{"id":10884,"date":"2019-05-31T10:27:09","date_gmt":"2019-05-31T14:27:09","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=10884"},"modified":"2024-07-30T16:23:47","modified_gmt":"2024-07-30T20:23:47","slug":"acme-protocol-what-it-is-and-how-it-works","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/acme-protocol-what-it-is-and-how-it-works\/","title":{"rendered":"ACME Protocol: What It Is and How iI Works"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-automated-certificate-management-environments-explained\">Automated Certificate Management Environments explained.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The ACME (Automated Certificate Management Environment)\nprotocol was originally developed by the Internet Security Research Group for\nits public CA, Let\u2019s Encrypt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ACME is what facilitates Let\u2019s Encrypt\u2019s entire business\nmodel, allowing it to issue 90-day domain validated SSL certificates that can\nbe renewed and replaced without website owners ever having to lift a finger. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In March of this year the ACME protocol was finally published as an internet standard (<a href=\"https:\/\/tools.ietf.org\/html\/rfc8555\">RFC 8555<\/a>) and now we\u2019re starting to see commercial CAs support it. <a href=\"https:\/\/sectigo.com\/newsroom\/sectigo-adds-acme-protocol-support-in-certificate-manager-platform-to-automate-ssl-lifecycle-management\">Including one of our biggest partners, Sectigo (formerly Comodo CA)<\/a>, which is currently beta testing its support for the protocol before a planned full launch this Summer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously \u2013 given the fact Sectigo offers business authentication SSL\/TLS certificates in addition to other X.509 certificates like S\/MIME, Code Signing, etc. \u2013 the use case for the ACME protocol is about to change quite a bit. But that\u2019s to the benefit of corporate and enterprise clients with massive infrastructures and considerable digital certificate needs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, today we\u2019re going to spend some time introducing the uninitiated\nto the ACME protocol, explaining what it does, how it works and why it\u2019s going\nto change the way organizations manage their digital certificates forever.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-acme-protocol\">What is the ACME protocol?<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"230\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/bigstock-182802247-300x230.png\" alt=\"An anvil from the fiction company ACME\" class=\"wp-image-10886\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/bigstock-182802247-300x230.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/bigstock-182802247-768x590.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/bigstock-182802247-1024x787.png 1024w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">For the vast majority of people that don\u2019t spend their time focusing on PKI and digital certificates, mention of the word \u201cACME\u201d probably calls to mind the fictional organization that used to ship Wile E. Coyote products for all those harebrained schemes that inevitably failed to get him a taste of that sweet, stringy road runner meat. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, we\u2019re not talking about that ACME, enjoyable as discussing business ethics in the Looney Tune-iverse might be. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start with sort of an executive summary and then we\u2019ll\ndrill down into the specifics further down the page. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ACME protocol functions by installing a certificate management agent on a given web server. The organization or domain undergoes validation at the outset, with the agent assisting with the domain control verification aspects, and once completed the agent can request, renew and revoke certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The way that process works is that the agent generates a key pair and shares it with the CA at the outset of the validation process. Once validation is finished and the agent is verified as the proven owner of the key pair, it can use its key to digitally sign the CSRs it generates and sends to the CA via HTTPS requests. The CA uses the CSR, along with its associated public key, to issue the certificate and send it back to the agent. The agent downloads and installs it, then notifies the designated contact. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The agent can be automated to check in with the CA at given intervals to rotate certificates and keys. None of this requires human intervention. Agents can be installed on any server that uses X.509 certificates and can handle multiple domains on the same server; or agents can be installed on a domain-by-domain basis. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This knocks out about 95% of the labor typically involved\nwith requisitioning digital certificates, which can be a massive savings at\nscale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now let\u2019s drill down a little deeper.