The S/MIME Certificate Working Group (SMCWG) of the CA/Browser Forum is 
considering a change to the S/MIME Baseline Requirements (BR) that will require 
the use of Multi Perspective Issuance Corroboration (MPIC) when conducting 
validation of email domains in accordance with sections 3.2.2.1 or 3.2.2.3 of 
the S/MIME BR.



The proposed approach is based on a similar ballot recently passed as SC67 in 
the TLS Baseline Requirements. The approach requires CAs, when performing 
domain validation and Certification Authority Authorization (CAA) checks, to 
check DNS from multiple network perspectives.  The goal of MPIC is to make it 
more difficult for adversaries to successfully launch attacks (such as BGP 
hijacks) against the domain validation processes.  The S/MIME BR reference the 
affected methods in the TLS BR.



Please note that CAs fall within the scope of the S/MIME BR if they issue 
public-trust end entity certificates that include an Extended Key Usage (EKU) 
for id-kp-emailProtection (OID: 1.3.6.1.5.5.7.3.4) and include an rfc822Name or 
an otherName of type id-on-SmtpUTF8Mailbox in the subjectAltName extension.



The SMCWG encourages CAs that issue S/MIME certificates to be aware of the 
developments surrounding MPIC.  It is noted that the majority of public-trust 
S/MIME issuers also issue TLS certificates and so will automatically be drawn 
into MPIC adoption by the TLS BR ballot.  For more information:



*       S/MIME Certificate Working Group (SMCWG): 
https://cabforum.org/working-groups/smime/
*       TLS BR Ballot 67 describing MPIC: 
https://cabforum.org/2024/08/05/ballot-sc-67-v3-require-domain-validation-and-caa-checks-to-be-performed-from-multiple-network-perspectives-corroboration/
*       SMCWG Public List: 
https://groups.google.com/a/groups.cabforum.org/g/smcwg-public



With kind regards,

Stephen Davidson

Chair, S/MIME Certificate Working Group (SMCWG)

-- 
You received this message because you are subscribed to the Google Groups 
"[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/BL1PR14MB51430391885AD1D80D6F2BDFE59C2%40BL1PR14MB5143.namprd14.prod.outlook.com.

Reply via email to