ACME and Validation

The ACME Protocol and Domain Validation

ACME (RFC 8555) is the JSON-over-HTTPS protocol between a client such as Certbot 1,690 and a CA: register an account key, order names, prove control of each, send a signing request, download the chain.

An ACME order validated with the http-01 challenge
An ACME order validated with the http-01 challenge

Three challenge types are in use. http-01 serves a token at /.well-known/acme-challenge/<token> on port 80 and cannot prove a wildcard. dns-01 publishes a TXT record at _acme-challenge.<name>, covers wildcards and unreachable servers, and needs your DNS provider's API. tls-alpn-01 answers on port 443 with a special certificate; mod_md and Caddy 7,400 use it. The CA checks from several network locations, which is why the test run's access log shows each token fetched two or three times by LetsEncrypt-Pebble-VA.