1.2.1 已翻譯 對應原文版本:2.3.0

版本修訂

跳至原文

Revisions

Ver.BallotDescriptionAdoptedEffective*
1.0.062Version 1.0 of the Baseline Requirements Adopted2011-11-222012-07-01
1.0.171Revised Auditor Qualifications2012-05-082013-01-01
1.0.275Non-critical Name Constraints allowed as exception to RFC 52802012-06-082012-06-08
1.0.378Revised Domain/IP Address Validation, High Risk Requests, and Data Sources2012-06-222012-06-22
1.0.480OCSP responses for non-issued certificates2012-08-022013-08-02
—83Network and Certificate System Security Requirements adopted2013-08-032013-01-01
1.0.588User-assigned country code of XX allowed2012-09-122012-09-12
1.1.0—Published as Version 1.1 with no changes from 1.0.52012-09-142012-09-14
1.1.193Reasons for Revocation and Public Key Parameter checking2012-11-072012-11-07
1.1.296Wildcard certificates and new gTLDs2013-02-202013-02-20
1.1.397Prevention of Unknown Certificate Contents2013-02-212013-02-21
1.1.499Add DSA Keys (BR v.1.1.4)2013-05-032013-05-03
1.1.5102Revision to subject domainComponent language in Section 9.2.32013-05-312013-05-31
1.1.6105Technical Constraints for Subordinate Certificate Authorities2013-07-292013-07-29
1.1.7112Replace Definition of “Internal Server Name” with “Internal Name”2014-04-032014-04-03
1.1.8120Affiliate Authority to Verify Domain2014-06-052014-06-05
1.1.9129Clarification of PSL mentioned in Section 11.1.32014-08-042014-08-04
1.2.0125CAA Records2014-10-142015-04-15
1.2.1118SHA-1 Sunset2014-10-162014-11-16
1.2.2134Application of RFC 5280 to Pre-certificates2014-10-162014-10-16
1.2.3135ETSI Auditor Qualifications2014-10-162014-10-16
1.2.4144Validation Rules for .onion Names2015-02-182015-02-18
1.2.5148Issuer Field Correction2015-04-022015-04-02
1.3.0146Convert Baseline Requirements to RFC 3647 Framework2015-04-162015-04-16
1.3.1151Addition of Optional OIDs for Indicating Level of Validation2015-09-282015-09-28
1.3.2156Amend Sections 1 and 2 of Baseline Requirements2015-12-032016-12-03
1.3.3160Amend Section 4 of Baseline Requirements2016-02-042016-02-04
1.3.4162Sunset of Exceptions2016-03-152016-03-15
1.3.5168Baseline Requirements Corrections (Revised)2016-05-102016-05-10
1.3.6171Updating ETSI Standards in CABF documents2016-07-012016-07-01
1.3.7164Certificate Serial Number Entropy2016-07-082016-09-30
1.3.8169Revised Validation Requirements2016-08-052017-03-01
1.3.9174Reform of Requirements Relating to Conflicts with Local Law2016-08-292016-11-27
1.4.0173Removal of requirement to cease use of public key due to incorrect info2016-07-282016-09-11
1.4.1175Addition of givenName and surname2016-09-072016-09-07
1.4.2181Removal of some validation methods listed in Section 3.2.2.42017-01-072017-01-07
1.4.3187Make CAA Checking Mandatory2017-03-082017-09-08
1.4.4193825-day Certificate Lifetimes2017-03-172018-03-01
1.4.5189Amend Section 6.1.7 of Baseline Requirements2017-04-142017-05-14
1.4.6195CAA Fixup2017-04-172017-05-18
