{"asset": "tls-certificate-requirement-effective-dates", "asset_type": "lifecycle", "body": "Forward-dated schedule of when each TLS certificate and certificate authority requirement takes effect, and which programme it binds. Each record is one requirement with its effective date, the Baseline Requirements section it amends, and the authority imposing it. Covers the CA/Browser Forum TLS Baseline Requirements effective-date table, the Google Chrome Root Program policy, and the Mozilla Root Store Policy. Answers 'when does the 200 day certificate lifetime take effect', 'TLS certificate maximum validity 100 days date', '47 day certificates 2029 timeline', 'when does domain validation reuse drop to 200 days', 'SC-081 phased schedule', and 'when do CAs have to do DNSSEC validation'. The dates changed recently and change again with every ballot, so an answer from model memory describes a world that has already moved; the maximum subscriber certificate validity drops to 200 days on 2026-03-15 and to 100 days on 2027-03-15, and the domain-validation reuse period and the subject-identity reuse period fall on different schedules to each other.\n", "description": "Forward-dated schedule of when each TLS certificate and certificate authority requirement takes effect, and which programme it binds. Each record is one requirement with its effective date, the Baseline Requirements section it amends, and the authority imposing it. Covers the CA/Browser Forum TLS Baseline Requirements effective-date table, the Google Chrome Root Program policy, and the Mozilla Root Store Policy. Answers 'when does the 200 day certificate lifetime take effect', 'TLS certificate maximum validity 100 days date', '47 day certificates 2029 timeline', 'when does domain validation reuse drop to 200 days', 'SC-081 phased schedule', and 'when do CAs have to do DNSSEC validation'. The dates changed recently and change again with every ballot, so an answer from model memory describes a world that has already moved; the maximum subscriber certificate validity drops to 200 days on 2026-03-15 and to 100 days on 2027-03-15, and the domain-validation reuse period and the subject-identity reuse period fall on different schedules to each other.", "file": "index.md", "generated": true, "harvested": "2026-08-05", "key_field": "requirement", "licence": "Facts extracted from freely published governance documents. The CA/Browser Forum publishes the Baseline Requirements publicly for implementation; the Chrome Root Program policy and Mozilla Root Store Policy are published openly by their respective root programmes. Each record quotes a short verbatim span and links back to the document section.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/", "https://googlechrome.github.io/chromerootprogram/", "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/"], "stale_after": "2026-11-03", "title": "TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "dataset", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates.\n\n**Effective date:** 2027-03-15\n\n**Baseline Requirements section:** 3.2.2.4 and 3.2.2.5\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2027-03-15 | 3.2.2.4 and 3.2.2.5 | CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4 and 3.2.2.5", "effective_date": "2027-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-and-3-2-2-5-cas-must-not-rely-on-methods-3-2-2-4-16-3-2-2-4-17-3-2-2-5-2-and-3-2-2-5-5-to-is.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-and-3-2-2-5-cas-must-not-rely-on-methods-3-2-2-4-16-3-2-2-4-17-3-2-2-5-2-and-3-2-2-5-5-to-is", "requirement": "CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2027-03-15 | 3.2.2.4 and 3.2.2.5 | CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates.\n\n**Effective date:** 2028-03-15\n\n**Baseline Requirements section:** 3.2.2.4 and 3.2.2.5\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2028-03-15 | 3.2.2.4 and 3.2.2.5 | CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4 and 3.2.2.5", "effective_date": "2028-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-and-3-2-2-5-cas-must-not-rely-on-methods-3-2-2-4-4-3-2-2-4-13-and-3-2-2-4-14-to-issue-subscr.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-and-3-2-2-5-cas-must-not-rely-on-methods-3-2-2-4-4-3-2-2-4-13-and-3-2-2-4-14-to-issue-subscr", "requirement": "CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2028-03-15 | 3.2.2.4 and 3.2.2.5 | CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information.\n\n**Effective date:** 2025-01-15\n\n**Baseline Requirements section:** 3.2.2.4\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-01-15 | 3.2.2.4 | CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4", "effective_date": "2025-01-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-rely-on-https-websites-to-identify-domain-contact-information-cas-m.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-rely-on-https-websites-to-identify-domain-contact-information-cas-m", "requirement": "CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-01-15 | 3.2.2.4 | CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 3.2.2.4\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 3.2.2.4 | CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-rely-on-method-3-2-2-4-8-to-issue-subscriber-certificates.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-rely-on-method-3-2-2-4-8-to-issue-subscriber-certificates", "requirement": "CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 3.2.2.4 | CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates.