1.2.1 已翻譯 對應原文版本:2.3.0
版本修訂
Revisions
Ver. Ballot Description Adopted Effective* 1.0.0 62 Version 1.0 of the Baseline Requirements Adopted 2011-11-22 2012-07-01 1.0.1 71 Revised Auditor Qualifications 2012-05-08 2013-01-01 1.0.2 75 Non-critical Name Constraints allowed as exception to RFC 5280 2012-06-08 2012-06-08 1.0.3 78 Revised Domain/IP Address Validation, High Risk Requests, and Data Sources 2012-06-22 2012-06-22 1.0.4 80 OCSP responses for non-issued certificates 2012-08-02 2013-08-02 — 83 Network and Certificate System Security Requirements adopted 2013-08-03 2013-01-01 1.0.5 88 User-assigned country code of XX allowed 2012-09-12 2012-09-12 1.1.0 — Published as Version 1.1 with no changes from 1.0.5 2012-09-14 2012-09-14 1.1.1 93 Reasons for Revocation and Public Key Parameter checking 2012-11-07 2012-11-07 1.1.2 96 Wildcard certificates and new gTLDs 2013-02-20 2013-02-20 1.1.3 97 Prevention of Unknown Certificate Contents 2013-02-21 2013-02-21 1.1.4 99 Add DSA Keys (BR v.1.1.4) 2013-05-03 2013-05-03 1.1.5 102 Revision to subject domainComponent language in Section 9.2.3 2013-05-31 2013-05-31 1.1.6 105 Technical Constraints for Subordinate Certificate Authorities 2013-07-29 2013-07-29 1.1.7 112 Replace Definition of “Internal Server Name” with “Internal Name” 2014-04-03 2014-04-03 1.1.8 120 Affiliate Authority to Verify Domain 2014-06-05 2014-06-05 1.1.9 129 Clarification of PSL mentioned in Section 11.1.3 2014-08-04 2014-08-04 1.2.0 125 CAA Records 2014-10-14 2015-04-15 1.2.1 118 SHA-1 Sunset 2014-10-16 2014-11-16 1.2.2 134 Application of RFC 5280 to Pre-certificates 2014-10-16 2014-10-16 1.2.3 135 ETSI Auditor Qualifications 2014-10-16 2014-10-16 1.2.4 144 Validation Rules for .onion Names 2015-02-18 2015-02-18 1.2.5 148 Issuer Field Correction 2015-04-02 2015-04-02 1.3.0 146 Convert Baseline Requirements to RFC 3647 Framework 2015-04-16 2015-04-16 1.3.1 151 Addition of Optional OIDs for Indicating Level of Validation 2015-09-28 2015-09-28 1.3.2 156 Amend Sections 1 and 2 of Baseline Requirements 2015-12-03 2016-12-03 1.3.3 160 Amend Section 4 of Baseline Requirements 2016-02-04 2016-02-04 1.3.4 162 Sunset of Exceptions 2016-03-15 2016-03-15 1.3.5 168 Baseline Requirements Corrections (Revised) 2016-05-10 2016-05-10 1.3.6 171 Updating ETSI Standards in CABF documents 2016-07-01 2016-07-01 1.3.7 164 Certificate Serial Number Entropy 2016-07-08 2016-09-30 1.3.8 