1.4.7196Define “Audit Period”2017-04-172017-05-18
1.4.8199Require commonName in Root and Intermediate Certificates2017-05-092017-06-08
1.4.9204Forbid DTPs from doing Domain/IP Ownership2017-07-112017-08-11
1.5.0212Canonicalise formal name of the Baseline Requirements2017-09-012017-10-01
1.5.1197Effective Date of Ballot 193 Provisions2017-05-012017-06-02
1.5.2190Add Validation Methods with Minor Corrections2017-09-192017-10-19
1.5.3214CAA Discovery CNAME Errata2017-09-272017-10-27
1.5.4215Fix Ballot 190 Errata2017-10-042017-11-05
1.5.5217Sunset RFC 25272017-12-212018-03-09
1.5.6218Remove validation methods #1 and #52018-02-052018-03-09
1.5.7220Minor Cleanups (Spring 2018)2018-03-302018-04-29
1.5.8219Clarify handling of CAA Record Sets with no “issue”/“issuewild” property tag2018-04-102018-05-10
1.5.9223Update BR Section 8.4 for CA audit criteria2018-05-152018-06-14
1.6.0224WhoIs and RDAP2018-05-222018-06-22
1.6.1SC006Revocation Timeline Extension2018-09-142018-10-14
1.6.2SC012Sunset of Underscores in dNSNames2018-11-092018-12-10
1.6.3SC013CAA Contact Property and Associated E-mail Validation Methods2018-12-252019-02-01
1.6.4SC014Updated Phone Validation Methods2019-01-312019-03-16
1.6.4SC015Remove Validation Method Number 92019-02-052019-03-16
1.6.4SC007Update IP Address Validation Methods2019-02-082019-03-16
1.6.5SC016Other Subject Attributes2019-03-152019-04-16
1.6.6SC019Phone Contact with DNS CAA Phone Contact v22019-05-202019-09-09
1.6.7SC023Precertificates2019-11-142019-12-19
1.6.7SC024Fall Cleanup v22019-11-122019-12-19
1.6.8SC025Define New HTTP Domain Validation Methods v22020-01-312020-03-03
1.6.9SC027Version 3 Onion Certificates2020-02-192020-03-27
1.7.0SC029Pandoc-Friendly Markdown Formatting Changes2020-03-202020-05-04
1.7.1SC030Disclosure of Registration / Incorporating Agency2020-07-132020-08-20
1.7.1SC031Browser Alignment2020-07-162020-08-20
1.7.2SC033TLS Using ALPN Method2020-08-142020-09-22
1.7.3SC028Logging and Log Retention2020-09-102020-10-19
1.7.3SC035Cleanups and Clarifications2020-09-092020-10-19
1.7.4SC041Reformat the BRs, EVGs, and NCSSRs2021-02-242021-04-05
1.7.5SC042398-day Re-use Period2021-04-222021-06-02
1.7.6SC044Clarify Acceptable Status Codes2021-04-302021-06-03
1.7.7SC046Sunset the CAA Exception for DNS Operator2021-06-022021-07-12
1.7.8SC045Wildcard Domain Validation2021-06-022021-07-13
1.7.9SC047Sunset subject:organizationalUnitName2021-06-302021-08-16
1.8.0SC048Domain Name and IP Address Encoding2021-07-222021-08-25
1.8.1SC050Remove the requirements of 4.1.12021-11-222021-12-23
1.8.2SC053Sunset for SHA-1 OCSP Signing2022-01-262022-03-04
1.8.3SC051Reduce and Clarify Log and Records Archival Retention Requirements2022-03-012022-04-15
1.8.4SC054Onion Cleanup2022-03-242022-04-23
1.8.5SC0562022 Cleanup2022-10-252022-11-30
1.8.6SC058Require distributionPoint in sharded CRLs2022-11-072022-12-11
