[Acme] [acme] RFC 9773 ARI: Gap in normative guidance on renewal window computation
Brian Vicente <bvicente@sanctumsecops.com> Sun, 07 June 2026 20:37 UTC
Return-Path: <bvicente@sanctumsecops.com>
X-Original-To: acme@mail2.ietf.org
Delivered-To: acme@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id AAE28FCF109E for <acme@mail2.ietf.org>; Sun, 7 Jun 2026 13:37:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780864653; bh=9aUUDuCGyHXiUVTPPu6uHtvGh94Jh8CYOuBYbkdc1nA=; h=From:To:Subject:Date; b=qXOxwvIFW7t6tm46Ued2+gubERSUIonlc6UMFoA7DeYjTOG3srkxO1cq+Qx/0BtUG DBZocC7wucKUHE2XsCEQNSG85RZIQliNvhMLfSxEI1aYfbAm7AUrLd4XVFWPHzuyX9 dlS8xOPjA0RMJ6/WOviXS6P3qZooE3HSRqBPcsdU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PqtLWSgs7GuN for <acme@mail2.ietf.org>; Sun, 7 Jun 2026 13:37:33 -0700 (PDT)
Received: from DM1PR04CU001.outbound.protection.outlook.com (mail-centralusazon11020076.outbound.protection.outlook.com [52.101.61.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 19777FCF0D91 for <acme@ietf.org>; Sun, 7 Jun 2026 13:35:28 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=uLpV1xPblnVoIh8QMWTV1/3qRuJC1SFS9dgKP4pEZy2vMyuTF6x9fL4+mu840NMAiC33doB0kJpCvPYmTPCtRnfJCSrkAC/NjFgKCOevlQ32OX1SIQ0f+bpgUGI+D7lNwx5c9Bx71U4y5R6Yr5M5xZb33WJpSLYQwNEnGPmX5n9hgQX4cLazINL+jgi9GG6r5lSqDNRfJqUU8vgqf7ShCJr5e54scVSsc2yCoM0QT2tjyYA6Y3QlAXBsxe9UaLmijp0/fR3A1kBlAx0XN3EOoY6kA+nIeSdQHFz58pJ+JY07OOk/SPXHGAPFyMYqP+zDHxpWJVWCd15UZ98gqLw4dQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=9aUUDuCGyHXiUVTPPu6uHtvGh94Jh8CYOuBYbkdc1nA=; b=wUNolDhreXtZUR2iVnD3r6z7KqfGEf5IwAcaKJAbTLdBZZeBsEcBcwXpAB/s3BQjKVM7KcVsNC6O2zVVrCqLBCSlPvDIiJ9xNjNN2IZv3FYUaeLWs50Y3xq1K+6sYpGpYbj2q+tGrYqNvbtg1EfCiTAWdxK7z894SwY22xAtj6OiNVelgmkFHllkiP04kJZc4nsHE4qzL2GEU7EmogJAV5RMvxjYo+4KE+vMBi45on/UewULDa+oynCB1eRrSTFcdC9SfOym2Rw/539raccI1Ft2WmgnuGd+MGsRPV4Qah1ePDHx1tQlu5aSLIKJnn74H18TCmLFWCR/60aHFQdWWw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=sanctumsecops.com; dmarc=pass action=none header.from=sanctumsecops.com; dkim=pass header.d=sanctumsecops.com; arc=none
Received: from DS0PR10MB7405.namprd10.prod.outlook.com (2603:10b6:8:15e::19) by IA1PR10MB5948.namprd10.prod.outlook.com (2603:10b6:208:3d4::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.92.12; Sun, 7 Jun 2026 20:35:20 +0000
Received: from DS0PR10MB7405.namprd10.prod.outlook.com ([fe80::3036:e723:644e:ae54]) by DS0PR10MB7405.namprd10.prod.outlook.com ([fe80::3036:e723:644e:ae54%5]) with mapi id 15.21.0092.011; Sun, 7 Jun 2026 20:35:20 +0000
From: Brian Vicente <bvicente@sanctumsecops.com>
To: "acme@ietf.org" <acme@ietf.org>
Thread-Topic: [acme] RFC 9773 ARI: Gap in normative guidance on renewal window computation
Thread-Index: AQHc9r0ONcTwTRNFT022S4TdI3fdQA==
Date: Sun, 07 Jun 2026 20:35:20 +0000
Message-ID: <DS0PR10MB7405ED98E45B92D43790664CDB1F2@DS0PR10MB7405.namprd10.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=sanctumsecops.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DS0PR10MB7405:EE_|IA1PR10MB5948:EE_
x-ms-office365-filtering-correlation-id: 2abe553c-c11f-4172-5f35-08dec4d44b30
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|41320700013|34036016|586017|376014|34096008|38070700021|8096899003|6133799003|3023799007|18002099003|56012099006;
