Automatic Certificate Management Environment (ACME)

Automatic Certificate Management Environment (ACME)
复制标题

DOI:
10.17487/rfc8555
复制
发表时间:
2019-03
期刊:
RFC
影响因子:
--
通讯作者:
Richard L. Barnes;Jacob Hoffman-Andrews;D. McCarney;James Kasten
Richard L. Barnes;Jacob Hoffman-Andrews;D. McCarney;James Kasten
中科院分区:
其他
文献类型:
--
作者:
Richard L. Barnes;Jacob Hoffman-Andrews;D. McCarney;James Kasten

文献摘要

被引文献

相似文献

公钥基础设施X.509(PKIX)证书用于多种目的,其中最重要的是域名的认证。因此,Web PKI中的证书颁发机构(CA)被信任来验证证书的申请者合法地表示证书中的域名。今天,这种核查是通过一系列特设机制进行的。本文档描述了一个协议,CA和申请者可以使用该协议自动执行验证和证书颁发过程。该协议还为其他证书管理功能提供了便利,例如证书撤销。RFC编辑:请删除以下段落:此草案的源代码在GitHub中维护。建议的更改应在https://github.com/ietf-wg-acme/acme [1]上作为拉取请求提交。说明书也在这一页上。编辑性的更改可以在GitHub中管理,但任何实质性的更改都应在ACME邮件列表(acme@ietf.org)上讨论。
Public Key Infrastructure X.509 (PKIX) certificates are used for a number of purposes, the most significant of which is the authentication of domain names. Thus, certification authorities (CAs) in the Web PKI are trusted to verify that an applicant for a certificate legitimately represents the domain name(s) in the certificate. Today, this verification is done through a collection of ad hoc mechanisms. This document describes a protocol that a CA and an applicant can use to automate the process of verification and certificate issuance. The protocol also provides facilities for other certificate management functions, such as certificate revocation. RFC EDITOR: PLEASE REMOVE THE FOLLOWING PARAGRAPH: The source for this draft is maintained in GitHub. Suggested changes should be submitted as pull requests at https://github.com/ietf-wg-acme/acme [1]. Instructions are on that page as well. Editorial changes can be managed in GitHub, but any substantive change should be discussed on the ACME mailing list (acme@ietf.org).