Articles

How HTTP-01 automated validation works

What is an HTTP-01 challenge?

Automated Certificate Management Environment (ACME) HTTP-01 is a standards-based way to prove control of a domain by serving a short-lived challenge response over HTTP. It can be simple and highly automatable when the target hostname is reachable on port 80, but redirects, load balancers, CDNs, geographic filtering, and multi-perspective validation can change the design.

HTTP-01 is one of the challenge types defined by the Automated Certificate Management Environment (ACME) protocol. Its purpose is domain control validation (DCV), proving that the requester controls the hostname for which a certificate is being requested. The ACME server provides a challenge token, and the ACME client uses that token plus its ACME account key to construct a key authorization. The client makes that response available at a standard URL on the requested hostname:

http://yourdomain.example/.well-known/acme-challenge/<token>

DigiCert retrieves the resource over HTTP on TCP port 80 and verifies that the response contains the expected key authorization. Successful DCV establishes control of the hostname for that validation event; certificate issuance still depends on the certificate product, any required organization validation, CAA checks, approval settings, and other issuance requirements.

How HTTP-01 works, step by step

  1. The ACME client starts an order — the client requests a certificate for one or more fully qualified domain names (FQDNs) using DigiCert ACME credentials and an ACME directory URL.
  2. DigiCert returns an authorization challenge — for a domain that requires dynamic ACME validation, the ACME server returns an HTTP-01 challenge containing a unique token.
  3. The client publishes the challenge response — the client computes the key authorization and serves it at /.well-known/acme-challenge/<token> on the HTTP service for the FQDN being validated.
  4. The client signals that the response is ready — the ACME client tells the ACME server that the challenge resource has been provisioned.
  5. DigiCert validates from the network — DigiCert requests the challenge URL on port 80 and verifies the returned key authorization. For publicly trusted TLS issuance, DigiCert also performs required CAA and multi-perspective checks.
  6. Issuance can proceed — if DCV succeeds and all other validation, policy, and approval requirements are satisfied, DigiCert can issue the certificate. Installation and service reload are separate lifecycle steps handled by the client or automation workflow.

When HTTP-01 is a good fit

HTTP-01 is often a strong choice when the ACME client can control the web server or routing layer, and DigiCert can reliably reach the requested hostname on port 80. It avoids the need to grant the ACME client DNS API credentials and can be straightforward on conventional web-server deployments.

When HTTP-01 is not the right option

Choose another DCV approach when the environment cannot reliably satisfy HTTP-01 requirements. DNS-01 is the standard ACME alternative for wildcard names and is often better suited to environments where validation should be decoupled from web-server routing.

Design requirements that commonly determine success

Why did my HTTP-01 challenge fail?

Start with the network path rather than the certificate request itself. The following checks resolve most HTTP-01 failures:

Frequently asked questions

Does HTTP-01 require port 80 to be open?
Yes, the ACME HTTP-01 validation URL uses HTTP on TCP port 80. The hostname must be reachable from DigiCert validation infrastructure. If your firewall restricts by source IP, use DigiCert's current published validation IP ranges. If policy does not permit HTTP-01 reachability, use another supported DCV method such as DNS-01.
Do I have to disable HTTP-to-HTTPS redirects?
No, redirects are not inherently incompatible with HTTP-01. ACME permits servers to follow redirects, however, a redirect that uses an unsupported status code or destination, loops, is blocked, or prevents retrieval of the expected challenge response will cause validation to fail. Many web-server integrations deliberately exempt the ACME challenge path because it is simple and predictable, but that is an implementation choice rather than a universal protocol requirement.
Can HTTP-01 validate wildcard certificates?
No, standard ACME HTTP-01 cannot validate a wildcard identifier such as *.example.com. Use ACME DNS-01 for wildcard validation.
How does HTTP-01 work behind a load balancer or CDN?
It works when every validation request can retrieve the same expected response. You can distribute the challenge response to all possible backends or configure the routing layer to send /.well-known/acme-challenge/ requests to a centralized responder. If regional edges or origins behave differently, MPIC may expose the inconsistency.
Is HTTP-01 easier to automate than DNS-01?
It depends on the environment. HTTP-01 can be simpler when the ACME client controls the web server and port 80 is reliably reachable. DNS-01 is required for wildcards and often fits centralized, load-balanced, or firewalled architectures better, but it usually requires secure automation of DNS changes and careful handling of DNS API credentials.
What DigiCert IP addresses should I allowlist?
Use only the current IP ranges published in DigiCert documentation for HTTP validation. Do not copy static ranges into long-lived architecture documentation because validation infrastructure can change. Also make sure geographic filtering does not unintentionally block one of the network perspectives used for public-trust validation.
Does DigiCert require DNSSEC?
No, DNSSEC is not required for certificate issuance. However, when DNSSEC is configured for a domain, DigiCert validates it during applicable domain-control and CAA checks. A broken DNSSEC configuration can therefore prevent validation or issuance.

Supplemental resources

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across protected web servers and the rest of your enterprise certificate estate.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert