Currently, we called it as API token if you want to use StartAPI, it is a 
string like this: tk_dc09cfc9aff5409ea98227e212858669.

We use this API Token together with the API authentication certificate to call 
our API.

So if we can add this API Token in the ACME registration, then we can bind this 
customer to his/her StartSSL account, then we know his/her account validation 
level to issue the correct validation level SSL certificate. If his/her account 
is Class 4 validation, then we can issue EV SSL certificate. 

No more change need in ACME protocol, but for more flexible, we can add a cert 
type parameter to let the Class 4 validation subscriber can choose to issue EV 
SSL, OV SSL and DV SSL.

 

Please advise, thanks.

 

Andy

 

 

From: J.C. Jones [mailto:[email protected]] 
Sent: Monday, August 15, 2016 11:53 PM
To: Andy Ligg <[email protected]>
Cc: [email protected]
Subject: Re: [Acme] Add a special token parameter in ACME registration

 

Hi Andy,

I'm not sure I follow exactly what the format of this token would be, or what 
message(s) in the protocol you'd like to add it to. Perhaps you can make some 
specific recommendations - even if they're tentative examples - for the WG to 
look at and reason through?

Thanks!

J.C.

 

On Sun, Aug 14, 2016 at 9:10 PM, Andy Ligg <[email protected] 
<mailto:[email protected]> > wrote:

Hi all,

StartCom plan to use ACME protocol for StartEncrypt, we need to identify the 
client's validation level, so the subscriber administration can generate a 
special token in the StartSSL.com account that send this token to the email 
address used in the ACME registration.

At the registration, user need to enter email and this token with the 
certificate to let the CA system know this customer's validation level.
After the CA system receive the email, the token and signing certificate, CA 
system know what type of certificate we can issue to this client; if this 
client account is class 4 validated, then the client can get EV SSL 
certificate, not DV SSL.
please add this a parameter to the ACME protocol, thanks.

Best Regards,

Andy Ligg
StartCom
_______________________________________________
Acme mailing list
[email protected] <mailto:[email protected]> 
https://www.ietf.org/mailman/listinfo/acme

 

_______________________________________________
Acme mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/acme

Reply via email to