Skip to main content
SGSiteGraph

cabforum.org

CA/Browser Forum - Certificate Issuers, Certificate Consumers, and Interested Parties Working to Secure the Web

Last scanned Aug 24, 2026, 1:22 PM

85

Overall score

Great

Summary

The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers)… This website uses Svelte hosted on Fastly behind Fastly CDN. SEO is good (80/100) and accessibility is excellent (100/100). Security scores fair (65/100) and performance excellent (100/100). Top issue: Title longer than 60 characters.

The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers). More information for about the forum and information for Site Owners, Developers, Auditors and Assessors, and Potential Members can be found in the About section of this website. Recent posts Ballot SMC018: Realignment of Multipurpose use cases August 11, 2026 by Stephen Davidson Ballot S/MIME Ballot SMC018: Realignment of Multipurpose use casesSummary: This ballot implements the requirements of CCADB Policy Section 6.3 relating to cross-certificates into the S/MIME BR effective immediately. Ballot SC100: DNSSEC Clarification and Consolidation August 6, 2026 by Ballot Server Certificates Voting Results Certificate Issuers 22 votes in total: 2026-07-30 Minutes of the Server Certificate Working Group July 30, 2026 by Wayne Thayer Minutes Server Certificates Minutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia) More posts of the CA/Browser Forum

United States
Hosted on Fastly

Top issues to fix

7 issues found · 2 high priority

  • Missing Strict-Transport-Security header

    Security

    Add HSTS so browsers always use HTTPS — this closes the protocol-downgrade attack window.

  • Missing Content-Security-Policy header

    Security

    Add a CSP to control which sources can run scripts — the strongest single defense against XSS.

  • Missing X-Content-Type-Options header

    Security

    Add X-Content-Type-Options: nosniff to stop MIME-sniffing attacks.

  • Missing X-Frame-Options header

    Security

    Add X-Frame-Options (or a CSP frame-ancestors rule) to prevent clickjacking via hidden iframes.

  • Title longer than 60 characters

    SEO

    Shorten the title to under 60 characters so search results don't truncate it.

  • Meta description longer than 160 characters

    SEO

    Trim the meta description to under 160 characters to avoid truncation in search results.

+1 more issue — details in the sections below.

80

SEO

3 issue(s) found

100

Performance

205 ms

65

Security

HTTPS & header checks

100

Accessibility

0 issue(s) found

Not enough scan history yet to show a trend — check back after this site has been re-scanned a few more times.

Organization

Company details published in this site's own structured data.

The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers). More information for about the forum and information for Site Owners, Developers, Auditors and Assessors, and Potential Members can be found in the About section of this website. Recent posts Ballot SMC018: Realignment of Multipurpose use cases August 11, 2026 by Stephen Davidson Ballot S/MIME Ballot SMC018: Realignment of Multipurpose use casesSummary: This ballot implements the requirements of CCADB Policy Section 6.3 relating to cross-certificates into the S/MIME BR effective immediately. Ballot SC100: DNSSEC Clarification and Consolidation August 6, 2026 by Ballot Server Certificates Voting Results Certificate Issuers 22 votes in total: 2026-07-30 Minutes of the Server Certificate Working Group July 30, 2026 by Wayne Thayer Minutes Server Certificates Minutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia) More posts of the CA/Browser Forum

Contact

Email, phone, and address published on this site's own pages.

Meta tags

Title
CA/Browser Forum - Certificate Issuers, Certificate Consumers, and Interested Parties Working to Secure the Web
Description
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers). More information for about the forum and information for Site Owners, Developers, Auditors and Assessors, and Potential Members can be found in the About section of this website. Recent posts Ballot SMC018: Realignment of Multipurpose use cases August 11, 2026 by Stephen Davidson Ballot S/MIME Ballot SMC018: Realignment of Multipurpose use casesSummary: This ballot implements the requirements of CCADB Policy Section 6.3 relating to cross-certificates into the S/MIME BR effective immediately. Ballot SC100: DNSSEC Clarification and Consolidation August 6, 2026 by Ballot Server Certificates Voting Results Certificate Issuers 22 votes in total: 2026-07-30 Minutes of the Server Certificate Working Group July 30, 2026 by Wayne Thayer Minutes Server Certificates Minutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia) More posts of the CA/Browser Forum
Canonical
https://cabforum.org/
Language
en
Charset
utf-8
Viewport
width=device-width,initial-scale=1
Robots meta
Manifest

