Movatterモバイル変換


[0]ホーム

URL:


Internet Assigned Numbers Authority

Automated Certificate Management Environment (ACME) Protocol

Created
2019-01-02
Last Updated
2025-11-25
Available Formats

XML

HTML

Plain text

Registries Included Below

ACME Account Object Fields

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
Field NameField TypeRequestsReference
statusstringnew, account[RFC8555]
contactarray of stringnew, account[RFC8555]
externalAccountBindingobjectnew[RFC8555]
termsOfServiceAgreedbooleannew[RFC8555]
onlyReturnExistingbooleannew[RFC8555]
ordersstringnone[RFC8555]
delegationsstringnone[RFC9115]

ACME Order Object Fields

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
Field NameField TypeConfigurableReference
statusstringfalse[RFC8555]
expiresstringfalse[RFC8555]
identifiersarray of objecttrue[RFC8555]
notBeforestringtrue[RFC8555]
notAfterstringtrue[RFC8555]
errorstringfalse[RFC8555]
authorizationsarray of stringfalse[RFC8555]
finalizestringfalse[RFC8555]
certificatestringfalse[RFC8555]
auto-renewalobjecttrue[RFC8739]
star-certificatestringfalse[RFC8739]
allow-certificate-getbooleantrue[RFC9115]
delegationstringtrue[RFC9115]
replacesstringtrue[RFC9773]

ACME Authorization Object Fields

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
Field NameField TypeConfigurableReference
identifierobjecttrue[RFC8555]
statusstringfalse[RFC8555]
expiresstringfalse[RFC8555]
challengesarray of objectfalse[RFC8555]
wildcardbooleanfalse[RFC8555]
subdomainAuthAllowedbooleanfalse[RFC9444]

ACME Error Types

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
TypeDescriptionReference
accountDoesNotExistThe request specified an account that does not exist[RFC8555]
alreadyRevokedThe request specified a certificate to be revoked that has already been revoked[RFC8555]
badCSRThe CSR is unacceptable (e.g., due to a short key)[RFC8555]
badNonceThe client sent an unacceptable anti-replay nonce[RFC8555]
badPublicKeyThe JWS was signed by a public key the server does not support[RFC8555]
badRevocationReasonThe revocation reason provided is not allowed by the server[RFC8555]
badSignatureAlgorithmThe JWS was signed with an algorithm the server does not support[RFC8555]
caaCertification Authority Authorization (CAA) records forbid the CA from issuing a certificate[RFC8555]
compoundSpecific error conditions are indicated in the "subproblems" array[RFC8555]
connectionThe server could not connect to validation target[RFC8555]
dnsThere was a problem with a DNS query during identifier validation[RFC8555]
externalAccountRequiredThe request must include a value for the "externalAccountBinding" field[RFC8555]
incorrectResponseResponse received didn't match the challenge's requirements[RFC8555]
invalidContactA contact URL for an account was invalid[RFC8555]
malformedThe request message was malformed[RFC8555]
orderNotReadyThe request attempted to finalize an order that is not ready to be finalized[RFC8555]
rateLimitedThe request exceeds a rate limit[RFC8555]
rejectedIdentifierThe server will not issue certificates for the identifier[RFC8555]
serverInternalThe server experienced an internal error[RFC8555]
tlsThe server received a TLS error during validation[RFC8555]
unauthorizedThe client lacks sufficient authorization[RFC8555]
unsupportedContactA contact URL for an account used an unsupported protocol scheme[RFC8555]
unsupportedIdentifierAn identifier is of an unsupported type[RFC8555]
userActionRequiredVisit the "instance" URL and take actions specified there[RFC8555]
autoRenewalCanceledThe short-term certificate is no longer available because the auto-renewal Order has been explicitly canceled by the IdO[RFC8739]
autoRenewalExpiredThe short-term certificate is no longer available because the auto-renewal Order has expired[RFC8739]
autoRenewalCancellationInvalidA request to cancel an auto-renewal Order that is not in state "valid" has been received[RFC8739]
autoRenewalRevocationNotSupportedA request to revoke an auto-renewal Order has been received[RFC8739]
unknownDelegationAn unknown configuration is listed in the delegation attribute of the order request[RFC9115]
onionCAARequiredThe CA only supports checking the CAA for Hidden Services in-band, but the client has not provided an in-band CAA[RFC9799]
alreadyReplacedThe request specified a predecessor certificate that has already been marked as replaced[RFC9773]

