Skip to content

Commit 4c090a2

Browse files
authored
Add new DV method
1 parent b7fd69b commit 4c090a2

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

docs/BR.md

+10
Original file line numberDiff line numberDiff line change
@@ -980,6 +980,16 @@ Except for Onion Domain Names, CAs using this method MUST implement Multi-Perspe
980980

981981
**Note**: Once the FQDN has been validated using this method, the CA MUST NOT issue Certificates for other FQDNs that end with all the labels of the validated FQDN unless the CA performs a separate validation for that FQDN using an authorized method. This method is NOT suitable for validating Wildcard Domain Names.
982982

983+
##### 3.2.2.4.21 DNS Labeled with Account ID - ACME
984+
985+
Confirming the Applicant's control over the FQDN by performing the procedure documented for a “dns-account-01” challenge in draft 00 of “Automated Certificate Management Environment (ACME) DNS Labeled With ACME Account ID Challenge,” available at [https://datatracker.ietf.org/doc/draft-ietf-acme-dns-account-label/](https://datatracker.ietf.org/doc/draft-ietf-acme-dns-account-label/).
986+
987+
The token (as defined in draft 00 of “Automated Certificate Management Environment (ACME) DNS Labeled With ACME Account ID Challenge,” Section 3.1) MUST NOT be used for more than 30 days from its creation. The CPS MAY specify a shorter validity period for the token, in which case the CA MUST follow its CPS.
988+
989+
Except for Onion Domain Names, CAs using this method MUST implement Multi-Perspective Issuance Corroboration as specified in [Section 3.2.2.9](#3229-multi-perspective-issuance-corroboration). To count as corroborating, a Network Perspective MUST observe the same token as the Primary Network Perspective.
990+
991+
**Note**: Once the FQDN has been validated using this method, the CA MAY also issue Certificates for other FQDNs that end with all the Domain Labels of the validated FQDN. This method is suitable for validating Wildcard Domain Names.
992+
983993
#### 3.2.2.5 Authentication for an IP Address
984994

985995
This section defines the permitted processes and procedures for validating the Applicant’s ownership or control of an IP Address listed in a Certificate.

0 commit comments

Comments
 (0)