#1239: Other Spec Review: CRA web browser standard
Discussions
Log in to see TAG-private discussions.
Discussed
Jun 29, 2026 (See Github)
Heather: Did we decide this was out of scope, or we are unable to participate? Team working on it?
Yves: Simone worked on this from a security perspective.
Heather: Should we say this is individual participation only; not TAG?
Yves: Depends on scope of the review. If it's security related then it's better to have security people work on it.
Heather: So individual contribution is OK? But not TAG?
Yves: I think it would be hard for TAG to come to consensus?
Christian: Is it architectural? Or just definitions? What's the scope of the review request? The entire document?
Heather: Looks like.
Christian: It's very long. Not sure we can do this at all. Think we should decline it, stating we can't do it in that timeframe. I think it's within TAG's scope, but too long for us to process in the timeframe that remains.
Christian: Yves, could you check with the team if/how we can engage with this request, and what the scope is?
Yves: Yep
Christian: I'll send a response in the GitHub thread, and Yves is going to check on it within W3C.
Comment by @christianliebel Jul 1, 2026 (See Github)
@littledan Thanks for sending this to us. What is the expected scope of our review? The entire document, or specific sections?
Discussed
Jul 6, 2026 (See Github)
Lola: Heather and Ehsan are assigned to this, but the document is too much for two people. If we can get more people to take a look, especially people who have some knowledge of how security works in browsers. If you are interested, please assign yourself in the issue or on Slack. Note that this is not the whole of the CRA, and the authors were asked to use the W3C's user agent defintion and explicitly chose not to.
Christian: We have asked the submitter what kind of review they need.
Lola: The submitter won't likely offer a response because his paid engagement with this work has ended. Recommend instead that we just do the best we can with the people who volunteer.
Discussed
Jul 13, 2026 (See Github)
Lola: Heather asked in Slack if anyone else can review.
Heather: Ehsan has comments on the way. Is anyone else interested in chiming in? When asked what they want us to look at, they said the whole thing. I don't know enough of what's happening at the TLS level, but commented on what I could.
Matthew: That probably means waiting for Ehsan to review my review.
Lola: I think we should do this differently to a typical review. Normally we say 'these are our questions on the whole thing' and have a dialog. But in this case, I think we will be async, and can do this better as a rolling review. We're already missed the two-week deadline, so we're no longer beholden to that timeframe. It's a lot of technically challenging stuff. The people who've composed it don't have web/browser experience, so the input will probably be of help. And this is a bit harder than a normal spec review. So, rolling review; post questions as we have them. We could start opening issues in their system (GitLab).
Luke: Not a TLS expert, but if there are specific questiosn that you have, expertise that you need, it might be worth linking to those, and I can try to work on specific bits. Don't think it's going to be valuable for me to read through the whole thing.
Lola: If you have a look at Heather's comment in the brainstorming thread you'll see what she's written about places where she has questions. Brian has posted about where they've posted this (GitLab). We can figure out raising issues later.
Comment by @littledan Jul 14, 2026 (See Github)
The entire document.
Discussed
Jul 20, 2026 (See Github)
Ehsan: For this, I think we didn't have a lot of discussion. At least me and HEather. Either today or yesterday there was another post saying that it's been updated. My points have changed in the new development. I'm drafting something, and I hope that I will soon submit my opinions on the private brainstorm for Heather to review.
Comment by @littledan Jul 22, 2026 (See Github)
The final version to review is https://labs.etsi.org/rep/stan4cra/en-304-617/-/raw/main_publish/CRA_Vertical_hEN_Browsers-jul6.pdf . Thank you for your comments here!
Comment by @awhalley Jul 30, 2026 (See Github)
There was quite a bit of last minute churn, and the version that just passed remote consensus is: https://labs.etsi.org/rep/stan4cra/en-304-617/-/raw/main_publish/CRA_Vertical_hEN_Browsers-jul15.pdf
Any review would be greatly appreciated, though note there is still editorial cleanup to do, but the normative sections (5, 6, and Annex K) would be were to focus most attention.
OpenedJun 16, 2026
We have a new full draft. Please review. It would be best if comments were delivered within 2-4 weeks via a labs issue, as Simone delivered previously. Apologies for this request being not well formatted.
Specification
https://labs.etsi.org/rep/stan4cra/en-304-617/-/blob/main_publish/EN-304-617.md?ref_type=heads
Explainer
https://
Links
The specification
Where and by whom is the work is being done?
Please make comments in
https://labs.etsi.org/rep/stan4cra/en-304-617/-/work_items
Feedback so far
You should also know that...
No response
<!-- Content below this is maintained by @w3c-tag-bot -->Track conversations at https://tag-github-bot.w3.org/gh/w3ctag/design-reviews/1239