169 Revised Validation Requirements 2016-08-05 2017-03-01 1.3.9 174 Reform of Requirements Relating to Conflicts with Local Law 2016-08-29 2016-11-27 1.4.0 173 Removal of requirement to cease use of public key due to incorrect info 2016-07-28 2016-09-11 1.4.1 175 Addition of givenName and surname 2016-09-07 2016-09-07 1.4.2 181 Removal of some validation methods listed in Section 3.2.2.4 2017-01-07 2017-01-07 1.4.3 187 Make CAA Checking Mandatory 2017-03-08 2017-09-08 1.4.4 193 825-day Certificate Lifetimes 2017-03-17 2018-03-01 1.4.5 189 Amend Section 6.1.7 of Baseline Requirements 2017-04-14 2017-05-14 1.4.6 195 CAA Fixup 2017-04-17 2017-05-18 1.4.7 196 Define “Audit Period” 2017-04-17 2017-05-18 1.4.8 199 Require commonName in Root and Intermediate Certificates 2017-05-09 2017-06-08 1.4.9 204 Forbid DTPs from doing Domain/IP Ownership 2017-07-11 2017-08-11 1.5.0 212 Canonicalise formal name of the Baseline Requirements 2017-09-01 2017-10-01 1.5.1 197 Effective Date of Ballot 193 Provisions 2017-05-01 2017-06-02 1.5.2 190 Add Validation Methods with Minor Corrections 2017-09-19 2017-10-19 1.5.3 214 CAA Discovery CNAME Errata 2017-09-27 2017-10-27 1.5.4 215 Fix Ballot 190 Errata 2017-10-04 2017-11-05 1.5.5 217 Sunset RFC 2527 2017-12-21 2018-03-09 1.5.6 218 Remove validation methods #1 and #5 2018-02-05 2018-03-09 1.5.7 220 Minor Cleanups (Spring 2018) 2018-03-30 2018-04-29 1.5.8 219 Clarify handling of CAA Record Sets with no “issue”/“issuewild” property tag 2018-04-10 2018-05-10 1.5.9 223 Update BR Section 8.4 for CA audit criteria 2018-05-15 2018-06-14 1.6.0 224 WhoIs and RDAP 2018-05-22 2018-06-22 1.6.1 SC006 Revocation Timeline Extension 2018-09-14 2018-10-14 1.6.2 SC012 Sunset of Underscores in dNSNames 2018-11-09 2018-12-10 1.6.3 SC013 CAA Contact Property and Associated E-mail Validation Methods 2018-12-25 2019-02-01 1.6.4 SC014 Updated Phone Validation Methods 2019-01-31 2019-03-16 1.6.4 SC015 Remove Validation Method Number 9 2019-02-05 2019-03-16 1.6.4 SC007 Update IP Address Validation Methods 2019-02-08 2019-03-16 1.6.5 SC016 Other Subject Attributes 2019-03-15 2019-04-16 1.6.6 SC019 Phone Contact with DNS CAA Phone Contact v2 2019-05-20 2019-09-09 1.6.7 SC023 Precertificates 2019-11-14 2019-12-19 1.6.7 SC024 Fall Cleanup v2 2019-11-12 2019-12-19 1.6.8 SC025 Define New HTTP Domain Validation Methods v2 2020-01-31 2020-03-03 1.6.9 SC027 Version 3 Onion Certificates 