[Acme] I-D Action: draft-ietf-acme-star-delegation-04.txt

internet-drafts@ietf.org Tue, 25 August 2020 12:20 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: acme@ietf.org
Delivered-To: acme@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 55B223A0D0D; Tue, 25 Aug 2020 05:20:26 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Cc: acme@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 7.14.1
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: acme@ietf.org
Message-ID: <159835802630.10396.17359674822654564531@ietfa.amsl.com>
Date: Tue, 25 Aug 2020 05:20:26 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/5TJ1xQg4GQAAVHqwOtf9EJbyH8k>
Subject: [Acme] I-D Action: draft-ietf-acme-star-delegation-04.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Aug 2020 12:20:28 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Automated Certificate Management Environment WG of the IETF.

        Title           : An ACME Profile for Generating Delegated STAR Certificates
        Authors         : Yaron Sheffer
                          Diego Lopez
                          Antonio Agustin Pastor Perales
                          Thomas Fossati
	Filename        : draft-ietf-acme-star-delegation-04.txt
	Pages           : 33
	Date            : 2020-08-25

   This memo proposes a profile of the ACME protocol that allows the
   owner of an identifier (e.g., a domain name) to delegate to a third
   party access to a certificate associated with said identifier.  A
   primary use case is that of a CDN (the third party) terminating TLS
   sessions on behalf of a content provider (the owner of a domain
   name).  The presented mechanism allows the owner of the identifier to
   retain control over the delegation and revoke it at any time by
   cancelling the associated STAR certificate renewal with the ACME CA.
   Another key property of this mechanism is it does not require any
   modification to the deployed TLS ecosystem.

The IETF datatracker status page for this draft is:

There are also htmlized versions available at:

A diff from the previous version is available at:

Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at: