RFC 8555: ACME: Managing certificates automatically
Summary
RFC 8555 standardises ACME for the automated issuance, validation and renewal of certificates. Automation made short certificate lifetimes manageable in practice. PKI reliability increasingly depends on secure renewal processes.
Ideas
- Clients prove control over domain names through challenges.
- Accounts sign protocol messages.
- Orders bundle authorisations and certificate requests.
Remarks
- RFC 8555 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Automate renewal and test it before expiry.
- Protect account keys and limit access to challenges.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.