OpenGraph & Twitter Card

OpenGraph

og:title
CA/Browser Forum - Certificate Issuers, Certificate Consumers, and Interested Parties Working to Secure the Web
og:description
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers). More information for about the forum and information for Site Owners, Developers, Auditors and Assessors, and Potential Members can be found in the About section of this website. Recent posts Ballot SMC018: Realignment of Multipurpose use cases August 11, 2026 by Stephen Davidson Ballot S/MIME Ballot SMC018: Realignment of Multipurpose use casesSummary: This ballot implements the requirements of CCADB Policy Section 6.3 relating to cross-certificates into the S/MIME BR effective immediately. Ballot SC100: DNSSEC Clarification and Consolidation August 6, 2026 by Ballot Server Certificates Voting Results Certificate Issuers 22 votes in total: 2026-07-30 Minutes of the Server Certificate Working Group July 30, 2026 by Wayne Thayer Minutes Server Certificates Minutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia) More posts of the CA/Browser Forum
og:type
website
og:url
https://cabforum.org/

Twitter Card

twitter:card
summary_large_image
twitter:title
CA/Browser Forum - Certificate Issuers, Certificate Consumers, and Interested Parties Working to Secure the Web
twitter:description
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers). More information for about the forum and information for Site Owners, Developers, Auditors and Assessors, and Potential Members can be found in the About section of this website. Recent posts Ballot SMC018: Realignment of Multipurpose use cases August 11, 2026 by Stephen Davidson Ballot S/MIME Ballot SMC018: Realignment of Multipurpose use casesSummary: This ballot implements the requirements of CCADB Policy Section 6.3 relating to cross-certificates into the S/MIME BR effective immediately. Ballot SC100: DNSSEC Clarification and Consolidation August 6, 2026 by Ballot Server Certificates Voting Results Certificate Issuers 22 votes in total: 2026-07-30 Minutes of the Server Certificate Working Group July 30, 2026 by Wayne Thayer Minutes Server Certificates Minutes for the Server Certificate Working Group teleconference - July 30, 2026Meeting Date: 2026-07-30 Note Well: Wayne Thayer chaired the meeting in Dimitris Zacharopoulos’s absence. The Note Well was read. Prior to the start of the meeting, attendees briefly discussed enabling the Webex AI Assistant to generate meeting notes. No objections were raised, and the AI assistant was enabled on a trial basis. Review of Agenda: No changes or additions were proposed to the published agenda. Approval of Minutes: July 2, 2026 Teleconference approved without objection. July 16, 2026 Teleconference approved without objection. Membership Applications: There were no new membership applications. Ballot Status: SC-100 - DNSSEC Clarifications / Consolidation: Rich Smith reported that no additional comments had been received and that the discussion-period restart resolved prior concerns. Barring further objections, the ballot will enter the voting period at 17:00 UTC on July 30. Scott Rea expressed support for moving the ballot forward. SC-103 - Require EKUs for Cross-Certified Subordinate CAs: Aaron Gable reported that discussion remains active on the mailing list and outstanding questions still require responses. The ballot will remain in discussion until those issues are resolved. Let’s Encrypt has been busy implementing MTC issuance. Ballots in Voting: None. Ballots in IPR Review: Wayne Thayer reminded members that SC-101 and SC-102 remain under IPR review and encouraged members to complete their reviews before the review periods expire. Draft Ballots: Martijn Katerbarg’s Certificate Problem Report / Revocation clarification ballot received no update. Gurleen Grewal reported that work continues to reconcile the two ML-DSA proposal drafts, but there are no other updates at this time. No update was available on Dimitris Zacharopoulos’s revocation timeline ballot. CCADB Roadmap and API Discussion: Stephen Davidson suggested holding a future discussion devoted to the CCADB roadmap and API, noting that increasing reliance on CCADB automation makes it useful to discuss future plans and gather structured feedback from API users. Discussion included: Chad Dandar suggested the topic could be discussed during a future CCADB SC meeting. Aaron Poulsen supported including API documentation and sandbox capabilities in such a discussion. Ryan Dickson shared the current API documentation in chat: https://github.com/mozilla/CCADB-Tools/tree/master/API_AddUpdateIntermediateCert. Arman Asemani recommended beginning with a discussion thread on public@ccadb.org so that written feedback and enhancement requests could be collected before scheduling a broader discussion. Stephen Davidson agreed to initiate the mailing list discussion. Any Other Business: No other business was discussed. Adjourn The meeting adjourned. The next Server Certificate Working Group teleconference is scheduled for 2026-08-13. Attendees: Jeff Stapleton (Wells Fargo), Naresh Charugundla (Microsoft), Moritz Schaal (D-Trust), Aaron Gable (Let’s Encrypt), Aaron Poulsen (SSL.com), Abdul Hakeem Putra (MSC Trustgate Sdn Bhd), Adam Fiock (SSL.com), Adam Jones (Microsoft), Adriano Santoni (Actalis S.p.A.), Andrea Holland (IdenTrust), Antti Backman (Telia Company), Arman Asemani (Apple), Arno Fiedler (ETSI), Ben Wilson (Mozilla), Chad Dandar (Cisco Systems), Chris Clements (Google), Clint Wilson (Apple), Corey Rasmussen (OATI), Dan McKinney (US Federal PKI Management Authority), Dean Coclin (DigiCert), Dustin Hollenback (Apple), Eric Kramer (Sectigo), Gregory Tomko (GlobalSign), Gurleen Grewal (Google), Hogeun Yoo (NAVER Cloud Trust Services), Inaba Atsushi (GlobalSign), Johnny Reading (GoDaddy), Jos Purvis (Fastly), Josselin Allemandou (Certigna (DHIMYOTIS)), Jun Okura (Cybertrust Japan), Karolina Ruszczyńska (Asseco Data Systems SA (Certum)), Kiran Tummala (Apple), Li-Chun Chen (Chunghwa Telecom), Lucy Buecking (IdenTrust), Luis Cervantes (SSL.com), Luis Osses (Amazon), Mahua Chaudhuri (Microsoft), Masaru Sakamoto (Cybertrust Japan), Michelle Coon (OATI), Miguel Sanchez (Google), Mrugesh Chandarana (IdenTrust), Nate Smith (GoDaddy), Nome Huang (TrustAsia), Ono Fumiaki (SECOM Trust Systems), Peter Miskovic (Disig), Rebecca Kelly (SSL.com), Rich Smith (DigiCert), Rob White (GoDaddy), Rollin Yu (TrustAsia), Roman Fischer (SwissSign), Ryan Dickson (Google), Sándor Szőke (Microsec), Sandy Balzer (SwissSign), Scott Rea (eMudhra), Sean Huang (TWCA), Stephen Davidson (DigiCert), Tadahiko Ito (SECOM Trust Systems), Thomas Zermeno (SSL.com), Tobias Josefowitz (Opera Software AS), Tsung-Min Kuo (Chunghwa Telecom), Wayne Thayer (Fastly), Zoey Wang (TrustAsia) More posts of the CA/Browser Forum