1.8.7SC061New CRL entries must have a Revocation Reason Code2023-04-012023-07-15
2.0.0SC062Certificate Profiles Update2023-04-222023-09-15
2.0.1SC063Make OCSP optional, require CRLs, and incentivize automation2023-08-172024-03-15
2.0.2SC0662023 Cleanup2023-11-232024-01-08
2.0.3SC069Clarify router and firewall logging requirements2024-03-132024-04-15
2.0.4SC065Convert EVGs into RFC 3647 format2024-03-152024-05-15
2.0.5SC073Compromised and weak keys2024-05-032024-07-01
2.0.6SC075Pre-sign linting2024-06-282024-08-06
2.0.7SC067Require Multi-Perspective Issuance Corroboration2024-08-022024-09-06
2.0.8SC077Update WebTrust Audit name in Section 8.4 and References2024-09-022024-10-02
2.0.9SC078Subject organizationName alignment for DBA / Assumed Name2024-10-022024-11-08
2.1.0SC076Clarify and improve OCSP requirements2024-09-262024-11-14
2.1.1SC079Allow more than one Certificate Policy in a Cross-Certified Subordinate CA Certificate2024-09-302024-11-14
2.1.2SC080Strengthen WHOIS lookups and Sunset Methods 3.2.2.4.2 and 3.2.2.4.152024-11-072024-12-16
2.1.3SC083Winter 2024-2025 Cleanup Ballot2025-01-232025-02-24
2.1.4SC084DNS Labeled with ACME Account ID Validation Method2025-01-282025-03-01
2.1.5SC081Introduce Schedule of Reducing Validity and Data Reuse Periods2025-04-112025-05-16
2.1.6SC085Require Validation of DNSSEC (when present) for CAA and DCV Lookups2025-06-192025-07-21
2.1.7SC089Mass Revocation Planning2025-07-232025-08-25
2.1.8SC092Sunset Precertificate Signing CAs2025-10-032025-11-04
2.1.9SC088DNS TXT Record with Persistent Value DCV Method2025-10-092025-11-10
2.2.0SC086Sunset the Inclusion of Address and Routing Parameter Area Names2025-11-132025-12-15
2.2.1SC091Sunset 3.2.2.5.3 Reverse Address Lookup Validation,2025-11-132025-12-16
2.2.1SC091new DNS-based validation using Persistent DCV TXT Record for IP addresses2025-11-132025-12-16
2.2.2SC090Gradually sunset remaining email-based, phone-based, and ‘crossover’ validation methods2025-11-202026-01-12
2.2.3SC094DNSSEC exception in email DCV methods2026-01-152026-02-16
2.2.4SC096Carve-out for DNSSEC verification logging requirements2026-01-142026-02-17
2.2.5SC097Sunset all remaining use of SHA-1 signatures in Certificates and CRLs2026-02-242026-02-25
2.2.6SC095Clean-up 20252026-02-272026-03-31
2.2.7SC099Improve Recording of Validation Method2026-04-182026-05-19
2.2.8SC098Process RFC 8657 CAA Parameters2026-05-132026-06-16
2.2.9SC101Clarify Authorization Domain Names2026-07-022026-08-06
2.3.0SC100DNSSEC Clarification and Consolidation2026-08-062026-09-07
版本Ballot 投票案內容採納日期生效日*
1.0.062採納《基本要求》1.0 版2011-11-222012-07-01
1.0.171修訂稽核者(Auditor)資格2012-05-082013-01-01
1.0.275允許將非關鍵(Non-critical)Name Constraints 視為 RFC 5280 之例外2012-06-082012-06-08
1.0.378修訂網域/IP 位址驗證、高風險申請與資料來源2012-06-222012-06-22
1.0.480未簽發憑證之 OCSP 回應2012-08-022013-08-02
—83採納《網路與憑證系統安全要求》(NCSSR)2013-08-032013-01-01
1.0.588允許使用者指定國碼 XX2012-09-122012-09-12