2020-02-19 2020-03-27 1.7.0 SC029 Pandoc-Friendly Markdown Formatting Changes 2020-03-20 2020-05-04 1.7.1 SC030 Disclosure of Registration / Incorporating Agency 2020-07-13 2020-08-20 1.7.1 SC031 Browser Alignment 2020-07-16 2020-08-20 1.7.2 SC033 TLS Using ALPN Method 2020-08-14 2020-09-22 1.7.3 SC028 Logging and Log Retention 2020-09-10 2020-10-19 1.7.3 SC035 Cleanups and Clarifications 2020-09-09 2020-10-19 1.7.4 SC041 Reformat the BRs, EVGs, and NCSSRs 2021-02-24 2021-04-05 1.7.5 SC042 398-day Re-use Period 2021-04-22 2021-06-02 1.7.6 SC044 Clarify Acceptable Status Codes 2021-04-30 2021-06-03 1.7.7 SC046 Sunset the CAA Exception for DNS Operator 2021-06-02 2021-07-12 1.7.8 SC045 Wildcard Domain Validation 2021-06-02 2021-07-13 1.7.9 SC047 Sunset subject:organizationalUnitName 2021-06-30 2021-08-16 1.8.0 SC048 Domain Name and IP Address Encoding 2021-07-22 2021-08-25 1.8.1 SC050 Remove the requirements of 4.1.1 2021-11-22 2021-12-23 1.8.2 SC053 Sunset for SHA-1 OCSP Signing 2022-01-26 2022-03-04 1.8.3 SC051 Reduce and Clarify Log and Records Archival Retention Requirements 2022-03-01 2022-04-15 1.8.4 SC054 Onion Cleanup 2022-03-24 2022-04-23 1.8.5 SC056 2022 Cleanup 2022-10-25 2022-11-30 1.8.6 SC058 Require distributionPoint in sharded CRLs 2022-11-07 2022-12-11 1.8.7 SC061 New CRL entries must have a Revocation Reason Code 2023-04-01 2023-07-15 2.0.0 SC062 Certificate Profiles Update 2023-04-22 2023-09-15 2.0.1 SC063 Make OCSP optional, require CRLs, and incentivize automation 2023-08-17 2024-03-15 2.0.2 SC066 2023 Cleanup 2023-11-23 2024-01-08 2.0.3 SC069 Clarify router and firewall logging requirements 2024-03-13 2024-04-15 2.0.4 SC065 Convert EVGs into RFC 3647 format 2024-03-15 2024-05-15 2.0.5 SC073 Compromised and weak keys 2024-05-03 2024-07-01 2.0.6 SC075 Pre-sign linting 2024-06-28 2024-08-06 2.0.7 SC067 Require Multi-Perspective Issuance Corroboration 2024-08-02 2024-09-06 2.0.8 SC077 Update WebTrust Audit name in Section 8.4 and References 2024-09-02 2024-10-02 2.0.9 SC078 Subject organizationName alignment for DBA / Assumed Name 2024-10-02 2024-11-08 2.1.0 SC076 Clarify and improve OCSP requirements 2024-09-26 2024-11-14 2.1.1 SC079 Allow more than one Certificate Policy in a Cross-Certified Subordinate CA Certificate 2024-09-30 2024-11-14 2.1.2 SC080 Strengthen WHOIS lookups and Sunset Methods 3.2.2.4.2 and 3.2.2.4.15 2024-11-07 2024-12-16 2.1.3 