Technologies

Detected frameworks, languages, and tools.

Hosting & CDN

Hosting provider
Fastly
CDN provider
Fastly
IP address
185.199.110.153
ASN
AS54113 (FASTLY - Fastly, Inc., US)

DNS records

TypeValue
A
  • 185.199.110.153
  • 185.199.108.153
  • 185.199.109.153
  • 185.199.111.153
AAAA
MX
  • mail.cabforum.org
  • smtp.google.com
TXT
  • voflksiio1ltvmoh409fjkklj3
  • cisco-ci-domain-verification=3ccf485703c9f8a975db76eee2dde9f921442f04331a21dd1652506343835f8e
  • google-site-verification=X4Msnv1EwfO5v3RYj8qtGd6CJbbqDRlKVyVxkPw963g
  • 2htip4l64dabivf2272qet0ucu
  • m2cd3b17min0l6mb6jkd580t4s
  • v=spf1 ip4:104.238.65.198/32 ip4:64.202.160.248/32 include:_spf.google.com include:amazonses.com -all
NS
  • ns-56.awsdns-07.com
  • ns-536.awsdns-03.net
  • ns-1172.awsdns-18.org
  • ns-1717.awsdns-22.co.uk
CAA
CNAME
IPv6 supportNo

TLS / SSL certificate

Version
TLS 1.3
Issuer
Let's Encrypt
Subject
cabforum.org
Valid from
Jul 28, 2026
Valid to
Oct 26, 2026
Days until expiry
62
SAN domains
cabforum.org, www.cabforum.org

Security headers

  • Strict-Transport-SecurityMissing
  • Content-Security-PolicyMissing
  • X-Frame-OptionsMissing
  • X-Content-Type-OptionsMissing
  • Referrer-PolicyMissing
  • Permissions-PolicyMissing

Compression: gzip · 0 cookie(s) observed

Content & assets

Headings

H1 1 · H2 1 · H3 0

Links

24 internal · 6 external · 0 broken

Images

1 total · 0 missing alt

Scripts / Styles

2 scripts · 2 stylesheets

JS / CSS size

197 KB · 294 KB

Page size

35.0 KB

Robots.txt & Sitemap

robots.txt
Found
Disallow rules
0
sitemap.xml
Found
URLs in sitemap
1271

SEO issues

  • Title longer than 60 characters
  • Meta description longer than 160 characters
  • No structured data (JSON-LD) found

Accessibility issues

No accessibility issues detected.

Scan details

Requested URL
https://cabforum.org
Final URL
https://cabforum.org
HTTP status
200
HTTP version
HTTP/2
Response time
205 ms
HTML size
35.0 KB
Redirect chain
https://cabforum.org

See something wrong on this report? Request a correction

Frequently asked questions

What technology does cabforum.org use?
cabforum.org is built with Svelte.
Is cabforum.org secure (HTTPS)?
Yes. cabforum.org uses TLS 1.3 with a certificate issued by Let's Encrypt, valid until Oct 26, 2026.
Who hosts cabforum.org?
cabforum.org is hosted on Fastly, behind Fastly CDN.
What is cabforum.org's SEO score?
cabforum.org scored 80/100 for SEO in the latest analysis (great).
What is cabforum.org's overall website score?
cabforum.org has an overall SiteGraph score of 85/100, combining SEO, performance, security, and accessibility.