{"id":30214,"date":"2019-10-31T21:34:16","date_gmt":"2019-10-31T18:34:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami\/"},"modified":"2019-10-31T21:34:16","modified_gmt":"2019-10-31T18:34:16","slug":"ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami","title":{"rendered":"IETF approved ACME \u2014 a standard for working with SSL certificates","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The IETF approved <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8555\">the standard<\/a><\/noindex> Automatic Certificate Management Environment (ACME), which will help automate the obtaining of SSL certificates. Let\u2019s explain how it works.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/444986\/\"><img decoding=\"async\" alt=\"IETF approved ACME \u2014 a standard for working with SSL certificates\" src=\"\/wp-content\/uploads\/2019\/03\/1809c2cb9ea555a72e58207f3e21294d.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<i>\/ Flickr \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/cliff_77\/5373962025\/\">Cliff Johnson<\/a><\/noindex> \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/creativecommons.org\/licenses\/by-sa\/2.0\/\">CC BY-SA<\/a><\/noindex><\/i><\/p>\n<h2>Why the standard is needed<\/h2>\n<p>\nOn average, for configuration <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/services\/ssl?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=acme&amp;utm_content=site\">an SSL certificate.<\/a><\/noindex> for a domain, an administrator may spend between one to three hours. If a mistake is made, one has to wait for the application to be rejected before it can be submitted again. This complicates the deployment of large-scale systems.<\/p>\n<p>The domain validation procedure may differ among certification authorities. The lack of standardization often leads to security issues. A well-known <noindex><a rel=\"nofollow\" href=\"https:\/\/www.godaddy.com\/garage\/information-about-ssl-bug\/\">case<\/a><\/noindex>, where due to a bug in the system, one CA verified all declared domains. In such situations, SSL certificates can be issued to fraudulent resources.<\/p>\n<p>The IETF-approved ACME protocol (specification <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8555\">RFC8555<\/a><\/noindex>) is intended to automate and standardize the certificate obtaining process. Eliminating the human factor will help to enhance the reliability and security of domain name verification.<\/p>\n<p>The standard is open, and anyone interested can contribute to its development. In the <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ietf-wg-acme\/acme\/\">GitHub repository<\/a><\/noindex> , relevant instructions are published.<\/p>\n<h2>How it works<\/h2>\n<p>\nRequest exchanges in ACME occur over HTTPS using JSON messages. To work with the protocol, it is necessary to install an ACME client on the target node, which generates a unique key pair upon the first contact with the CA. Subsequently, these keys will be used to sign all messages between the client and the server.<\/p>\n<p>The first message contains the contact information of the domain owner. It is signed with the private key and sent to the server along with the public key. The server verifies the authenticity of the signature and, if everything is in order, begins the SSL certificate issuance procedure.<\/p>\n<p>To obtain a certificate, the client must prove to the server their ownership of the domain. To do this, they perform certain actions available only to the owner. For example, the certification authority may generate a unique token and ask the client to place it on the website. Next, the CA generates an HTTP or DNS request to retrieve the key from this token.<\/p>\n<p>For example, in the case of HTTP, the key from the token must be placed in a file that will be served by the web server. During DNS verification, the certification authority will look for a unique key in the DNS record text document. If everything is in order, the server confirms that the client has passed validation and the CA issues the certificate.<\/p>\n<p><img decoding=\"async\" alt=\"IETF approved ACME \u2014 a standard for working with SSL certificates\" src=\"\/wp-content\/uploads\/2019\/03\/dd324a6a94cea9254dc1041a3678a40a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>\/ Flickr \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/blondinrikard\/22308731499\/\">Blondinrikard Fr\u00f6berg<\/a><\/noindex> \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/creativecommons.org\/licenses\/by\/2.0\/\">CC BY<\/a><\/noindex><\/i><\/p>\n<h2>Opinions<\/h2>\n<p>\nAccording to <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ietfjournal.org\/acme-better-security-through-automation\/\">words<\/a><\/noindex> IETF, ACME will be useful for administrators who need to work with multiple domain names. The standard will help link each of them to the appropriate SSL.<\/p>\n<p>Among the advantages of the standard, experts also note several <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8555#section-10\">security mechanisms<\/a><\/noindex>. They must ensure that SSL certificates are issued only to the actual domain owners. In particular, a set of extensions is used to protect against DNS attacks, <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/DNSSEC\">DNSSEC<\/a><\/noindex>, while to protect against DoS, the standard limits the rate of execution of individual requests\u2014for example, HTTP for the method <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/POST_(HTTP)\">POST<\/a><\/noindex>. The developers of ACME <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8555#section-10.2\">recommend<\/a><\/noindex> adding entropy to DNS requests and performing them from multiple points in the network for increased security.<\/p>\n<h2>Similar solutions<\/h2>\n<p>\nProtocols are also used to obtain certificates, <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-gutmann-scep-13\">SCEP<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7030\">EST<\/a><\/noindex>.