Conversation

As a bonus, this would supercharge DANE deployment by making it a prerequisite for secure issuance of legacy PKI certificates. make it happen.
Quote Tweet
Replying to @DanielMicay
I wish LE/ACME would add HTTPS-only mode, where the self-referentiality is avoided by insisting on having a DANE record matching the server's key at the time of ACME request.
1
3
I've now tested that accounturi works too (valid and invalid). This provides a way to properly verify via HTTP authentication using the root of trust since the communication between the ACME client and server is authenticated for the accounturi. The issue is it's staging only.
1
1
Show replies