How ACME domain validation works

ACME (Automated Certificate Management Environment) is a standards-based protocol for automating certificate management. It can automate certificate requests, supported domain control validation, issuance, and recurring certificate renewal workflows.

For TLS certificates that require domain control validation (DCV), ACME can automate the proof that the requester controls the domain named in the certificate request. The exact validation flow depends on the challenge method and the certificate authority (CA), certificate type, and the domain's validation status.

What is an ACME challenge?

An ACME challenge is an automated way to prove control of a domain during certificate issuance. It is different from proving legal ownership of a domain, and it is not necessarily the only requirement for certificate issuance.

At a high level, the process is:

  1. Request: an ACME client requests a certificate from an ACME service.
  2. Challenge: the ACME service tells the client which challenge method or methods are available for proving control of the domain.
  3. Prove control: the client makes the required proof available, such as an HTTP challenge file or DNS TXT record.
  4. Verify and issue: the CA independently checks the proof. If domain control and any other applicable issuance requirements are satisfied, the certificate can be issued.

Once the environment is configured for automation, routine ACME issuance and renewal can occur machine-to-machine with little or no manual intervention. Initial setup may still require administrators to configure the ACME client, DNS access, certificate profiles, or network permissions.

Domain validation approaches relevant to ACME automation

The most applicable validation method depends on how the application is exposed, how DNS is managed, whether wildcard certificates are required, and which challenge methods your CA and ACME service support.

How ACME domain validation works

Where DigiCert fits

ACME is an industry protocol, not a DigiCert-specific technology. DigiCert supports ACME as one of several certificate automation methods.

DigiCert Trust Lifecycle Manager provides an ACME automation service for third-party ACME v2 clients. ACME-based certificate profiles define which certificates can be requested and provide the External Account Binding (EAB) credentials the client uses. Trust Lifecycle Manager can work with DigiCert Private CA and supported external issuing CAs through CA connectors.

CertCentral also supports ACME-based certificate automation, including HTTP-01 and DNS-01 domain validation workflows where applicable. For OV and EV certificates, CertCentral may use existing valid domain validation rather than requiring an HTTP-01 or DNS-01 challenge during every ACME request, depending on the domain's validation status and certificate workflow.

The right automation pattern depends on the target platform and architecture. ACME is a strong fit for ACME-capable servers, ingress controllers, Kubernetes environments, and other standards-based clients. In contrast, DigiCert agents, sensors, platform integrations, APIs, or other enrollment protocols may be better suited to those environments.

Supplemental information

Frequently asked questions

What is an ACME challenge, and why is it required?
An ACME challenge is an automated proof-of-control step used when domain control validation is required for a certificate request. The ACME service tells the client what proof is required, the client makes that proof available, and the CA independently verifies it. Successful domain control validation allows issuance to proceed when any other applicable validation, authorization, and approval requirements are also satisfied.
Does DNS-01 require access to my DNS provider API?
The ACME DNS-01 protocol defines the TXT record that must be published. It does not require a specific DNS provider API. For fully automated DNS-01 workflows, however, the ACME client or an integration generally needs a controlled way to create and remove the required DNS record.
Does ACME replace domain control validation?
No, ACME automates supported domain control validation methods and certificate-management interactions. The CA still performs the validation required by the applicable certificate policy and workflow.
Does using ACME mean the certificate is automatically installed?
Not in every implementation. ACME standardizes certificate-management interactions, but installation and deployment depend on the ACME client and target platform. With DigiCert Trust Lifecycle Manager, supported third-party ACME clients are configured locally to request, download, and install certificates on their systems. Other DigiCert automation patterns are available for platforms where ACME is not the best fit.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across protected web servers and the rest of your enterprise certificate estate.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert