[saag] ACME @ IETF 126

Mike Ounsworth <[email protected]> Wed, 29 Jul 2026 02:05:05 -0500
Newsgroups gmane.ietf.saag
Message-ID <CAKZgXHpesVy+yBnVV59nsSrL2wGQW8mHk+q8P8n9hdac6sbA1w@mail.gmail.com>
--===============0086227249781740699==
Content-Type: multipart/alternative; boundary="000000000000ecb66c0657ba932a"

--000000000000ecb66c0657ba932a
Content-Type: text/plain; charset="UTF-8"

The following drafts are moving nicely, with some requiring minor chair
actions (WGLCs):

draft-ietf-acme-integrations,
draft-ietf-acme-device-attest,
draft-ietf-acme-authority-token-jwtclaimcon,
draft-ietf-acme-dns-account-label,
draft-ietf-acme-dns-persist,
draft-ietf-acme-profiles, draft-ietf-acme-rats

New Business:
draft-geng-acme-public-key -- there seemed to be positive reaction to a new
pk-01 challenge that A) allows for an alternate to the ASN.1-based CSR in
ACME, and B) allows for support a KEM keys which cannot sign a CSR. Chairs
to start another CfA.

Presentation on the ACME aspects of MTC / PLANTS. Decision to leave the
ACME sections within the PLANT doc, but have regular cross-wg updates.

draft-ar-acme-pqc-tlsjws -- long discussion on how to update the one
sentence in RFC8555 that makes ECDSA-P256 mandatory to implement.

Discussion on how to handle the situation where someone no longer has
access to their account key and should be able to re-do domain validation
and then set a new account key and revoke the old one.

Discussion around support for the SM2 ciphers within ACME.

--000000000000ecb66c0657ba932a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>The following drafts are moving nicely, with some req=
uiring minor chair actions (WGLCs):</div><div><br></div><div>draft-ietf-acm=
e-integrations,</div><div>draft-ietf-acme-device-attest,</div><div>draft-ie=
tf-acme-authority-token-jwtclaimcon,</div><div>draft-ietf-acme-dns-account-=
label,</div><div>draft-ietf-acme-dns-persist,</div><div>draft-ietf-acme-pro=
files,=C2=A0draft-ietf-acme-rats</div><div><br></div><div>New Business:</di=
v><div>draft-geng-acme-public-key -- there seemed to be positive reaction t=
o a new pk-01 challenge that A) allows for an alternate to the ASN.1-based =
CSR in ACME, and B) allows for support a KEM keys which cannot sign a CSR. =
Chairs to start another CfA.</div><div><br></div><div>Presentation on the A=
CME aspects of MTC / PLANTS. Decision to leave the ACME sections within the=
 PLANT doc, but have regular cross-wg updates.</div><div><br></div><div>dra=
ft-ar-acme-pqc-tlsjws -- long discussion on how to update the one sentence =
in RFC8555 that makes ECDSA-P256 mandatory to implement.</div><div><br></di=
v><div>Discussion on how to handle the situation where someone no longer ha=
s access to their account key and should be able to re-do domain validation=
 and then set a new account key and revoke the old one.</div><div><br></div=
><div>Discussion around support for the SM2 ciphers within ACME.</div></div=
>

--000000000000ecb66c0657ba932a--


--===============0086227249781740699==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls
aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHNhYWctbGVhdmVAaWV0Zi5vcmcK

--===============0086227249781740699==--