-Council-Advance-Internet-Security-and-Trusted-SSL-Ecosystem
- ↑ http://www.thepaypers.com/news/e-identity-security-online-fraud/globalsign-joins-the-certificate-authority-security-council-to-upgrade-internet-security/750211-26
- ↑ http://inside.godaddy.com/announcing-certificate-authority-security-council/
- 1 2 http://www.darkreading.com/authentication/167901072/security/news/240148546/major-certificate-authorities-unite-in-the-name-of-ssl-security.html
- ↑ http://www.networkworld.com/news/2013/021413-council-digital-certificate-266728.html
- ↑ http://www.cmswire.com/cms/customer-experience/website-certificate-authorities-set-up-security-council-for-advocacy-research-019619.php
- ↑ http://electronicstaff.com/2013/ssl-certificate-authority-security-council-takes-root
External links
- Official website
- "Windows Root Certificate Program members". Support. Knowledge Base. Microsoft. Jan 11, 2013. 931125. Archived from the original on 2013-12-16.
CAs approved for EV in Microsoft IE7
- "Configure Trusted Roots and Disallowed Certificates". TechNet. Certification Authority Guidance. Microsoft. May 5, 2014. dn265983.
- Oiaga, Marius (Jun 13, 2007). "Microsoft's Internet Identity Technology Gets Certified". Softpedia.