x-microsoft-antispam-message-info: MCwHLb0LWC++34mhzuKEqwv3/nog6kzO8fWk3cnHGcUpkZzluZdHQHeP8lMj6aUIDGSXKaZUJilJDWSqDqwpWYfQopZIa04oudwQ4EC+OSo2Mwbckqz1hHjIXE0Xl1s9mmfYbhS/vcoZmXGhT+my5dbpV94x/BDG7xgTNmWBUIMWPdrqUYW5LQmmSz6pL+fZLOZuNu3UvQrnKClhIwrO0KSK0Hh2flAd9TNEd31Av0Qrc9I34tpi0PxCk34hf/gejdTpvFWbBDb+fHr+y0pqwzgSXfJ1GYpP5di0QqzeWx2L9pq5wWVb1CuHhexxEo3ClZ3TM/clOpBZBw9p83NdWl0oghCjAbGGLcWeoh3RVUj5nvDT89CFZfmh43oZSqg4JCXXsY6kBTVJaEUFp6Q04CPMmn5EzpDBwu97mSpINZv2N5jA6xupp9sttBDMFdNBIgkdYXLrjLKHeR1CssxAJTWYlfCz0TbAtKsHQybe5mmrCFLm0RDKPU0Re+JrhvXr7akKhKc5oi+jFT5yukrczh0RyK27X7KOQHOJC2erZlV/gkb4QWLzukhQLI5LyQDf+hT+ZcXaJ42g8D8LZqvJUzhtAn9l7v2LX3+r6agOYEkGNwo4lOyAjj5uUGS/LXh0MC9+Js1ISQmNuco+02/G8WJCLx/oF0nS9e11USvI92knUQa3kxDnRJ8tt31STbs/x1f/Hwg0oe+Jla7kTeoSz9md7HZGuQ+FI6zE8XXlvETwMhAAPZgeVYEpnv6SxzUI
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DS0PR10MB7405.namprd10.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(41320700013)(34036016)(586017)(376014)(34096008)(38070700021)(8096899003)(6133799003)(3023799007)(18002099003)(56012099006);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: bSJswXDsx/4KggEB/QQRNaG4gKiV0Z/FSyTgGo817Z0nZ4pVi4GXBXEzjsJFy5YPllABm/TKnyr8FR3lOtaiq2VlU7v/od2spQCJiWC+s3s1U+owsTW7h1o6tYsxoBaOyBn3pv0TPhO9SnL16CkGfIWO82Dk8fN5Tno4LVmDurCJ3yav7ynX23DzvARucyNQ0jHAnXugnwI0fjvZGrODy4Az+KYJOhtoB0qt9c1uPaiOd82vzkhNn51nnkNHicyyKyzTyJugMGD8oow4nmXeyuylH5kN/oJx9kRINeD7ummPgBrvGj0iyJAdMaREu8XFhzKQwtaAtAT5u/NzYWtu1WutE+FlDSdNdqQl/MWiMpWDb4L+E6AuuPOe1gY8a8cd0CJoog8Vf2t7sScLK/zmSsSIiVvSkIwVlB6Z0yY++/qv/EmFNodCsD1FoA+0UfIsKbAhz0J2xmTufknw41Fl3n+/VSjGbIzPfAryR8sLGOSc01ecgk2VIpkO1D7lsITJd73Hikopu7p/r6aSx99WjvuoqM0EYrDefITehFsICU0BoI2RMxir9PK1G7SNB8itDQsWiCxW9WzTrRQ3S3ChZU+RaotpGeEovwaMwMwvm3VgwyMcYJ/gkqGgB8GgDHvmVqn/2IGxp7+RtHQxPq2zqgEVnLGVbvUQ1yrjODooa6iwM8VVfOvL1GOEhANGQsHIMXXpsDAoFgvltqCSN/fodpPVnsLVPRGe44PI+YiWlH6m9eGpiPPlcsFw5EyTg+h4aoZuuK/HfpvBkxdwoEW3/AkXHV0YgOUh1Y+oqfTVQFCyc23vkJZyHRVbmRrIKlpA2xf5jcN0dCzSF6MnT+5VW73j/7agOUG3WRdaia9WRMmqa/bnWss7hOQxjhL2lidaegGOhYouRX1BeV95PFb1lW3PMo3/t4r2Bm+nJesOWD71nEvIRBhCYE9QnSfZr50Mh1gE9rLqt3oHmriLpB1/woSEn5VOR9Fv/EYibfCef5qkHAvkcMgxIDyUsmuRacpjuXNcFkh73oVtMfehqCSutROzLcEKGSuczetuOgLetjN28RmqPrhYrCrPpXJZgsaeTZeKIT/jQrelKD0ATGOc+9S2YBIRI8Y46tZOx7RjZszl0N2k6iLe4FMP0jD+V+Ri7JTR5ocHZmmGpiwv3ASbDxrzgHtuevqboQp2oF1DFzVWiETVnt9Fj80KjhAwt0VbUKxtzYbSBwQJK8iAFJiMVyIylRkne714sRhidxty6z+ev4ppnftyxCUGNwXh5tmtjIAf7BTPJ5ZVtn+WP/IwEFc0Vy8gnwlMdCluVahdKMTvqLQhPpqADISQ7oCuUHNQIDtav2gKvg5N+Wez319JTkJkTocUwu9pdC2M5FSxYawzkj9NKh0WM3ihvqDhcKRMfBJhxQ+TWuUnHaY3fZE6Vmkk/YbrDrcWbdjk01sFm6hiXeIkSnsG3VKjsm4i8e6Kbxrvu3LeTKZa1lJYGZhJB6eanEyG+Q9ygG8fL/0dAad40YAjA+/93QgPKznDBuGRvutHBvvbW7lZrf9WgNkxo7+7SiGiqmV+U36enM9B1LOH2RGcv+o+gL6c0Q46xiwTcjcWB1t5vUjvtLFVMXku0CikeZzBnHzcXG8+GWf1FvfTGGVd49CCt6bzrp2NjIyC4MNGk0/SvzZK1/t+YiKVUaYjmAPLujiL73YsYatNdTgxMSkoij3Q8OTzuSOqeKpnUUN3SHyNOaoqVz8HzhX6rbAvl3j4qv5v2q+fKx0QOw8=
Content-Type: multipart/alternative; boundary="_000_DS0PR10MB7405ED98E45B92D43790664CDB1F2DS0PR10MB7405namp_"
MIME-Version: 1.0
X-OriginatorOrg: sanctumsecops.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DS0PR10MB7405.namprd10.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2abe553c-c11f-4172-5f35-08dec4d44b30
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jun 2026 20:35:20.6131 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2a93bdd1-b2dd-4327-b526-67840d763136
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: YYN0y8aggTMPqSyCZSrhFAYYu+CRL1JnfO1F1EB8Ik4FI44bzZ/mNw15llrBt7RSuJXuStY/XBGHYnruqsRNHV5BWYaiU8XtqF3maff4UaA=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA1PR10MB5948
