Podcast
Root Causes 243: Which Came First, the BRs or the EVGs?


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
September 20, 2022
Many people don't realize that the CA/Browser Forum's Baseline Requirements actually came LATER THAN the Extended Validation Guidelines. In this episode we explain how this seemly backward turn of events came about and what it says about how online trust has evolved over the past few decades.
Podcast Transcript
Lightly edited for flow and brevity.
So, let’s start with the basics and then somewhere along the line I’ll ask you a question and you may know the answer.
So, the Baseline Requirements are exactly what they say. They are baseline requirements. Every public certificate that’s covered, that’s in scope - which today is TLS, but there is other certificate types coming - must follow these requirements. It’s baseline. If it’s a public certificate, it must follow these guidelines. Then there is a separate document called the EV Guidelines – the EVGs – which is for an Extended Validation style of certificate, for the certificate types that support that, there are specific guidelines that are specific to Extended Validation that they must follow. Now, based on that, let me ask you this, Jason. Which one came first?
Wrongo. The EV Guidelines were created first and the Baseline Requirements came after.
When I first learned about domains probably like ’92, ’93, I bought a domain and I’ll tell you how I did it. I had to write a letter. I had to put it in a paper envelope. I then licked the stamp and put it in a mailbox and then there was a check drawn from a Canadian bank account, which confused the heck out of the folks at Rutgers University who received my letter and my check and they were kind enough to just say we are not even gonna cash your check because we don’t know what to do with Canadian money, but here is your domain.
And so, right. It was chaotic. It was very chaotic and there was increasing concern about, am I really going to be able to trust a certificate. Like can I trust a certificate at all? Can I trust what a certificate is claiming in a most basic fundamental way? And so, the EVGs were about creating a set of guidelines around this thing we called Extended Validation, and those will be used to create a consistently and reliably high or adequately high level of authentication for information.

