Re: [Acme] Alternative proposal for fixing TLS-SNI / revisiting HTTPS-01 authorization

2018-01-13 Thread Ilari Liusvaara
On Fri, Jan 12, 2018 at 06:21:00PM +0100, Gerd v. Egidy wrote: > > > I think you also need: > > > > > > - A user is able to trick the server into serving his document root as > > > default vhost > > > > > > - The webserver serves the default tls vhost, even if the CA requested a > > > specific

[Acme] -09 draft: Challenge objects?

2018-01-13 Thread Felipe Gasper
Hello, I’ve been looking over the -09 draft and have created a Perl client module against Pebble as well as LE’s new testing endpoint. I’m curious about whether the specification intends to define Challenge objects. They appear to exist, of course, but they’re not defined as