Conversation

As a bonus, this would supercharge DANE deployment by making it a prerequisite for secure issuance of legacy PKI certificates. make it happen.
Quote Tweet
Replying to @DanielMicay
I wish LE/ACME would add HTTPS-only mode, where the self-referentiality is avoided by insisting on having a DANE record matching the server's key at the time of ACME request.
1
3
Replying to and
By the way, it appears you can register an account (certbot register) and then pin the account id to have ECDSA-based authentication via ACME. The accounturi and validationmethods features are only used for the staging service though. I've tested that validationmethods works.
1
1
Show replies