getssl
getssl copied to clipboard
Feature Request: ACME Renewal Information (ARI)
See: https://letsencrypt.org/2023/03/23/improving-resliiency-and-reliability-with-ari.html
Example of a practical use case: https://community.letsencrypt.org/t/2023-06-15-certificate-policies-extension-mismatch/200155/2
Hi @killerbees19
Thanks for posting this - I'd not seen anything about this and it seems like a great feature to implement. I'll look at it after I've fixed the latest couple of issues.
Not to dissuade you from ARI but it is not trivial to implement. And, the specs are young enough to still be evolving. Here's a few recent discussions from the LE Forum Client Dev section
(petercooperjr is an ACME client dev active in the community) https://community.letsencrypt.org/t/thoughts-from-starting-to-play-with-ari/200276
(mholt is principal for caddy) https://community.letsencrypt.org/t/ari-experiences-and-suggestions-submitted-to-ietf/200630
(aarongable is key in ISRG for these specs) https://community.letsencrypt.org/t/can-ari-conforming-clients-be-granted-exemptions-to-relevant-rate-limits/195600/46
Search the forum for other threads
Just fyi Let's Encrypt Staff made announcement today about significant ARI spec changes https://community.letsencrypt.org/t/discontinuing-support-for-acme-clients-using-draft-ietf-acme-ari-01/215126
Hi @githubRover - thanks for that, I am subscribed to the API notification emails but didn't link that announcement to this issue!