Hello Chris,
> No, I am proposing we decouple Domain Validation checks from the certificate management. If you make it a requirement of certificate management, then that essentially forces only the ACME implementation, which as we've discussed is very challenging for non-HTTP use cases.
We are talking about using domain validated certificates in ALIII. As the name implies, these certificates require the domain to be validated as part of issuance. So, in order to automate certificate issuance (part of certificate management); domain validation must be automated. So if this standard is going to describe a mechanism for certificate management, must it not also describe a mechanism for domain validation?
> De-coupling it allows for more flexibility in both the Domain Validation and certificate management mechanisms that can be used.
> Bear in mind, most Public CA's already enforce Domain Validation checks even for certificates that are manually issued, see the below screenshot from Sectigo
Which of the domain validation mechanisms Sectigo supports would solve the challenges you described?
-
DNS CNAME - How do the challenges you described about dns-01 not apply to this?
-
DNS TXT - How do the challenges you described about dns-01 not apply to this?
-
Email - How would this be automated?
-
HTTP(s) - How do the challenges you described about http-01 not apply to this?
-
For dns-01, your concern was that there is not a widely used and standards-based mechanism for DNS updates, so implementations have to use proprietary APIs. I agree with this concern. But your solution to this problem appears to be to make the entire domain validation mechanism proprietary. How does that help?
> So my proposal would be to specify the requirement for Domain Validation checks between PA and CA, but not make them part of the certificate management automation mechanism itself.
Can you please elaborate? What would the PA's role in domain validation be? What about the service provider, are you saying they wouldn't be involved in domain validation? How specifically are you proposing that domain validation be performed?
Sincerely,
Alec Fenichel
Chief Technology Officer