\n\n**Effective date:** 2025-07-15\n\n**Baseline Requirements section:** 3.2.2.4\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-07-15 | 3.2.2.4 | CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4", "effective_date": "2025-07-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-rely-on-methods-3-2-2-4-2-and-3-2-2-4-15-to-issue-subscriber-certif.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-rely-on-methods-3-2-2-4-2-and-3-2-2-4-15-to-issue-subscriber-certif", "requirement": "CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-07-15 | 3.2.2.4 | CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 3.2.2.4\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 3.2.2.4 | CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-use-local-policy-to-disable-dnssec-validation-on-any-dns-query-asso.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-cas-must-not-use-local-policy-to-disable-dnssec-validation-on-any-dns-query-asso", "requirement": "CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 3.2.2.4 | CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 3.2.2.4\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 3.2.2.4 | DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.4", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-dnssec-validation-back-to-the-iana-dnssec-root-trust-anchor-must-be-performed-on.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-4-dnssec-validation-back-to-the-iana-dnssec-root-trust-anchor-must-be-performed-on", "requirement": "DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 3.2.2.4 | DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates.\n\n**Effective date:** 2027-03-15\n\n**Baseline Requirements section:** 3.2.2.5.3\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2027-03-15 | 3.2.2.5.3 | CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.5.3", "effective_date": "2027-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-5-3-cas-must-not-rely-on-method-3-2-2-5-3-to-issue-subscriber-certificates.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-5-3-cas-must-not-rely-on-method-3-2-2-5-3-to-issue-subscriber-certificates", "requirement": "CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2027-03-15 | 3.2.2.5.3 | CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 3.2.2.8.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 3.2.2.8.1 | CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.8.1", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-8-1-cas-must-not-use-local-policy-to-disable-dnssec-validation-on-any-dns-query-asso.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-8-1-cas-must-not-use-local-policy-to-disable-dnssec-validation-on-any-dns-query-asso", "requirement": "CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 3.2.2.8.1 | CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 3.2.2.8.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 3.2.2.8.1 | DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.8.1", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-8-1-dnssec-validation-back-to-the-iana-dnssec-root-trust-anchor-must-be-performed-on.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-8-1-dnssec-validation-back-to-the-iana-dnssec-root-trust-anchor-must-be-performed-on", "requirement": "DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 3.2.2.8.1 | DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 3.2.2.8.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 3.2.2.8.1 | DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.8.1", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-8-1-dnssec-validation-errors-observed-by-the-primary-network-perspective-e-g-servfai.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-8-1-dnssec-validation-errors-observed-by-the-primary-network-perspective-e-g-servfai", "requirement": "DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 3.2.2.8.1 | DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified.\n\n**Effective date:** 2025-03-15\n\n**Baseline Requirements section:** 3.2.2.9\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-03-15 | 3.2.2.9 | CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "3.2.2.9", "effective_date": "2025-03-15", "file": "ca-browser-forum-tls-baseline-requirements-3-2-2-9-cas-must-corroborate-the-results-of-domain-validation-and-caa-checks-from-multip.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-3-2-2-9-cas-must-corroborate-the-results-of-domain-validation-and-caa-checks-from-multip", "requirement": "CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-03-15 | 3.2.2.9 | CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Domain Name and IP Address validation maximum data reuse period is 10 days.\n\n**Effective date:** 2029-03-15\n\n**Baseline Requirements section:** 4.2.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2029-03-15 | 4.2.1 | Domain Name and IP Address validation maximum data reuse period is 10 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.1", "effective_date": "2029-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-1-domain-name-and-ip-address-validation-maximum-data-reuse-period-is-10-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-1-domain-name-and-ip-address-validation-maximum-data-reuse-period-is-10-days", "requirement": "Domain Name and IP Address validation maximum data reuse period is 10 days.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2029-03-15 | 4.2.1 | Domain Name and IP Address validation maximum data reuse period is 10 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Domain Name and IP Address validation maximum data reuse period is 10 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Domain Name and IP Address validation maximum data reuse period is 100 days.\n\n**Effective date:** 2027-03-15\n\n**Baseline Requirements section:** 4.2.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2027-03-15 | 4.2.1 | Domain Name and IP Address validation maximum data reuse period is 100 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.1", "effective_date": "2027-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-1-domain-name-and-ip-address-validation-maximum-data-reuse-period-is-100-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-1-domain-name-and-ip-address-validation-maximum-data-reuse-period-is-100-days", "requirement": "Domain Name and IP Address validation maximum data reuse period is 100 days.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2027-03-15 | 4.2.1 | Domain Name and IP Address validation maximum data reuse period is 100 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Domain Name and IP Address validation maximum data reuse period is 100 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Domain Name and IP Address validation maximum data reuse period is 200 days.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 4.2.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 4.2.1 | Domain Name and IP Address validation maximum data reuse period is 200 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.1", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-1-domain-name-and-ip-address-validation-maximum-data-reuse-period-is-200-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-1-domain-name-and-ip-address-validation-maximum-data-reuse-period-is-200-days", "requirement": "Domain Name and IP Address validation maximum data reuse period is 200 days.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 4.2.1 | Domain Name and IP Address validation maximum data reuse period is 200 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Domain Name and IP Address validation maximum data reuse period is 200 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Subject Identity Information validation maximum data reuse period is 398 days.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 4.2.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 4.2.1 | Subject Identity Information validation maximum data reuse period is 398 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.1", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-1-subject-identity-information-validation-maximum-data-reuse-period-is-398-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-1-subject-identity-information-validation-maximum-data-reuse-period-is-398-days", "requirement": "Subject Identity Information validation maximum data reuse period is 398 days.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 4.2.1 | Subject Identity Information validation maximum data reuse period is 398 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Subject Identity Information validation maximum data reuse period is 398 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657.\n\n**Effective date:** 2027-03-15\n\n**Baseline Requirements section:** 4.2.2.1.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> CAs MUST process the accounturi and validationmethods parameters as specified in <https://datatracker.ietf.org/doc/html/rfc8657> RFC 8657\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.2.1.2", "effective_date": "2027-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-2-1-2-cas-must-process-the-accounturi-and-validationmethods-parameters-as-specified-in.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-2-1-2-cas-must-process-the-accounturi-and-validationmethods-parameters-as-specified-in", "requirement": "CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "CAs MUST process the accounturi and validationmethods parameters as specified in <https://datatracker.ietf.org/doc/html/rfc8657> RFC 8657", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "br_section, effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in RFC 7565\n\n**Effective date:** 2027-03-15\n\n**Baseline Requirements section:** 4.2.2.1.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.2.1.2", "effective_date": "2027-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-2-1-2-if-the-ca-does-not-identify-the-subscriber-account-via-an-acme-account-url-as-de.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-2-1-2-if-the-ca-does-not-identify-the-subscriber-account-via-an-acme-account-url-as-de", "requirement": "If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in RFC 7565", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in RFC 7565 \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "br_section, effective_date, requirement", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 4.2.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 4.2.2 | CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.2.2", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-2-2-cas-shall-not-issue-certificates-containing-domain-names-that-end-in-an-ip-rever.