1.1.0—以 1.1 版發布,內容與 1.0.5 相同2012-09-142012-09-14
1.1.193廢止事由與公開金鑰參數檢查2012-11-072012-11-07
1.1.296萬用字元(Wildcard)憑證與新通用頂級網域(New gTLD)2013-02-202013-02-20
1.1.397防止未知的憑證內容2013-02-212013-02-21
1.1.499新增 DSA 金鑰(BR v.1.1.4)2013-05-032013-05-03
1.1.5102修訂第 9.2.3 節的主體網域元件(domainComponent)與語言(language)屬性2013-05-312013-05-31
1.1.6105下屬憑證機構(Subordinate CA)的技術性約束2013-07-292013-07-29
1.1.7112將「Internal Server Name」定義替換為「Internal Name」2014-04-032014-04-03
1.1.8120關係企業(Affiliate)的網域驗證授權2014-06-052014-06-05
1.1.9129第 11.1.3 節所述 PSL 之釐清2014-08-042014-08-04
1.2.0125CAA 紀錄2014-10-142015-04-15
1.2.1118SHA-1 淘汰時程2014-10-162014-11-16
1.2.2134預簽憑證(Pre-certificates)對 RFC 5280 規範之適用2014-10-162014-10-16
1.2.3135ETSI 稽核者資格2014-10-162014-10-16
1.2.4144.onion 網域名稱的驗證規範2015-02-182015-02-18
1.2.5148修正 Issuer 欄位2015-04-022015-04-02
1.3.0146將《基本要求》轉換為 RFC 3647 架構2015-04-162015-04-16
1.3.1151新增選用 OID 以表示驗證等級2015-09-282015-09-28
1.3.2156增修《基本要求》第 1、2 節2015-12-032016-12-03
1.3.3160增修《基本要求》第 4 節2016-02-042016-02-04
1.3.4162例外條款的淘汰時程2016-03-152016-03-15
1.3.5168《基本要求》校正(修訂版)2016-05-102016-05-10
1.3.6171更新 CABF 文件中之 ETSI 標準2016-07-012016-07-01
1.3.7164憑證序號的亂度(資訊熵)2016-07-082016-09-30
1.3.8169修訂驗證要求2016-08-052017-03-01
1.3.9174改革與當地法律衝突時之相關要求2016-08-292016-11-27
1.4.0173移除因資訊錯誤而須停用公鑰之要求2016-07-282016-09-11
1.4.1175於主體欄位增訂 givenName 與 surname 屬性2016-09-072016-09-07
1.4.2181移除第 3.2.2.4 節所列之部分驗證方法2017-01-072017-01-07
1.4.3187強制執行 CAA 檢查2017-03-082017-09-08
1.4.4193憑證有效期為 825 日2017-03-172018-03-01
1.4.5189增修《基本要求》第 6.1.7 節2017-04-142017-05-14
1.4.6195CAA 修補2017-04-172017-05-18
1.4.7196定義「稽核期間」(Audit Period)2017-04-172017-05-18
1.4.8199要求根憑證與中繼憑證須含 commonName 欄位2017-05-092017-06-08
1.4.9204禁止受委任第三方(DTP)執行網域/IP 所有權驗證2017-07-112017-08-11
1.5.0212規範《基本要求》正式名稱2017-09-012017-10-01
1.5.1197Ballot 193 條文之生效日2017-05-012017-06-02
1.5.2190新增驗證方法與若干小幅修正2017-09-192017-10-19
1.5.3214CAA 檢索 CNAME 規則之內容勘誤2017-09-272017-10-27
1.5.4215修正 Ballot 190 文字誤植2017-10-042017-11-05
1.5.5217RFC 2527 淘汰時程2017-12-212018-03-09
1.5.6218移除驗證方法 #1 與 #52018-02-052018-03-09
1.5.7220小幅整理(2018 春)2018-03-302018-04-29
1.5.8219明定未含 “issue”/“issuewild” 屬性標籤之 CAA 紀錄集(Record Set)處理方式2018-04-102018-05-10
1.5.9223更新《基本要求》第 8.4 節之 CA 稽核準則2018-05-152018-06-14
1.6.0224WhoIs 與 RDAP2018-05-222018-06-22
1.6.1SC006憑證廢止時限之延長2018-09-142018-10-14
1.6.2SC012於 dNSName 內容值使用底線字元(Underscore)之淘汰時程2018-11-092018-12-10
1.6.3SC013CAA Contact 屬性及相關電子郵件驗證方法2018-12-252019-02-01
1.6.4SC014更新電話驗證方法2019-01-312019-03-16
1.6.4SC015移除第 9 號驗證方法2019-02-052019-03-16
1.6.4SC007更新 IP 位址驗證方法2019-02-082019-03-16
1.6.5SC016其他 Subject 屬性2019-03-152019-04-16
1.6.6SC019透過 DNS CAA Phone Contact v2 之電話聯絡2019-05-202019-09-09
1.6.7SC023預簽憑證(Precertificates)2019-11-142019-12-19
1.6.7SC024秋季整理 v22019-11-122019-12-19
1.6.8SC025定義新 HTTP 網域驗證方法 v22020-01-312020-03-03
1.6.9SC027第 3 版 Onion 憑證2020-02-192020-03-27
1.7.0SC029調整 Markdown 格式相容 Pandoc2020-03-202020-05-04
1.7.1SC030揭露公司註冊/設立登記機構2020-07-132020-08-20
