See below inline, thanks.

 

From: Jacob Hoffman-Andrews [mailto:[email protected]] 
Sent: Tuesday, August 16, 2016 12:35 AM
To: J.C. Jones <[email protected]>; Andy Ligg <[email protected]>
Cc: [email protected]
Subject: Re: [Acme] Add a special token parameter in ACME registration

 

One possibility would to make it the client's responsibility to request EV
by including the desired O, OU, etc. fields in the Subject DN of the CSR. It
would then be the server's responsibility to accept or reject the request
based on whether the account has a sufficient validation level (and
payment).



A: StartCom issued the certificate not based on CSR info, we don't care
about the info in the CSR, we issue the certificate based on this account
validated level and validated identity information. This mode don't work,
CSR is not enough to identify the certificate type.


One of the big open questions in ACME is how paid CAs will manage the
connection between existing accounts and accounts as defined by ACME. It
sounds like that's a need you're likely to have. Do you have any particular
ideas about how you'd like to manage it?

A: Yes, our API call is the same way as ACME registration - using client
certificate for authentication. In my last email, we need to add a API Token
in the ACME registration, then all are OK for paid CA.
Sure, if the paid CA is not this way but like to use ACME, then they need to
change the API system.

Thanks.

Andy 

 

On 08/15/2016 08:53 AM, J.C. Jones wrote:

Hi Andy,

I'm not sure I follow exactly what the format of this token would be, or
what message(s) in the protocol you'd like to add it to. Perhaps you can
make some specific recommendations - even if they're tentative examples -
for the WG to look at and reason through?

Thanks!

J.C.

 

On Sun, Aug 14, 2016 at 9:10 PM, Andy Ligg <[email protected]
<mailto:[email protected]> > wrote:

Hi all,

StartCom plan to use ACME protocol for StartEncrypt, we need to identify the
client's validation level, so the subscriber administration can generate a
special token in the StartSSL.com account that send this token to the email
address used in the ACME registration.

At the registration, user need to enter email and this token with the
certificate to let the CA system know this customer's validation level.
After the CA system receive the email, the token and signing certificate, CA
system know what type of certificate we can issue to this client; if this
client account is class 4 validated, then the client can get EV SSL
certificate, not DV SSL.
please add this a parameter to the ACME protocol, thanks.

Best Regards,

Andy Ligg
StartCom
_______________________________________________
Acme mailing list
[email protected] <mailto:[email protected]> 
https://www.ietf.org/mailman/listinfo/acme

 






_______________________________________________
Acme mailing list
[email protected] <mailto:[email protected]> 
https://www.ietf.org/mailman/listinfo/acme

 

_______________________________________________
Acme mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/acme

Reply via email to