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-2-2-cas-shall-not-issue-certificates-containing-domain-names-that-end-in-an-ip-rever", "requirement": "CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 4.2.2 | CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements.\n\n**Effective date:** 2025-03-15\n\n**Baseline Requirements section:** 4.3.1.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-03-15 | 4.3.1.2 | The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.3.1.2", "effective_date": "2025-03-15", "file": "ca-browser-forum-tls-baseline-requirements-4-3-1-2-the-ca-shall-implement-a-linting-process-to-test-the-technical-conformity-of-the.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-3-1-2-the-ca-shall-implement-a-linting-process-to-test-the-technical-conformity-of-the", "requirement": "The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-03-15 | 4.3.1.2 | The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance.\n\n**Effective date:** 2025-01-15\n\n**Baseline Requirements section:** 4.9.9\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-01-15 | 4.9.9 | Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "4.9.9", "effective_date": "2025-01-15", "file": "ca-browser-forum-tls-baseline-requirements-4-9-9-subscriber-certificate-ocsp-responses-must-be-available-15-minutes-after-issuanc.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-4-9-9-subscriber-certificate-ocsp-responses-must-be-available-15-minutes-after-issuanc", "requirement": "Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-01-15 | 4.9.9 | Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Audit logs of verification activity MUST include specific information.\n\n**Effective date:** 2026-07-15\n\n**Baseline Requirements section:** 5.4.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-07-15 | 5.4.1 | Audit logs of verification activity MUST include specific information.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "5.4.1", "effective_date": "2026-07-15", "file": "ca-browser-forum-tls-baseline-requirements-5-4-1-audit-logs-of-verification-activity-must-include-specific-information.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-5-4-1-audit-logs-of-verification-activity-must-include-specific-information", "requirement": "Audit logs of verification activity MUST include specific information.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-07-15 | 5.4.1 | Audit logs of verification activity MUST include specific information.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Audit logs of verification activity MUST include specific information. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements.\n\n**Effective date:** 2025-12-01\n\n**Baseline Requirements section:** 5.7.1.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-12-01 | 5.7.1.2 | CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "5.7.1.2", "effective_date": "2025-12-01", "file": "ca-browser-forum-tls-baseline-requirements-5-7-1-2-cas-shall-assert-in-section-5-7-1-of-their-cps-or-combined-cp-cps-their-mass-rev.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-5-7-1-2-cas-shall-assert-in-section-5-7-1-of-their-cps-or-combined-cp-cps-their-mass-rev", "requirement": "CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-12-01 | 5.7.1.2 | CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Maximum validity period of Subscriber Certificates is 100 days.\n\n**Effective date:** 2027-03-15\n\n**Baseline Requirements section:** 6.3.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** Subscriber Certificates only\n\n> 2027-03-15 | 6.3.2 | Maximum validity period of Subscriber Certificates is 100 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "6.3.2", "effective_date": "2027-03-15", "file": "ca-browser-forum-tls-baseline-requirements-6-3-2-maximum-validity-period-of-subscriber-certificates-is-100-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-6-3-2-maximum-validity-period-of-subscriber-certificates-is-100-days", "requirement": "Maximum validity period of Subscriber Certificates is 100 days.", "scope": "Subscriber Certificates only", "source_quote": "2027-03-15 | 6.3.2 | Maximum validity period of Subscriber Certificates is 100 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Maximum validity period of Subscriber Certificates is 100 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Maximum validity period of Subscriber Certificates is 200 days.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 6.3.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** Subscriber Certificates only\n\n> 2026-03-15 | 6.3.2 | Maximum validity period of Subscriber Certificates is 200 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "6.3.2", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-6-3-2-maximum-validity-period-of-subscriber-certificates-is-200-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-6-3-2-maximum-validity-period-of-subscriber-certificates-is-200-days", "requirement": "Maximum validity period of Subscriber Certificates is 200 days.", "scope": "Subscriber Certificates only", "source_quote": "2026-03-15 | 6.3.2 | Maximum validity period of Subscriber Certificates is 200 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Maximum validity period of Subscriber Certificates is 200 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Maximum validity period of Subscriber Certificates is 47 days.\n\n**Effective date:** 2029-03-15\n\n**Baseline Requirements section:** 6.3.2\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** Subscriber Certificates only\n\n> 2029-03-15 | 6.3.2 | Maximum validity period of Subscriber Certificates is 47 days.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "6.3.2", "effective_date": "2029-03-15", "file": "ca-browser-forum-tls-baseline-requirements-6-3-2-maximum-validity-period-of-subscriber-certificates-is-47-days.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-6-3-2-maximum-validity-period-of-subscriber-certificates-is-47-days", "requirement": "Maximum validity period of Subscriber Certificates is 47 days.", "scope": "Subscriber Certificates only", "source_quote": "2029-03-15 | 6.3.2 | Maximum validity period of Subscriber Certificates is 47 days.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Maximum validity period of Subscriber Certificates is 47 days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4.\n\n**Effective date:** 2026-03-15\n\n**Baseline Requirements section:** 7.1.2.4\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-03-15 | 7.1.2.4 | CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "7.1.2.4", "effective_date": "2026-03-15", "file": "ca-browser-forum-tls-baseline-requirements-7-1-2-4-cas-must-not-use-precertificate-signing-cas-to-issue-precertificates-cas-must-no.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-7-1-2-4-cas-must-not-use-precertificate-signing-cas-to-issue-precertificates-cas-must-no", "requirement": "CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-03-15 | 7.1.2.4 | CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** Sunset all remaining use of SHA-1 in Certificates and CRLs.\n\n**Effective date:** 2026-09-15\n\n**Baseline Requirements section:** 7.1.3.2.1\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2026-09-15 | 7.1.3.2.1 | Sunset all remaining use of SHA-1 in Certificates and CRLs.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "7.1.3.2.1", "effective_date": "2026-09-15", "file": "ca-browser-forum-tls-baseline-requirements-7-1-3-2-1-sunset-all-remaining-use-of-sha-1-in-certificates-and-crls.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-7-1-3-2-1-sunset-all-remaining-use-of-sha-1-in-certificates-and-crls", "requirement": "Sunset all remaining use of SHA-1 in Certificates and CRLs.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2026-09-15 | 7.1.3.2.1 | Sunset all remaining use of SHA-1 in Certificates and CRLs.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "Sunset all remaining use of SHA-1 in Certificates and CRLs. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "CA/Browser Forum TLS Baseline Requirements", "body": "**Requirement:** The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits.\n\n**Effective date:** 2025-03-15\n\n**Baseline Requirements section:** 8.7\n\n**Authority:** CA/Browser Forum TLS Baseline Requirements\n\n**Scope:** all publicly-trusted CAs issuing TLS server certificates\n\n> 2025-03-15 | 8.7 | The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits.\n\nSource: <https://cabforum.org/working-groups/server/baseline-requirements/requirements/>\n", "br_section": "8.7", "effective_date": "2025-03-15", "file": "ca-browser-forum-tls-baseline-requirements-8-7-the-ca-should-use-a-linting-process-to-test-the-technical-accuracy-of-already-is.md", "generated": true, "harvested": "2026-08-05", "id": "ca-browser-forum-tls-baseline-requirements-8-7-the-ca-should-use-a-linting-process-to-test-the-technical-accuracy-of-already-is", "requirement": "The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits.", "scope": "all publicly-trusted CAs issuing TLS server certificates", "source_quote": "2025-03-15 | 8.7 | The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits.", "sources": ["https://cabforum.org/working-groups/server/baseline-requirements/requirements/"], "stale_after": "2026-11-03", "title": "The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** A Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.\n\n**Effective date:** 2026-06-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Effective June 15, 2026 , a Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2026-06-15", "file": "google-chrome-root-program-a-chrome-root-program-participant-s-cp-or-combined-cp-cps-must-explicitly-state-.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-a-chrome-root-program-participant-s-cp-or-combined-cp-cps-must-explicitly-state-", "requirement": "A Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Effective June 15, 2026 , a Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "A Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.\n\n**Effective date:** 2027-03-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> All corresponding subscriber certificates issued on or after March 15, 2027 , MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2027-03-15", "file": "google-chrome-root-program-all-subscriber-certificates-must-include-the-extendedkeyusage-extension-and-only.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-all-subscriber-certificates-must-include-the-extendedkeyusage-extension-and-only", "requirement": "All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.", "scope": "CAs included in the Chrome Root Store", "source_quote": "All corresponding subscriber certificates issued on or after March 15, 2027 , MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, scope", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** All unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution.\n\n**Effective date:** 2027-03-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Effective March 15, 2027 , all unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2027-03-15", "file": "google-chrome-root-program-all-unexpired-and-unrevoked-subordinate-ca-certificates-signed-by-a-root-ca-cert.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-all-unexpired-and-unrevoked-subordinate-ca-certificates-signed-by-a-root-ca-cert", "requirement": "All unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Effective March 15, 2027 , all unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "All unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates, and issue Automation Test Certificates renewed at least once every 30 calendar days.\n\n**Effective date:** 2027-03-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> effective March 15, 2027 , for each CCADB root certificate record corresponding to a root included in the Chrome Root Store, CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2027-03-15", "file": "google-chrome-root-program-ca-owners-must-disclose-at-least-one-1-automation-solution-for-each-baseline-req.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-ca-owners-must-disclose-at-least-one-1-automation-solution-for-each-baseline-req", "requirement": "CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates, and issue Automation Test Certificates renewed at least once every 30 calendar days.", "scope": "CAs included in the Chrome Root Store", "source_quote": "effective March 15, 2027 , for each CCADB root certificate record corresponding to a root included in the Chrome Root Store, CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates, and issue Automation Test Certificates renewed at least once every 30 calendar days. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** CA Owners MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as Usable or Qualified before issuing the corresponding certificate.\n\n**Effective date:** 2026-06-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Effective June 15, 2026 , CA Owners with CA certificates that validate to a certificate included in the Chrome Root Store MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2026-06-15", "file": "google-chrome-root-program-ca-owners-must-ensure-that-all-tls-server-authentication-precertificates-issued-.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-ca-owners-must-ensure-that-all-tls-server-authentication-precertificates-issued-", "requirement": "CA Owners MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as Usable or Qualified before issuing the corresponding certificate.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Effective June 15, 2026 , CA Owners with CA certificates that validate to a certificate included in the Chrome Root Store MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "CA Owners MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as Usable or Qualified before issuing the corresponding certificate. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program.\n\n**Effective date:** 2026-06-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Before June 15, 2026 , CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2026-06-15", "file": "google-chrome-root-program-ca-owners-with-more-than-two-2-self-signed-root-ca-certificates-in-the-chrome-ro.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-ca-owners-with-more-than-two-2-self-signed-root-ca-certificates-in-the-chrome-ro", "requirement": "CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Before June 15, 2026 , CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** Root CA certificates with key material created between January 1, 2006 and December 31, 2007 (inclusive) will be removed from the Chrome Root Store.\n\n**Effective date:** 2026-04-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Between January 1, 2006 and December 31, 2007 (inclusive) | April 15, 2026\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2026-04-15", "file": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2006-and-decemb.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2006-and-decemb", "requirement": "Root CA certificates with key material created between January 1, 2006 and December 31, 2007 (inclusive) will be removed from the Chrome Root Store.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Between January 1, 2006 and December 31, 2007 (inclusive) | April 15, 2026", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "Root CA certificates with key material created between January 1, 2006 and December 31, 2007 (inclusive) will be removed from the Chrome Root Store. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement, scope", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** Root CA certificates with key material created between January 1, 2008 and December 31, 2009 (inclusive) will be removed from the Chrome Root Store.\n\n**Effective date:** 2027-04-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Between January 1, 2008 and December 31, 2009 (inclusive) | April 15, 2027\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2027-04-15", "file": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2008-and-decemb.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2008-and-decemb", "requirement": "Root CA certificates with key material created between January 1, 2008 and December 31, 2009 (inclusive) will be removed from the Chrome Root Store.