ACME Resource Types

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
Field NameResource TypeReference
newNonceNew nonce[RFC8555]
newAccountNew account[RFC8555]
newOrderNew order[RFC8555]
newAuthzNew authorization[RFC8555]
revokeCertRevoke certificate[RFC8555]
keyChangeKey change[RFC8555]
metaMetadata object[RFC8555]
renewalInfoRenewalInfo object[RFC9773]

ACME Directory Metadata Fields

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
Field NameField TypeReference
termsOfServicestring[RFC8555]
websitestring[RFC8555]
caaIdentitiesarray of string[RFC8555]
externalAccountRequiredboolean[RFC8555]
auto-renewalobject[RFC8739]
delegation-enabledboolean[RFC9115]
allow-certificate-getboolean[RFC9115]
subdomainAuthAllowedboolean[RFC9444]
onionCAARequiredboolean[RFC9799]

ACME Identifier Types

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
LabelReference
dns[RFC8555]
ip[RFC8738]
email[RFC8823][RFC-ietf-emailcore-rfc5321bis-43][RFC6531]
TNAuthList[RFC9448]
bundleEID[RFC9891]
NfInstanceId[3GPP TS 33.310]

ACME Validation Methods

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC8555]
Available Formats

CSV
LabelIdentifier TypeACMEReference
http-01dnsY[RFC8555]
dns-01dnsY[RFC8555]
tls-sni-01RESERVEDN[RFC8555]
tls-sni-02RESERVEDN[RFC8555]
http-01ipY[RFC8738]
tls-alpn-01ipY[RFC8738]
tls-alpn-01dnsY[RFC8737]
email-reply-00emailY[RFC8823]
tkauth-01TNAuthListY[RFC9447]
onion-csr-01dnsY[RFC9799]
bp-nodeid-00bundleEIDY[RFC9891]
tkauth-01NfInstanceIdY[3GPP TS 33.310]

ACME Order Auto-Renewal Fields

Registration Procedure(s)
Specification Required
Expert(s)
Yaron Sheffer, Diego R. Lopez, Thomas Fossati, Aaron Gable
Reference
[RFC8739]
Available Formats

CSV
Field NameField TypeConfigurableReference
start-datestringtrue[RFC8739]
end-datestringtrue[RFC8739]
lifetimeintegertrue[RFC8739]
lifetime-adjustintegertrue[RFC8739]
allow-certificate-getbooleantrue[RFC8739]

ACME Directory Metadata Auto-Renewal Fields

Registration Procedure(s)
Specification Required
Expert(s)
Yaron Sheffer, Diego R. Lopez, Thomas Fossati, Aaron Gable
Reference
[RFC8739]
Available Formats

CSV
Field NameField TypeReference
min-lifetimeinteger[RFC8739]
max-durationinteger[RFC8739]
allow-certificate-getboolean[RFC8739]

STAR Delegation CSR Template Extensions

Registration Procedure(s)
Specification Required
Expert(s)
Yaron Sheffer, Diego R. Lopez, Thomas Fossati, Aaron Gable
Reference
[RFC9115]
Available Formats

CSV
Extension NameExtension Syntax and ReferenceMapping to X.509 Certificate Extension
keyUsage[RFC9115, Appendix A][RFC5280, Section 4.2.1.3]
extendedKeyUsage[RFC9115, Appendix A][RFC5280, Section 4.2.1.12]
subjectAltName[RFC9115, Appendix A][RFC5280, Section 4.2.1.6] (note that only specific name formats are allowed: URI, DNS name, email address)

ACME Authority Token Challenge Types

Registration Procedure(s)
Specification Required
Expert(s)
Mary Barnes, Aaron Gable
Reference
[RFC9447]
Available Formats

CSV
LabelDescriptionReference
atcJSON Web Token (JWT) challenge type[RFC9447]

ACME RenewalInfo Object Fields

Registration Procedure(s)
Specification Required
Expert(s)
Richard Barnes, Aaron Gable
Reference
[RFC9773]
Available Formats

CSV
Field NameField TypeReference
suggestedWindowobject[RFC9773]
explanationURLstring[RFC9773]

[8]ページ先頭

©2009-2026 Movatter.jp