Message-ID-Hash: 3HDJR657YEP3BWSOKNB3P3RMKGDXE563
X-Message-ID-Hash: 3HDJR657YEP3BWSOKNB3P3RMKGDXE563
X-MailFrom: bvicente@sanctumsecops.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] [acme] RFC 9773 ARI: Gap in normative guidance on renewal window computation
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/DixxmYI_8BrjRmz8RItFzqI7k-U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>
Hi all,
I'm writing as an implementer of ACME-based certificate lifecycle
management in a multi-tenant PKI environment. I'd like to raise a
gap I've encountered in RFC 9773 (ACME Renewal Information) that
I think warrants either errata consideration or a companion
informational document.
RFC 9773 §4.1 specifies the on-the-wire format for an ACME server
to advertise a suggestedWindow (notBefore / notAfter) to a client.
The mechanism itself is well-defined. However, the RFC is explicitly
silent on how a server SHOULD compute that window. This leaves
implementers with no normative guidance on two operationally
significant factors:
1. Per-CA-mount throughput constraints.
In a multi-tenant or high-volume PKI, multiple certificate
populations may have overlapping ARI renewal windows. If all
clients respond to simultaneously emitted windows, the issuing
CA mount may receive a burst of signing requests that exceeds
its processing capacity, causing issuance failures for relying
systems during what is supposed to be a controlled renewal
cycle. RFC 9773 does not address how a server should stagger
emitted windows to respect per-CA throughput limits, nor does
it recommend any backpressure or concurrency-awareness in
window selection.
2. Dependency ordering between issuing CAs and the certificates
they sign.
In a CA topology with root → intermediate → end-entity
relationships, an end-entity's ARI renewal window should not
fire before its issuing intermediate CA has itself completed
rotation. If an end-entity certificate is reissued under an
intermediate CA that has not yet been rotated to the target
algorithm, the resulting chain may be inconsistent with the
deployment's migration goal. RFC 9773 provides no normative
guidance on how a server should account for signing-chain
dependency ordering when computing suggested windows.
Both of these gaps become particularly relevant in the context of
post-quantum algorithm migration, where large numbers of
certificates across a CA hierarchy must be rotated in a controlled
sequence and the cost of misordering is a broken or
cryptographically inconsistent trust chain.
I'm not proposing a specific computation method in this message.
I'd suggest the working group consider whether a companion
informational document or a section in a future revision could
provide:
(a) SHOULD-level guidance that ARI window computation account
for per-CA issuing capacity constraints, and
(b) SHOULD-level guidance that window computation respect the
topological ordering of the CA hierarchy from which the
certificate descends.
Happy to discuss or contribute text if there is interest.
-Thank You
Brian Vicente
CEO • Sanctum SecOps LLC
Trust. Evidence. Identity.
✉ bvicente@sanctumsecops.com
🌐 sanctumsecops.com
📞 (607) 703-1189
📍 Pine City, New York, USA
- [Acme] [acme] RFC 9773 ARI: Gap in normative guid… Brian Vicente
- [Acme] Re: [acme] RFC 9773 ARI: Gap in normative … Sebastian Robin Nielsen