How ACME domain validation works
ACME (Automated Certificate Management Environment) is a standards-based protocol for automating certificate management. It can automate certificate requests, supported domain control validation, issuance, and recurring certificate renewal workflows.
For TLS certificates that require domain control validation (DCV), ACME can automate the proof that the requester controls the domain named in the certificate request. The exact validation flow depends on the challenge method and the certificate authority (CA), certificate type, and the domain's validation status.
What is an ACME challenge?
An ACME challenge is an automated way to prove control of a domain during certificate issuance. It is different from proving legal ownership of a domain, and it is not necessarily the only requirement for certificate issuance.
At a high level, the process is:
- Request: an ACME client requests a certificate from an ACME service.
- Challenge: the ACME service tells the client which challenge method or methods are available for proving control of the domain.
- Prove control: the client makes the required proof available, such as an HTTP challenge file or DNS TXT record.
- Verify and issue: the CA independently checks the proof. If domain control and any other applicable issuance requirements are satisfied, the certificate can be issued.
Once the environment is configured for automation, routine ACME issuance and renewal can occur machine-to-machine with little or no manual intervention. Initial setup may still require administrators to configure the ACME client, DNS access, certificate profiles, or network permissions.
Domain validation approaches relevant to ACME automation
The most applicable validation method depends on how the application is exposed, how DNS is managed, whether wildcard certificates are required, and which challenge methods your CA and ACME service support.
- HTTP-01 — a challenge response is made available at an HTTP URL under /.well-known/acme-challenge/. The validation URL must be publicly reachable on TCP port 80. Typical fit: publicly reachable web services where the challenge path can be served reliably. Wildcard validation is not supported.
- DNS-01 — a challenge value is published in a TXT record under _acme-challenge for the domain. The CA validates through DNS rather than connecting to the application server. Automated implementations commonly use DNS API access. Typical fit: firewalled or non-public application servers, load-balanced environments, and wildcard certificates.
Where DigiCert fits
ACME is an industry protocol, not a DigiCert-specific technology. DigiCert supports ACME as one of several certificate automation methods.
DigiCert Trust Lifecycle Manager provides an ACME automation service for third-party ACME v2 clients. ACME-based certificate profiles define which certificates can be requested and provide the External Account Binding (EAB) credentials the client uses. Trust Lifecycle Manager can work with DigiCert Private CA and supported external issuing CAs through CA connectors.
CertCentral also supports ACME-based certificate automation, including HTTP-01 and DNS-01 domain validation workflows where applicable. For OV and EV certificates, CertCentral may use existing valid domain validation rather than requiring an HTTP-01 or DNS-01 challenge during every ACME request, depending on the domain's validation status and certificate workflow.
The right automation pattern depends on the target platform and architecture. ACME is a strong fit for ACME-capable servers, ingress controllers, Kubernetes environments, and other standards-based clients. In contrast, DigiCert agents, sensors, platform integrations, APIs, or other enrollment protocols may be better suited to those environments.
Supplemental information
Frequently asked questions
Ready to evaluate your environment?
See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across protected web servers and the rest of your enterprise certificate estate.