Skip to content
Surf Wiki
Save to docs
general/internet-security

From Surf Wiki (app.surf) — the open knowledge base

Certificate Authority Security Council

Organization


Summary

Organization

FieldValue
nameCertificate Authority Security Council
abbreviationCASC
imageCA_Security_Council.png
typeIndustry Advocacy Organization
formationFebruary 2013
purposeExploration and promotion of best practices that advance trusted SSL deployment and CA operations as well as the security of the Internet in general
region_servedWorldwide
membership7 publicly trusted PKI authorities
website

|}}

The Certificate Authority Security Council (CASC) is a multi-vendor industry advocacy group created to conduct research, promote Internet security standards and educate the public on Internet security issues.

History

The group was founded in February 2013 with the seven largest certificate authorities, issuers of SSL certificates — Comodo, Symantec, Trend Micro, DigiCert, Entrust, GlobalSign and GoDaddy. DigiCert withdrew from the group June 15, 2018.

Objectives

The CASC supports the efforts of the CA/Browser Forum and other standards-setting bodies. They support the development of enhancements that improve the Secure Sockets Layer (SSL) and the operations of the certificate authorities (CA).

According to Robin Alden, CTO of Comodo and member of the Council, the CASC will serve as a united front for all of the CAs involved: "While not a standards-setting organization, we’re committed to supplementing standards-setting organizations by providing education, research, and advocacy on the best practices and use of SSL."

Membership requirements

The CASC limits membership to SSL certificate authorities that meet their requirements for reputation, operation, and security. Members are required to undergo an annual audit and to adhere to industry standards, such as the CA/Browser Forum’s Baseline Requirements and Network Security Guidelines.

Industry initiatives

The group works collaboratively to create and define the initiatives to improve the understanding of policies and their impact on Internet infrastructure.

Certificate Revocation and OCSP Stapling

The group's primary focus was promoting an understanding of the importance of certificate revocation checking and the benefits of OCSP stapling. The protocol is intended to ensure that web users are aware when they visit a web site with a revoked or expired SSL certificate.

Securing Software Distribution with Digital Code Signing

The group has also worked to secure software distribution with digital code signing. Code signing certificates play a key role in helping users identify authentic software code from reputable publishers and receive the assurance that the code has not been tampered with beforehand.

References

References

  1. [https://web.archive.org/web/20130217082728/http://www.symantec.com/connect/blogs/let-s-build-more-secure-future Let’s Build a More Secure Future. Symantec Connect Community]
  2. [http://www.entrust.com/news/2013-02-14-Entrust-Joins-Worlds-Leading-CAs-to-Form-Certificate-Authority-Security-Council-Advance-Internet-Security-and-Trusted-SSL-Ecosystem Entrust Joins World's Leading CAs to Form Certificate Authority Security Council, Advance Internet Security and Trusted SSL Ecosystem - Feb 14, 2013]
  3. "The Paypers. Insights in payments".
  4. "Announcing the Certificate Authority Security Council {{!}} Inside GoDaddy.com".
  5. "Major Certificate Authorities Unite In The Name Of SSL Security - Dark Reading".
  6. "Multivendor power council formed to address digital certificate issues - Network World".
  7. [http://www.cmswire.com/cms/customer-experience/website-certificate-authorities-set-up-security-council-for-advocacy-research-019619.php Website Certificate Authorities Set Up Security Council for Advocacy, Research]
  8. [http://electronicstaff.com/2013/ssl-certificate-authority-security-council-takes-root SSL Certificate Authority Security Council Takes Root. Electronic Staff] {{webarchive. link. (2014-07-14)
  9. (2018-06-15). "Notice of Withdrawal from the CA Security Council {{!}} DigiCert Blog". DigiCert.
  10. "About the CA Security Council".
  11. [https://casecurity.org/2013/02/14/worlds-leading-certificate-authorities-come-together-to-advance-internet-security-and-the-trusted-ssl-ecosystem/ CA Security Council. World’s Leading Certificate Authorities Come Together to Advance Internet Security and the Trusted SSL Ecosystem]
  12. [http://www.networkworld.com/news/2013/021513-certificate-authorities-band-together-to-266752.html Certificate authorities band together to boost security – Network World] {{webarchive. link. (February 25, 2014)
  13. [http://threatpost.com/en_us/blogs/cas-form-new-alliance-focus-security-issues-education-021413 CAs Form New Alliance to Focus on Security Issues, Education. threatpost] {{webarchive. link. (March 8, 2013)
  14. "CA Security Council {{!}} About the CA Security Council".
  15. "New Certificate Authorities group promises better revocation checking - Techworld.com".
  16. [http://www.computerworld.com/s/article/9236803/Certificate_Authorities_to_push_for_better_certificate_revocation_checking?taxonomyId=245 Certificate Authorities to push for better certificate-revocation checking - Computerworld]
  17. Kerner, Sean Michael. "Code Signing Seen as Effective Way to Safeguard App Security". eWeek.
Wikipedia Source

This article was imported from Wikipedia and is available under the Creative Commons Attribution-ShareAlike 4.0 License. Content has been adapted to SurfDoc format. Original contributors can be found on the article history page.

Want to explore this topic further?

Ask Mako anything about Certificate Authority Security Council — get instant answers, deeper analysis, and related topics.

Research with Mako

Free with your Surf account

Content sourced from Wikipedia, available under CC BY-SA 4.0.

This content may have been generated or modified by AI. CloudSurf Software LLC is not responsible for the accuracy, completeness, or reliability of AI-generated content. Always verify important information from primary sources.

Report