<\/p>\n<p>The first was developed at Cisco Systems. Its goal was to simplify the procedure for issuing X.509 digital certificates and make it as scalable as possible. Before the advent of SCEP, this process required active participation from sysadmins and was poorly scalable. Today, this protocol is one of the most widely used.<\/p>\n<p>As for EST, it allows PKI clients to obtain certificates over secure channels. It applies TLS for message transmission and SSL issuance, as well as for linking the CSR to the sender. Additionally, EST supports elliptic cryptography methods, providing an extra layer of protection.<\/p>\n<p>According to <noindex><a rel=\"nofollow\" href=\"http:\/\/ipj.dreamhosters.com\/wp-content\/uploads\/2017\/08\/ipj20-2.pdf\">According to experts,<\/a><\/noindex>, solutions like ACME should gain broader adoption. They offer a simplified and secure SSL setup model and speed up the process.<\/p>\n<h5>Additional posts from our corporate blog:<\/h5>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/blog\/varianty-it-infrastrukture-dlya-organizacii?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=acme&amp;utm_content=blog\">Options for the organization's IT infrastructure<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/blog\/rezervnoe-kopirovanie-failov?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=acme&amp;utm_content=blog\">File backup: how to prepare for data loss<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/blog\/oblachnyj-server-dlja-praktiki-sysadmina?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=acme&amp;utm_content=blog\">Training environment for admins: how the cloud can help<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/blog\/our-system-architecture-evolution?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=acme&amp;utm_content=blog\">Evolution of the cloud architecture 1cloud<\/a><\/noindex><\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/444986\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>IETF \u043e\u0434\u043e\u0431\u0440\u0438\u043b\u0438 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 Automatic Certificate Management Environment (ACME), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u0435 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432. \u0420\u0430\u0441\u0441\u043a\u0430\u0436\u0435\u043c, \u043a\u0430\u043a \u044d\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442. \/ Flickr \/ Cliff Johnson \/ CC BY-SA \u0417\u0430\u0447\u0435\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u043b\u0441\u044f \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 \u0412 \u0441\u0440\u0435\u0434\u043d\u0435\u043c \u043d\u0430 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0434\u043b\u044f \u0434\u043e\u043c\u0435\u043d\u0430 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440 \u043c\u043e\u0436\u0435\u0442 \u0437\u0430\u0442\u0440\u0430\u0442\u0438\u0442\u044c \u043e\u0442 \u043e\u0434\u043d\u043e\u0433\u043e \u0434\u043e \u0442\u0440\u0435\u0445 \u0447\u0430\u0441\u043e\u0432. \u0415\u0441\u043b\u0438 \u0434\u043e\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u043e\u0448\u0438\u0431\u043a\u0443, \u0442\u043e \u043f\u0440\u0438\u0434\u0435\u0442\u0441\u044f \u0436\u0434\u0430\u0442\u044c, \u043f\u043e\u043a\u0430 \u0437\u0430\u044f\u0432\u043a\u0430 \u0431\u0443\u0434\u0435\u0442 \u043e\u0442\u043a\u043b\u043e\u043d\u0435\u043d\u0430, \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u0441\u043b\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-30214","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"IETF \u043e\u0434\u043e\u0431\u0440\u0438\u043b\u0438 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 Automatic Certificate Management Environment (ACME), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u0435 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47IETF \u043e\u0434\u043e\u0431\u0440\u0438\u043b\u0438 ACME \u2014 \u044d\u0442\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430\u043c\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"IETF \u043e\u0434\u043e\u0431\u0440\u0438\u043b\u0438 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 Automatic Certificate Management Environment (ACME), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u0435 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:34:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:34:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47IETF approved ACME \u2014 the standard for working with SSL certificates | ProHoster","description":"The IETF approved the Automatic Certificate Management Environment (ACME) standard, which will help automate the obtaining of SSL certificates.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47IETF \u043e\u0434\u043e\u0431\u0440\u0438\u043b\u0438 ACME \u2014 \u044d\u0442\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430\u043c\u0438 | ProHoster","og:description":"IETF \u043e\u0434\u043e\u0431\u0440\u0438\u043b\u0438 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 Automatic Certificate Management Environment (ACME), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u0435 SSL-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432.","og:url":"https:\/\/prohoster.info\/en\/blog\/ietf-odobrili-acme-eto-standart-dlya-raboty-s-ssl-sertifikatami","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:34:16+00:00","article:modified_time":"2019-10-31T18:34:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"30214","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 00:10:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:39:23","updated":"2026-01-21 00:10:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/30214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=30214"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/30214\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=30214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=30214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=30214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}