ATIS/SIP Forum IP-NNI Task Force

 View Only
  • 1.  [External] : ALIII Certs

    Posted 8 hours ago
    Oracle Confidential

    Hi Alec,

        "Are you saying we should just skip domain validation?"

    No, I am proposing we decouple Domain Validation checks from the certificate management. If you make it a requirement of certificate management, then that essentially forces only the ACME implementation, which as we've discussed is very challenging for non-HTTP use cases.

    De-coupling it allows for more flexibility in both the Domain Validation and certificate management mechanisms that can be used.

    Bear in mind, most Public CA's already enforce Domain Validation checks even for certificates that are manually issued, see the below screenshot from Sectigo:

    So my proposal would be to specify the requirement for Domain Validation checks between PA and CA, but not make them part of the certificate management automation mechanism itself.

    Regards,

    -

    Chris Telford
    Solutions Architect

    Oracle Communications

    chris.telford@oracle.com

    : 44.207.562.5645



    Oracle Confidential