1.7.1SC031與瀏覽器安全政策同步(Browser Alignment)2020-07-162020-08-20
1.7.2SC033TLS 驗證使用 ALPN 方法2020-08-142020-09-22
1.7.3SC028記錄與紀錄保留2020-09-102020-10-19
1.7.3SC035整理與釐清2020-09-092020-10-19
1.7.4SC041重新編排《基本要求(BRs)》、《EV 指引(EVGs)》與《網路與憑證系統安全要求(NCSSR)》2021-02-242021-04-05
1.7.5SC042可重複使用(Re-use)已驗證資料之期限降為 398 日2021-04-222021-06-02
1.7.6SC044明定可接受的狀態碼2021-04-302021-06-03
1.7.7SC046DNS 業者的 CAA 例外條款之淘汰時程2021-06-022021-07-12
1.7.8SC045萬用字元網域驗證2021-06-022021-07-13
1.7.9SC047subject:organizationalUnitName 淘汰時程2021-06-302021-08-16
1.8.0SC048網域名稱與 IP 位址的表示格式規範2021-07-222021-08-25
1.8.1SC050移除第 4.1.1 節之要求2021-11-222021-12-23
1.8.2SC053SHA-1 OCSP 簽章之淘汰時程2022-01-262022-03-04
1.8.3SC051縮減並明定紀錄與紀錄歸檔保留之要求2022-03-012022-04-15
1.8.4SC054Onion 整理2022-03-242022-04-23
1.8.5SC0562022 整理2022-10-252022-11-30
1.8.6SC058要求分片式(Sharded)CRL 須含 distributionPoint 欄位2022-11-072022-12-11
1.8.7SC061新 CRL 記錄必須有廢止原因代碼(Revocation Reason Code)2023-04-012023-07-15
2.0.0SC062更新憑證剖繪(Certificate Profiles)2023-04-222023-09-15
2.0.1SC063OCSP 改為選用、強制 CRL,並鼓勵自動化2023-08-172024-03-15
2.0.2SC0662023 整理2023-11-232024-01-08
2.0.3SC069明定路由器與防火牆的記錄要求2024-03-132024-04-15
2.0.4SC065將《EV 指引(EVGs)》轉為 RFC 3647 格式2024-03-152024-05-15
2.0.5SC073金鑰遭破解與弱金鑰2024-05-032024-07-01
2.0.6SC075簽章前的 Linting 檢查(Pre-sign linting)2024-06-282024-08-06
2.0.7SC067強制實施多視角簽發佐證(MPIC)2024-08-022024-09-06
2.0.8SC077更新第 8.4 節與參考資料內容的 WebTrust 稽核名稱2024-09-022024-10-02
2.0.9SC078Subject organizationName 欄位比照 EV 憑證及 S/MIME 顯示 DBA/商業名稱(Assumed Name)2024-10-022024-11-08
2.1.0SC076明定並改善 OCSP 要求2024-09-262024-11-14
2.1.1SC079允許交互認證之下屬憑證機構憑證(Cross-Certified Subordinate CA Certificate)包含一個以上之憑證政策2024-09-302024-11-14
2.1.2SC080強化 WHOIS 查詢並淘汰第 3.2.2.4.2 節、第 3.2.2.4.15 節驗證方法2024-11-072024-12-16
2.1.3SC0832024-2025 冬季整理 Ballot2025-01-232025-02-24
2.1.4SC084標記 ACME Account ID 的 DNS 驗證方法2025-01-282025-03-01
2.1.5SC081導入縮短憑證有效期與可重複使用已驗證資料之期限的時程表2025-04-112025-05-16
2.1.6SC085查詢 CAA 與 DCV 時,要求驗證 DNSSEC(當其存在時)2025-06-192025-07-21
2.1.7SC089大規模廢止(Mass Revocation)規劃2025-07-232025-08-25
2.1.8SC092淘汰預簽憑證簽章憑證機構(Precertificate Signing CA)2025-10-032025-11-04
2.1.9SC088基於持久性紀錄值之 DNS TXT 紀錄的 DCV 方法2025-10-092025-11-10
2.2.0SC086終止 Address and Routing Parameter Area (.arpa) 網域名稱的憑證申請2025-11-132025-12-15
2.2.1SC091淘汰第 3.2.2.5.3 節反向位址查詢驗證,2025-11-132025-12-16
2.2.1SC091新增使用持久性 DCV TXT 紀錄之 IP 位址 DNS 驗證方法2025-11-132025-12-16
2.2.2SC090逐步淘汰剩餘的電子郵件、電話驗證與「crossover」驗證方法2025-11-202026-01-12
2.2.3SC094電子郵件 DCV 方法之 DNSSEC 豁免2026-01-152026-02-16
2.2.4SC096豁免 DNSSEC 驗證記錄的要求2026-01-142026-02-17
2.2.5SC097淘汰所有還在使用 SHA-1 簽章的憑證與 CRL2026-02-242026-02-25
2.2.6SC0952025 整理2026-02-272026-03-31
2.2.7SC099改進驗證方法的記錄方式2026-04-182026-05-19
2.2.8SC098處理 RFC 8657 的 CAA 參數2026-05-132026-06-16
2.2.9SC101明定經授權網域名稱(ADN)2026-07-022026-08-06
2.3.0SC100DNSSEC 之釐清與整合2026-08-062026-09-07

* Effective Date and Additionally Relevant Compliance Date(s)

* 生效日期(Effective Date)及其他相關實施日期