SC083 Winter 2024-2025 Cleanup Ballot 2025-01-23 2025-02-24 2.1.4 SC084 DNS Labeled with ACME Account ID Validation Method 2025-01-28 2025-03-01 2.1.5 SC081 Introduce Schedule of Reducing Validity and Data Reuse Periods 2025-04-11 2025-05-16 2.1.6 SC085 Require Validation of DNSSEC (when present) for CAA and DCV Lookups 2025-06-19 2025-07-21 2.1.7 SC089 Mass Revocation Planning 2025-07-23 2025-08-25 2.1.8 SC092 Sunset Precertificate Signing CAs 2025-10-03 2025-11-04 2.1.9 SC088 DNS TXT Record with Persistent Value DCV Method 2025-10-09 2025-11-10 2.2.0 SC086 Sunset the Inclusion of Address and Routing Parameter Area Names 2025-11-13 2025-12-15 2.2.1 SC091 Sunset 3.2.2.5.3 Reverse Address Lookup Validation, 2025-11-13 2025-12-16 2.2.1 SC091 new DNS-based validation using Persistent DCV TXT Record for IP addresses 2025-11-13 2025-12-16 2.2.2 SC090 Gradually sunset remaining email-based, phone-based, and ‘crossover’ validation methods 2025-11-20 2026-01-12 2.2.3 SC094 DNSSEC exception in email DCV methods 2026-01-15 2026-02-16 2.2.4 SC096 Carve-out for DNSSEC verification logging requirements 2026-01-14 2026-02-17 2.2.5 SC097 Sunset all remaining use of SHA-1 signatures in Certificates and CRLs 2026-02-24 2026-02-25 2.2.6 SC095 Clean-up 2025 2026-02-27 2026-03-31 2.2.7 SC099 Improve Recording of Validation Method 2026-04-18 2026-05-19 2.2.8 SC098 Process RFC 8657 CAA Parameters 2026-05-13 2026-06-16 2.2.9 SC101 Clarify Authorization Domain Names 2026-07-02 2026-08-06 2.3.0 SC100 DNSSEC Clarification and Consolidation 2026-08-06 2026-09-07
| 版本 | Ballot 投票案 | 內容 | 採納日期 | 生效日* |
|---|---|---|---|---|
| 1.0.0 | 62 | 採納《基本要求》1.0 版 | 2011-11-22 | 2012-07-01 |
| 1.0.1 | 71 | 修訂稽核者(Auditor)資格 | 2012-05-08 | 2013-01-01 |
| 1.0.2 | 75 | 允許將非關鍵(Non-critical)Name Constraints 視為 RFC 5280 之例外 | 2012-06-08 | 2012-06-08 |
| 1.0.3 | 78 | 修訂網域/IP 位址驗證、高風險申請與資料來源 | 2012-06-22 | 2012-06-22 |
| 1.0.4 | 80 | 未簽發憑證之 OCSP 回應 | 2012-08-02 | 2013-08-02 |
| — | 83 | 採納《網路與憑證系統安全要求》(NCSSR) | 2013-08-03 | 2013-01-01 |
| 1.0.5 | 88 | 允許使用者指定國碼 XX | 2012-09-12 | 2012-09-12 |
| 1.1.0 | — | 以 1.1 版發布,內容與 1.0.5 相同 | 2012-09-14 | 2012-09-14 |
| 1.1.1 | 93 | 廢止事由與公開金鑰參數檢查 | 2012-11-07 | 2012-11-07 |
| 1.1.2 | 96 | 萬用字元(Wildcard)憑證與新通用頂級網域(New gTLD) | 2013-02-20 | 2013-02-20 |
| 1.1.3 | 97 | 防止未知的憑證內容 | 2013-02-21 | 2013-02-21 |
| 1.1.4 | 99 | 新增 DSA 金鑰(BR v.1.1.4) | 2013-05-03 | 2013-05-03 |