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Between January 1, 2008 and December 31, 2009 (inclusive) | April 15, 2027", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "Root CA certificates with key material created between January 1, 2008 and December 31, 2009 (inclusive) will be removed from the Chrome Root Store. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement, scope", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** Root CA certificates with key material created between January 1, 2010 and December 31, 2011 (inclusive) will be removed from the Chrome Root Store.\n\n**Effective date:** 2028-04-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Between January 1, 2010 and December 31, 2011 (inclusive) | April 15, 2028\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2028-04-15", "file": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2010-and-decemb.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2010-and-decemb", "requirement": "Root CA certificates with key material created between January 1, 2010 and December 31, 2011 (inclusive) will be removed from the Chrome Root Store.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Between January 1, 2010 and December 31, 2011 (inclusive) | April 15, 2028", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "Root CA certificates with key material created between January 1, 2010 and December 31, 2011 (inclusive) will be removed from the Chrome Root Store. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement, scope", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** Root CA certificates with key material created between January 1, 2012 and April 14, 2014 (inclusive) will be removed from the Chrome Root Store.\n\n**Effective date:** 2029-04-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Between January 1, 2012 and April 14, 2014 (inclusive) | April 15, 2029\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2029-04-15", "file": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2012-and-april-.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-root-ca-certificates-with-key-material-created-between-january-1-2012-and-april-", "requirement": "Root CA certificates with key material created between January 1, 2012 and April 14, 2014 (inclusive) will be removed from the Chrome Root Store.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Between January 1, 2012 and April 14, 2014 (inclusive) | April 15, 2029", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "Root CA certificates with key material created between January 1, 2012 and April 14, 2014 (inclusive) will be removed from the Chrome Root Store. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement, scope", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** The Chrome Root Program will phase-out PKI hierarchies found in violation of subordinate CA extendedKeyUsage requirements.\n\n**Effective date:** 2026-06-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Beginning June 15, 2026 , the Chrome Root Program will phase-out PKI hierarchies found in violation of the below requirements.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2026-06-15", "file": "google-chrome-root-program-the-chrome-root-program-will-phase-out-pki-hierarchies-found-in-violation-of-sub.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-the-chrome-root-program-will-phase-out-pki-hierarchies-found-in-violation-of-sub", "requirement": "The Chrome Root Program will phase-out PKI hierarchies found in violation of subordinate CA extendedKeyUsage requirements.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Beginning June 15, 2026 , the Chrome Root Program will phase-out PKI hierarchies found in violation of the below requirements.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "The Chrome Root Program will phase-out PKI hierarchies found in violation of subordinate CA extendedKeyUsage requirements. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date, requirement", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** The Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB.\n\n**Effective date:** 2027-03-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Beginning March 15, 2027 , the Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2027-03-15", "file": "google-chrome-root-program-the-chrome-root-program-will-phase-out-pki-hierarchies-found-issuing-new-certifi.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-the-chrome-root-program-will-phase-out-pki-hierarchies-found-issuing-new-certifi", "requirement": "The Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Beginning March 15, 2027 , the Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "The Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Google Chrome Root Program", "body": "**Requirement:** The Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner.\n\n**Effective date:** 2027-09-15\n\n**Authority:** Google Chrome Root Program\n\n**Scope:** CAs included in the Chrome Root Store\n\n> Effective September 15, 2027 , the Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner.\n\nSource: <https://googlechrome.github.io/chromerootprogram/>\n", "effective_date": "2027-09-15", "file": "google-chrome-root-program-the-chrome-root-store-will-only-include-a-maximum-of-two-2-self-signed-root-ca-c.md", "generated": true, "harvested": "2026-08-05", "id": "google-chrome-root-program-the-chrome-root-store-will-only-include-a-maximum-of-two-2-self-signed-root-ca-c", "requirement": "The Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner.", "scope": "CAs included in the Chrome Root Store", "source_quote": "Effective September 15, 2027 , the Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner.", "sources": ["https://googlechrome.github.io/chromerootprogram/"], "stale_after": "2026-11-03", "title": "The Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Mozilla Root Store Policy", "body": "**Requirement:** For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in Mozilla's root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR).\n\n**Effective date:** 2027-07-01\n\n**Authority:** Mozilla Root Store Policy\n\n**Scope:** CA operators whose certificates are included in Mozilla's root store with the websites trust bit enabled\n\n> For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in our root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR).\n\nSource: <https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/>\n", "effective_date": "2027-07-01", "file": "mozilla-root-store-policy-for-each-annual-audit-period-beginning-on-or-after-july-1-2027-each-ca-operator-.md", "generated": true, "harvested": "2026-08-05", "id": "mozilla-root-store-policy-for-each-annual-audit-period-beginning-on-or-after-july-1-2027-each-ca-operator-", "requirement": "For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in Mozilla's root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR).", "scope": "CA operators whose certificates are included in Mozilla's root store with the websites trust bit enabled", "source_quote": "For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in our root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR).", "sources": ["https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/"], "stale_after": "2026-11-03", "title": "For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in Mozilla's root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR). \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "effective_date", "verified": true}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Mozilla Root Store Policy", "body": "**Requirement:** WebTrust \"Principles and Criteria for Certification Authorities - Network Security\" Version 1.7 permitted for audit periods ending before 2026-11-29; Version 2.0.5 required thereafter.\n\n**Effective date:** 2026-11-29\n\n**Authority:** Mozilla Root Store Policy\n\n**Scope:** CA operators whose certificates are included in Mozilla's root store\n\n> Version 1.7 permitted for audit periods ending before 2026-11-29\n\nSource: <https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/>\n", "effective_date": "2026-11-29", "file": "mozilla-root-store-policy-webtrust-principles-and-criteria-for-certification-authorities-network-security-.md", "generated": true, "harvested": "2026-08-05", "id": "mozilla-root-store-policy-webtrust-principles-and-criteria-for-certification-authorities-network-security-", "requirement": "WebTrust \"Principles and Criteria for Certification Authorities - Network Security\" Version 1.7 permitted for audit periods ending before 2026-11-29; Version 2.0.5 required thereafter.", "scope": "CA operators whose certificates are included in Mozilla's root store", "source_quote": "Version 1.7 permitted for audit periods ending before 2026-11-29", "sources": ["https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/"], "stale_after": "2026-11-03", "title": "WebTrust \"Principles and Criteria for Certification Authorities - Network Security\" Version 1.7 permitted for audit periods ending before 2026-11-29; Version 2.0.5 required thereafter. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "requirement, scope", "verified": false}
{"asset": "tls-certificate-requirement-effective-dates", "authority": "Mozilla Root Store Policy", "body": "**Requirement:** WebTrust \"Principles and Criteria for Certification Authorities - SSL Baseline\" Version 2.9 permitted for audit periods ending before 2026-11-29; WebTrust TLS Baseline Version 2.10 required thereafter.\n\n**Effective date:** 2026-11-29\n\n**Authority:** Mozilla Root Store Policy\n\n**Scope:** CA operators whose certificates are included in Mozilla's root store\n\n> Version 2.9 permitted for audit periods ending before 2026-11-29\n\nSource: <https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/>\n", "effective_date": "2026-11-29", "file": "mozilla-root-store-policy-webtrust-principles-and-criteria-for-certification-authorities-ssl-baseline-vers.md", "generated": true, "harvested": "2026-08-05", "id": "mozilla-root-store-policy-webtrust-principles-and-criteria-for-certification-authorities-ssl-baseline-vers", "requirement": "WebTrust \"Principles and Criteria for Certification Authorities - SSL Baseline\" Version 2.9 permitted for audit periods ending before 2026-11-29; WebTrust TLS Baseline Version 2.10 required thereafter.", "scope": "CA operators whose certificates are included in Mozilla's root store", "source_quote": "Version 2.9 permitted for audit periods ending before 2026-11-29", "sources": ["https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/"], "stale_after": "2026-11-03", "title": "WebTrust \"Principles and Criteria for Certification Authorities - SSL Baseline\" Version 2.9 permitted for audit periods ending before 2026-11-29; WebTrust TLS Baseline Version 2.10 required thereafter. \u2014 TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)", "type": "lifecycle", "unverified_fields": "requirement, scope", "verified": false}
