Plans to support RFC 8738

Hey, author of the RFC here. The main impetus for this extension was to widen the applicability of ACME to non-HTTPS based TLS systems that rely on the web PKI but may not use DNS names. One major example of this is DNS-over-TLS (DoT), but there are numerous other protocols where DNS names are not routinely used.

This document was also aimed at bringing ACME CAs up to parity with the capabilities of existing non-ACME CAs. Being able to standardize how the validation of IP addresses should be performed also allows us to push for further tightening of the CABF Baseline Requirements on validation techniques.

10 Likes