| 1.1.5 | 102 | 修訂第 9.2.3 節的主體網域元件(domainComponent)與語言(language)屬性 | 2013-05-31 | 2013-05-31 |
| 1.1.6 | 105 | 下屬憑證機構(Subordinate CA)的技術性約束 | 2013-07-29 | 2013-07-29 |
| 1.1.7 | 112 | 將「Internal Server Name」定義替換為「Internal Name」 | 2014-04-03 | 2014-04-03 |
| 1.1.8 | 120 | 關係企業(Affiliate)的網域驗證授權 | 2014-06-05 | 2014-06-05 |
| 1.1.9 | 129 | 第 11.1.3 節所述 PSL 之釐清 | 2014-08-04 | 2014-08-04 |
| 1.2.0 | 125 | CAA 紀錄 | 2014-10-14 | 2015-04-15 |
| 1.2.1 | 118 | SHA-1 淘汰時程 | 2014-10-16 | 2014-11-16 |
| 1.2.2 | 134 | 預簽憑證(Pre-certificates)對 RFC 5280 規範之適用 | 2014-10-16 | 2014-10-16 |
| 1.2.3 | 135 | ETSI 稽核者資格 | 2014-10-16 | 2014-10-16 |
| 1.2.4 | 144 | .onion 網域名稱的驗證規範 | 2015-02-18 | 2015-02-18 |
| 1.2.5 | 148 | 修正 Issuer 欄位 | 2015-04-02 | 2015-04-02 |
| 1.3.0 | 146 | 將《基本要求》轉換為 RFC 3647 架構 | 2015-04-16 | 2015-04-16 |
| 1.3.1 | 151 | 新增選用 OID 以表示驗證等級 | 2015-09-28 | 2015-09-28 |
| 1.3.2 | 156 | 增修《基本要求》第 1、2 節 | 2015-12-03 | 2016-12-03 |
| 1.3.3 | 160 | 增修《基本要求》第 4 節 | 2016-02-04 | 2016-02-04 |
| 1.3.4 | 162 | 例外條款的淘汰時程 | 2016-03-15 | 2016-03-15 |
| 1.3.5 | 168 | 《基本要求》校正(修訂版) | 2016-05-10 | 2016-05-10 |
| 1.3.6 | 171 | 更新 CABF 文件中之 ETSI 標準 | 2016-07-01 | 2016-07-01 |
| 1.3.7 | 164 | 憑證序號的亂度(資訊熵) | 2016-07-08 | 2016-09-30 |
| 1.3.8 | 169 | 修訂驗證要求 | 2016-08-05 | 2017-03-01 |
| 1.3.9 | 174 | 改革與當地法律衝突時之相關要求 | 2016-08-29 | 2016-11-27 |
| 1.4.0 | 173 | 移除因資訊錯誤而須停用公鑰之要求 | 2016-07-28 | 2016-09-11 |
| 1.4.1 | 175 | 於主體欄位增訂 givenName 與 surname 屬性 | 2016-09-07 | 2016-09-07 |
| 1.4.2 | 181 | 移除第 3.2.2.4 節所列之部分驗證方法 | 2017-01-07 | 2017-01-07 |
| 1.4.3 | 187 | 強制執行 CAA 檢查 | 2017-03-08 | 2017-09-08 |
| 1.4.4 | 193 | 憑證有效期為 825 日 | 2017-03-17 | 2018-03-01 |
| 1.4.5 | 189 | 增修《基本要求》第 6.1.7 節 | 2017-04-14 | 2017-05-14 |
| 1.4.6 | 195 | CAA 修補 | 2017-04-17 | 2017-05-18 |
| 1.4.7 | 196 | 定義「稽核期間」(Audit Period) | 2017-04-17 | 2017-05-18 |
| 1.4.8 | 199 | 要求根憑證與中繼憑證須含 commonName 欄位 | 2017-05-09 | 2017-06-08 |
| 1.4.9 | 204 | 禁止受委任第三方(DTP)執行網域/IP 所有權驗證 | 2017-07-11 | 2017-08-11 |
| 1.5.0 | 212 | 規範《基本要求》正式名稱 | 2017-09-01 | 2017-10-01 |
| 1.5.1 | 197 | Ballot 193 條文之生效日 | 2017-05-01 | 2017-06-02 |
| 1.5.2 | 190 | 新增驗證方法與若干小幅修正 | 2017-09-19 | 2017-10-19 |
| 1.5.3 | 214 | CAA 檢索 CNAME 規則之內容勘誤 | 2017-09-27 | 2017-10-27 |
| 1.5.4 | 215 | 修正 Ballot 190 文字誤植 | 2017-10-04 | 2017-11-05 |
| 1.5.5 | 217 | RFC 2527 淘汰時程 | 2017-12-21 | 2018-03-09 |
| 1.5.6 | 218 | 移除驗證方法 #1 與 #5 | 2018-02-05 | 2018-03-09 |
| 1.5.7 | 220 | 小幅整理(2018 春) | 2018-03-30 | 2018-04-29 |