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-does-the-acme-protocol-work\">How does the ACME protocol work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s really two explanations for this question. There\u2019s a high-level one that just covers the basics and then there\u2019s a more in-depth one that covers the technical side. We&#8217;re going to try to keep this high level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you get the ACME agent installed and configured properly, it\u2019s actually pretty simple. We\u2019ll talk about setup in a minute, but for now just keep in mind that during the verification process that takes place when the agent is installed a key pair will be generated for use by the agent and the CA. Those keys are sometimes referred to as &#8220;authorization keys.&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-issuance-renewal\">Issuance\/Renewal<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To get a digital certificate issued, the agent simply needs\nto generate a CSR for the desired domain and send it along to the CA. This is\ndone via HTTPS. <\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The agent generates a CSR for the domain<\/li>\n\n\n\n<li>The agent signs the public key generated alongside the CSR with the corresponding private key<\/li>\n\n\n\n<li>The agent signs the whole CSR with its own private key (the authorization key generated during initial configuration)<\/li>\n\n\n\n<li>The CA verifies both signatures and issues the certificate<\/li>\n\n\n\n<li>The agent receives the certificate and installs it on the relevant domain<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"654\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Issuance-1024x654.png\" alt=\"Issuance process using ACME protocol\" class=\"wp-image-10889\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Issuance-1024x654.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Issuance-300x192.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Issuance-768x490.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Issuance.png 1090w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">I realize that the agent we\u2019re discussing is definitely not a little person that resides on your server like the icons I\u2019ve chosen might indicate. So, there\u2019s no need to point that out. It&#8217;s just more amusing to imagine that way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anyway, this process plays out more or less the same with renewals, as well. The agent can be configured to ping the CA at regular intervals to either rotate keys or swap out entire certificates. And this is all done behind the scenes, without the need for any human intervention.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-revocation\">Revocation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Much like getting a certificate issued, getting one revoked requires the agent to sign a request with its private key &#8211; just in this case it&#8217;s a revocation request. The CA verifies the signature, revokes the certificate and then publishes that information to the requisite Certificate Revocations Lists (CRLs) and <a href=\"https:\/\/www.thesslstore.com\/blog\/ocsp-stapling-best-method-checking-certificate-validity\/\">Online Certificate Status Protocol<\/a> responders (OCSPs). These are the mechanisms that browsers use to check the validity of SSL\/TLS certificates.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The agent generates a revocation request for the<br>SSL\/TLS certificate<\/li>\n\n\n\n<li>The agent signs the request with its private key<\/li>\n\n\n\n<li>The CA verifies the signature to ensure the<br>request is authorized<\/li>\n\n\n\n<li>The CA revokes the certificate<\/li>\n\n\n\n<li>The certificate\u2019s revocation status is published<br>to CRLs and OCSP responders<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"697\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Revocation-1024x697.png\" alt=\"Revocation process using the ACME protocol\" class=\"wp-image-10888\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Revocation-1024x697.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Revocation-300x204.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Revocation-768x522.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Revocation.png 1104w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">There are scenarios where the admin or employee responsible for\noverseeing certificate management may have to initiate the revocation request,\nbut after that everything is hands-off. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-setting-up-acme\">Setting up ACME<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ok, now let\u2019s get into what setup looks like when you decide to start using the ACME protocol. The very first thing you\u2019re going to need to decide on is what client you want to use. There are dozens of different clients that run in every conceivable language and environment. <\/p>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<ul class=\"wp-block-list\">\n<li>Bash<\/li>\n\n\n\n<li>C<\/li>\n\n\n\n<li>C++<\/li>\n\n\n\n<li>Clojure<\/li>\n\n\n\n<li>Docker<\/li>\n\n\n\n<li>Go<\/li>\n\n\n\n<li>HAProxy<\/li>\n\n\n\n<li>Java<\/li>\n\n\n\n<li>Microsoft Azure <\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<ul class=\"wp-block-list\">\n<li>nginx<\/li>\n\n\n\n<li>Node.js<\/li>\n\n\n\n<li>OpenShift<\/li>\n\n\n\n<li>Perl<\/li>\n\n\n\n<li>PHP<\/li>\n\n\n\n<li>Python<\/li>\n\n\n\n<li>Ruby<\/li>\n\n\n\n<li>Rust<\/li>\n\n\n\n<li>Windows\/IIS <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Despite the fact Let\u2019s Encrypt was the first to leverage the ACME protocol &#8211; and despite the fact it was designed by its parent organization &#8211; it\u2019s open source. There is no proprietary client for any of the CAs. Rather the protocol is designed to give the user their pick of Certificate Authorities, provided that CA supports it. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re currently on v2 of the protocol, which was published\naround a year ago in March of 2018. ACME v2 is not backwards compatible with\nACME v1. In addition to overhauling some of its existing functions for the sake\nof a more streamlined user experience, v2 also added the ability to issue Wildcard\nSSL\/TLS certificates, albeit with a rather strict DNS text record challenge. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges, in the context of ACME, refers to the tests given by the CA to verify the agent\u2019s control over a given domain. More on that in a minute.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a list of some of the most <a href=\"https:\/\/github.com\/topics\/acme-client\">popular ACME v2 clients<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Certbot<\/li>\n\n\n\n<li>ACMESharp<\/li>\n\n\n\n<li>acme-client<\/li>\n\n\n\n<li>GetSSL<\/li>\n\n\n\n<li>Posh-ACME<\/li>\n\n\n\n<li>Caddy<\/li>\n\n\n\n<li>Sewer<\/li>\n\n\n\n<li>nginx ACME<\/li>\n\n\n\n<li>node-acme-lambda<\/li>\n\n\n\n<li>peter_sslers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The last one made the cut <a href=\"https:\/\/en.wikipedia.org\/wiki\/Peter_Sellers\">for the name alone<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s get back to setting up your domain\/server to use the\nACME protocol. Now that you\u2019ve chosen the client you want to use and installed\nit on your server, we can get into the configuration.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The client will prompt you to enter the domain(s) it will be managing<\/li>\n\n\n\n<li>The client will offer a <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-certificate-authority-list-and-where-can-i-find-one\/\">list of Certificate Authorities<\/a> that support the ACME protocol<\/li>\n\n\n\n<li>Once a CA is selected, the client contacts the CA and generates an authorization key pair<\/li>\n\n\n\n<li>The CA will issue challenges (DNS or HTTPS) requiring the agent to take an action that demonstrates control over said domain(s)<\/li>\n\n\n\n<li>In addition to the challenges, the CA also sends a nonce \u2013 <a href=\"https:\/\/www.thesslstore.com\/blog\/why-all-the-fuss-about-64-bit-serial-numbers\/\">a randomly generated number<\/a> \u2013 that the agent must sign with the private key it just generated to demonstrate ownership of said key pair<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"735\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-setup-1024x735.png\" alt=\"Validation process with ACME protocol\" class=\"wp-image-10887\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-setup-1024x735.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-setup-300x215.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-setup-768x551.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-setup.png 1105w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Once the CA is able to verify that the challenges have been satisfied\nand the signature is authentic, the agent is officially authorized to act on\nbehalf of the validated domains. All-in-all the whole process takes maybe 10\nminutes. From there, just make the configurations you want in terms of how\nfrequently the agent will contact the CA to rotate or renew certificates, etc. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where having <a href=\"https:\/\/www.thesslstore.com\/blog\/the-rise-of-cyber-resilience\/\">pre-defined security policies<\/a> comes in handy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-common-acme-errors\">Common ACME Errors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, with anything of this nature errors are going to occur. The ACME protocol uses a standardized format for reporting these errors. It\u2019s called a problem document (<a href=\"https:\/\/tools.ietf.org\/html\/rfc7807\">RFC 7807<\/a>) and in its \u201ctype\u201d field the server arranges a series of tokens that provide information as to what the problem is. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The string looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">urn:ietf:params:acme:error:<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">When you see the word \u201ctoken,\u201d the ACME RFC is using the\nterm to describe the inputs between each one of those colons. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Thus, API clients can be informed of both the high-level error class (using the status code) and the finer-grained details of the problem (using one of these formats).