ACME process in Protocol Gateway
The ACME process is made up of the following major steps:
- Create ACME account - The ACME client creates an account on the ACME server.
The ACME service in Protocol Gateway can be configured so that creating ACME accounts either:- is allowed for all requesting clients
- requires a preregistration in Certificate Manager
- Create order - The ACME client requests a certificate by creating an order for certain domain names.
If ACME is configured to require preregistration, then the preregistration can also contain a list of allowed domain names per registration. - Validate challenge - The ACME server verifies that the requested domain names are controlled by the ACME client, by validating a set of server-issued challenges.
- Issue certificate - The ACME service in Protocol Gateway uses Certificate Manager to issue a certificate, using a certificate signing request (CSR) provided by the ACME client.
Manage ACME accounts in Nexus PRIME
The credential management solution Nexus PRIME is planned to implement support for ACME accounts and lifecycle management of certificates from Certificate Manager or from third-party CAs, such as QuoVadis and D-Trust.
Certficates from all CAs will be published to PRIME, to have the complete and seamless lifecycle management in one central system.What is ACME?
Include Page What is ACME? What is ACME?