| 1.5.8 | 219 | 明定未含 “issue”/“issuewild” 屬性標籤之 CAA 紀錄集(Record Set)處理方式 | 2018-04-10 | 2018-05-10 |
| 1.5.9 | 223 | 更新《基本要求》第 8.4 節之 CA 稽核準則 | 2018-05-15 | 2018-06-14 |
| 1.6.0 | 224 | WhoIs 與 RDAP | 2018-05-22 | 2018-06-22 |
| 1.6.1 | SC006 | 憑證廢止時限之延長 | 2018-09-14 | 2018-10-14 |
| 1.6.2 | SC012 | 於 dNSName 內容值使用底線字元(Underscore)之淘汰時程 | 2018-11-09 | 2018-12-10 |
| 1.6.3 | SC013 | CAA Contact 屬性及相關電子郵件驗證方法 | 2018-12-25 | 2019-02-01 |
| 1.6.4 | SC014 | 更新電話驗證方法 | 2019-01-31 | 2019-03-16 |
| 1.6.4 | SC015 | 移除第 9 號驗證方法 | 2019-02-05 | 2019-03-16 |
| 1.6.4 | SC007 | 更新 IP 位址驗證方法 | 2019-02-08 | 2019-03-16 |
| 1.6.5 | SC016 | 其他 Subject 屬性 | 2019-03-15 | 2019-04-16 |
| 1.6.6 | SC019 | 透過 DNS CAA Phone Contact v2 之電話聯絡 | 2019-05-20 | 2019-09-09 |
| 1.6.7 | SC023 | 預簽憑證(Precertificates) | 2019-11-14 | 2019-12-19 |
| 1.6.7 | SC024 | 秋季整理 v2 | 2019-11-12 | 2019-12-19 |
| 1.6.8 | SC025 | 定義新 HTTP 網域驗證方法 v2 | 2020-01-31 | 2020-03-03 |
| 1.6.9 | SC027 | 第 3 版 Onion 憑證 | 2020-02-19 | 2020-03-27 |
| 1.7.0 | SC029 | 調整 Markdown 格式相容 Pandoc | 2020-03-20 | 2020-05-04 |
| 1.7.1 | SC030 | 揭露公司註冊/設立登記機構 | 2020-07-13 | 2020-08-20 |
| 1.7.1 | SC031 | 與瀏覽器安全政策同步(Browser Alignment) | 2020-07-16 | 2020-08-20 |
| 1.7.2 | SC033 | TLS 驗證使用 ALPN 方法 | 2020-08-14 | 2020-09-22 |
| 1.7.3 | SC028 | 記錄與紀錄保留 | 2020-09-10 | 2020-10-19 |
| 1.7.3 | SC035 | 整理與釐清 | 2020-09-09 | 2020-10-19 |
| 1.7.4 | SC041 | 重新編排《基本要求(BRs)》、《EV 指引(EVGs)》與《網路與憑證系統安全要求(NCSSR)》 | 2021-02-24 | 2021-04-05 |
| 1.7.5 | SC042 | 可重複使用(Re-use)已驗證資料之期限降為 398 日 | 2021-04-22 | 2021-06-02 |
| 1.7.6 | SC044 | 明定可接受的狀態碼 | 2021-04-30 | 2021-06-03 |
| 1.7.7 | SC046 | DNS 業者的 CAA 例外條款之淘汰時程 | 2021-06-02 | 2021-07-12 |
| 1.7.8 | SC045 | 萬用字元網域驗證 | 2021-06-02 | 2021-07-13 |
| 1.7.9 | SC047 | subject:organizationalUnitName 淘汰時程 | 2021-06-30 | 2021-08-16 |
| 1.8.0 | SC048 | 網域名稱與 IP 位址的表示格式規範 | 2021-07-22 | 2021-08-25 |
| 1.8.1 | SC050 | 移除第 4.1.1 節之要求 | 2021-11-22 | 2021-12-23 |
| 1.8.2 | SC053 | SHA-1 OCSP 簽章之淘汰時程 | 2022-01-26 | 2022-03-04 |
| 1.8.3 | SC051 | 縮減並明定紀錄與紀錄歸檔保留之要求 | 2022-03-01 | 2022-04-15 |
| 1.8.4 | SC054 | Onion 整理 | 2022-03-24 | 2022-04-23 |
| 1.8.5 | SC056 | 2022 整理 | 2022-10-25 | 2022-11-30 |
| 1.8.6 | SC058 | 要求分片式(Sharded)CRL 須含 distributionPoint 欄位 | 2022-11-07 | 2022-12-11 |
| 1.8.7 | SC061 | 新 CRL 記錄必須有廢止原因代碼(Revocation Reason Code) | 2023-04-01 | 2023-07-15 |
| 2.0.0 | SC062 | 更新憑證剖繪(Certificate Profiles) | 2023-04-22 | 2023-09-15 |
