Hi,

[apologies if this question duplicates the earlier thread "Issue: Allow ports other than 443"]

I was wondering whether people have considered services running on a port other than port 443; in particular, ports greater than 1024.

One particular use-case is that some services run on a higher port as they can (more easily) run as a non-root user, limited the danger if the service is compromised.

As I understand it, Domain Validated certificates provide an assurance about the DNS name of the asserted identity. It specifically makes no claim who is running the service.

Therefore, there seems no reason to limit ACME to the traditionally secure port number.

Cheers,

Paul.

_______________________________________________
Acme mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/acme

Reply via email to