<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The portion of that string we\u2019re going to focus on is the &#8220;error&#8221; token. Here\u2019s a quick list of the possible errors and what they mean. Many of these can be corrected by the ACME client itself. Some may involve human intervention. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-error-tokens\">Error Tokens <\/h3>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td>\n   <strong>Type<\/strong>\n   <\/td><td>    <strong>Description<\/strong>    <\/td><\/tr><\/thead><tbody><tr><td>\n  accountDoesNotExist\n  <\/td><td>\n  The requested account does not exist\n  <\/td><\/tr><tr><td>\n  alreadyRevoked\n  <\/td><td>\n  The requested certificate has already been revoked\n  <\/td><\/tr><tr><td>\n  badCSR\n  <\/td><td>\n  The CSR was generated incorrectly (non-compliant)\n  <\/td><\/tr><tr><td>\n  badNonce\n  <\/td><td>\n  The nonce generated was insufficient\n  <\/td><\/tr><tr><td>\n  badPublicKey\n  <\/td><td>\n  The server doesn\u2019t support the public key that signed this\n  <\/td><\/tr><tr><td>\n  badRevocationReason\n  <\/td><td>\n  The requested revocation lacks a valid reason\n  <\/td><\/tr><tr><td>\n  badSignatureAlgorithm\n  <\/td><td>\n  The server doesn\u2019t support the algorithm that was used to\n  sign this\n  <\/td><\/tr><tr><td>\n  caa\n  <\/td><td>\n  Issuance forbidden by a CAA record\n  <\/td><\/tr><tr><td>\n  compound\n  <\/td><td>\n  Specific error conditions are indicated in the\n  \u201csubproblems\u201d array\n  <\/td><\/tr><tr><td>\n  connection\n  <\/td><td>\n  The server couldn\u2019t connect to the validation target\n  <\/td><\/tr><tr><td>\n  dns\n  <\/td><td>\n  There was a problem with the DNS query during validation\n  <\/td><\/tr><tr><td>\n  externalAccountRequired\n  <\/td><td>\n  The request is missing a value in the\n  \u201cexternalAccountBinding\u201d field\n  <\/td><\/tr><tr><td>\n  incorrectResponse\n  <\/td><td>\n  The client returned and incorrect response to a validation\n  challenge\n  <\/td><\/tr><tr><td>\n  invalidContact\n  <\/td><td>\n  A contact URL for your account was invalid\n  <\/td><\/tr><tr><td>\n  malformed\n  <\/td><td>\n  The request message was malformed\n  <\/td><\/tr><tr><td>\n  orderNotReady\n  <\/td><td>\n  Self-explanatory\n  <\/td><\/tr><tr><td>\n  rateLimited\n  <\/td><td>\n  The request exceeds a rate limit\n  <\/td><\/tr><tr><td>\n  rejectedIdentifier\n  <\/td><td>\n  The server will not issue certificates for this domain\n  <\/td><\/tr><tr><td>\n  serverInternal\n  <\/td><td>\n  The server experienced an internal error\n  <\/td><\/tr><tr><td>\n  tls\n  <\/td><td>\n  A TLS error occurred during validation\n  <\/td><\/tr><tr><td>\n  unauthorized\n  <\/td><td>\n  The client isn\u2019t authorized to make this request\n  <\/td><\/tr><tr><td>\n  unsupportedContact\n  <\/td><td>\n  A contact URL for your account used an unsupported\n  protocol scheme\n  <\/td><\/tr><tr><td>\n  unsupportedIdentifier\n  <\/td><td>\n  Self-explanatory\n  <\/td><\/tr><tr><td>\n  userActionRequired\n  <\/td><td>\n  Manual intervention is required at the \u201cinstance\u201d URL\n  <\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-acme-challenges\">ACME Challenges<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Validation is one of the trickiest things Certificate Authorities are asked to do. There is no fool-proof single method for validating control over a domain or identifier \u2013 or at least none that have been standardized \u2013 instead CAs rely on a patchwork of validation checks for confirming whether an entity has control. The ACME protocol allows for this by offering different types of challenges that can verify control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While there were originally three challenges available when ACME v1 first came into use, today one has been deprecated. A third challenge type is being designed, but it\u2019s a fairly high-level standard that\u2019s intended more for large hosting providers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-http-challenges\">HTTP Challenges<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The CA sends your ACME agent a token to install on the server.\nThe agent creates a file that contains said token along with a thumbprint of the\nauthorization key that was generated during setup. The two are \u201cconcatenated\u201d\nwhich is a fancy five dollar word for putting two things end-to-end. <\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(Token) || '.' || (Thumbprint of Authorization Key)<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Once the file is installed, the agent informs the CA, which\ntries to retrieve it. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-dns-challenges\">DNS Challenges<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This challenge requires your ACME agent to place a given\nvalue in a TXT record in your domain\u2019s DNS space. Like with HTTP challenges,\nthe CA provides the agent a token, which is concatenated with the thumbprint of\nthe authorization key to create the TXT file. Once the agent notifies the CA\nthat the challenge has been met, the CA attempts to make a DNS lookup and\nretrieve the TXT record. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tls-sni-01-tls-alpn-01\">TLS-SNI-01 &amp; TLS-ALPN-01<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re just going to give these a quick look. SNI-01 was\ndeprecated back in March because there were some security concerns about it. It\nworked by facilitating a TLS handshake on port 443 and sending a specific SNI (Server\nName Indication) header. TLS-ALPN-01 is similar, and is currently being made\ninto its own standard, but it represents a level of complexity that most\norganizations aren\u2019t all that excited to jump into.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-long-does-it-take-to-satisfy-these-challenges\">How long does it take to satisfy these challenges?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This all happens behind the scenes very quickly. And the agent\ndoes all the work. There are a few suggestions made in the RFC though:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Challenges-300x300.png\" alt=\"How long does it take to satisfy an ACME challenge\" class=\"wp-image-10891\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Challenges-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-Challenges.png 350w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list\">\n<li>Clients shouldn\u2019t respond to challenges until they\u2019re sure that the server\u2019s queries will succeed.<\/li>\n\n\n\n<li>If the initial attempts fail, the CA\u2019s server will allow your agent to retry. It\u2019s advised not to retry more than once every 5-10 seconds though.<\/li>\n\n\n\n<li>The CA will view the challenge as \u201cin progress\u201d as long as the agent continues trying.<\/li>\n\n\n\n<li>There may be a small delay in between uploading the file or DNS record, and the CA being able to retrieve them.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Keep in mind though, we\u2019re speaking about time in a digital context that tracks some functions in milliseconds. Realistically, most of these challenges are satisfied in well under 15 seconds. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-i-thought-acme-only-issued-dv-ssl-certificates\">I thought ACME only issued DV SSL certificates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nope. That\u2019s just the only way it\u2019s ever been used. But ACME\ncan also be used to requisition high-value, business authentication\ncertificates as well. Obviously, you need to have some sort of existing\nbusiness relationship with the CA you\u2019re using. In Sectigo\u2019s case it will be any\nsort of account with a balance or a payment agreement. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The protocol still works completely the same, there are just a couple of things that happen independently alongside of what the ACME protocol is doing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alongside setting up the ACME client and configuring it to contact your chosen CA, your organization undergoes either organization or extended validation \u2013 whatever you choose. That validation information stays good for 24 months. Once that\u2019s complete, anytime a domain needs a certificate, the agent can contact the CA, satisfy the domain challenge and get the certificate issued. <\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-switching-cas-is-easy-with-acme\">Switching CAs is easy with ACME<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the biggest advantages to using the ACME protocol,\nwhich is likely going to see wide use now that commercial CAs are beginning to\nsupport it, is that it\u2019s easy to switch between CAs on the fly. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You literally just have to make an account with the new CA\nand then switch the URL or IP address that the agent is contacting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After a quick authorization, the agent does the rest,\nreplacing the old certificates with new ones from the new CA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sectigo plans to have a full rollout for its ACME protocol support this summer. <a href=\"https:\/\/www.digicert.com\/news\/digicert-announces-certcentral-enterprise-an-all-in-one-certificate-management-solution-for-tls-ssl\/\">DigiCert announced it was adding support earlier this year<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"How to Automate ACME Protocol Deployment\" width=\"960\" height=\"540\" src=\"https:\/\/www.youtube.com\/embed\/BTEnnx1wOAc?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>With more CAs beginning to support the ACME protocol, it&#8217;s time to take a look at what it is, how it works and why it&#8217;s going to change everything.<\/p>\n","protected":false},"author":6,"featured_media":10885,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[10448,9550],"class_list":["post-10884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-acme","tag-sectigo","post-with-tags"],"views":64627,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/ACME-feature.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=10884"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/10885"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=10884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=10884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=10884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}