| 2.0.1 | SC063 | OCSP 改為選用、強制 CRL,並鼓勵自動化 | 2023-08-17 | 2024-03-15 |
| 2.0.2 | SC066 | 2023 整理 | 2023-11-23 | 2024-01-08 |
| 2.0.3 | SC069 | 明定路由器與防火牆的記錄要求 | 2024-03-13 | 2024-04-15 |
| 2.0.4 | SC065 | 將《EV 指引(EVGs)》轉為 RFC 3647 格式 | 2024-03-15 | 2024-05-15 |
| 2.0.5 | SC073 | 金鑰遭破解與弱金鑰 | 2024-05-03 | 2024-07-01 |
| 2.0.6 | SC075 | 簽章前的 Linting 檢查(Pre-sign linting) | 2024-06-28 | 2024-08-06 |
| 2.0.7 | SC067 | 強制實施多視角簽發佐證(MPIC) | 2024-08-02 | 2024-09-06 |
| 2.0.8 | SC077 | 更新第 8.4 節與參考資料內容的 WebTrust 稽核名稱 | 2024-09-02 | 2024-10-02 |
| 2.0.9 | SC078 | Subject organizationName 欄位比照 EV 憑證及 S/MIME 顯示 DBA/商業名稱(Assumed Name) | 2024-10-02 | 2024-11-08 |
| 2.1.0 | SC076 | 明定並改善 OCSP 要求 | 2024-09-26 | 2024-11-14 |
| 2.1.1 | SC079 | 允許交互認證之下屬憑證機構憑證(Cross-Certified Subordinate CA Certificate)包含一個以上之憑證政策 | 2024-09-30 | 2024-11-14 |
| 2.1.2 | SC080 | 強化 WHOIS 查詢並淘汰第 3.2.2.4.2 節、第 3.2.2.4.15 節驗證方法 | 2024-11-07 | 2024-12-16 |
| 2.1.3 | SC083 | 2024-2025 冬季整理 Ballot | 2025-01-23 | 2025-02-24 |
| 2.1.4 | SC084 | 標記 ACME Account ID 的 DNS 驗證方法 | 2025-01-28 | 2025-03-01 |
| 2.1.5 | SC081 | 導入縮短憑證有效期與可重複使用已驗證資料之期限的時程表 | 2025-04-11 | 2025-05-16 |
| 2.1.6 | SC085 | 查詢 CAA 與 DCV 時,要求驗證 DNSSEC(當其存在時) | 2025-06-19 | 2025-07-21 |
| 2.1.7 | SC089 | 大規模廢止(Mass Revocation)規劃 | 2025-07-23 | 2025-08-25 |
| 2.1.8 | SC092 | 淘汰預簽憑證簽章憑證機構(Precertificate Signing CA) | 2025-10-03 | 2025-11-04 |
| 2.1.9 | SC088 | 基於持久性紀錄值之 DNS TXT 紀錄的 DCV 方法 | 2025-10-09 | 2025-11-10 |
| 2.2.0 | SC086 | 終止 Address and Routing Parameter Area (.arpa) 網域名稱的憑證申請 | 2025-11-13 | 2025-12-15 |
| 2.2.1 | SC091 | 淘汰第 3.2.2.5.3 節反向位址查詢驗證, | 2025-11-13 | 2025-12-16 |
| 2.2.1 | SC091 | 新增使用持久性 DCV TXT 紀錄之 IP 位址 DNS 驗證方法 | 2025-11-13 | 2025-12-16 |
| 2.2.2 | SC090 | 逐步淘汰剩餘的電子郵件、電話驗證與「crossover」驗證方法 | 2025-11-20 | 2026-01-12 |
| 2.2.3 | SC094 | 電子郵件 DCV 方法之 DNSSEC 豁免 | 2026-01-15 | 2026-02-16 |
| 2.2.4 | SC096 | 豁免 DNSSEC 驗證記錄的要求 | 2026-01-14 | 2026-02-17 |
| 2.2.5 | SC097 | 淘汰所有還在使用 SHA-1 簽章的憑證與 CRL | 2026-02-24 | 2026-02-25 |
| 2.2.6 | SC095 | 2025 整理 | 2026-02-27 | 2026-03-31 |
| 2.2.7 | SC099 | 改進驗證方法的記錄方式 | 2026-04-18 | 2026-05-19 |
| 2.2.8 | SC098 | 處理 RFC 8657 的 CAA 參數 | 2026-05-13 | 2026-06-16 |
| 2.2.9 | SC101 | 明定經授權網域名稱(ADN) | 2026-07-02 | 2026-08-06 |
| 2.3.0 | SC100 | DNSSEC 之釐清與整合 | 2026-08-06 | 2026-09-07 |
* Effective Date and Additionally Relevant Compliance Date(s)
* 生效日期(Effective Date)及其他相關實施日期