Skip to content

Commit 9a89c33

Browse files
authored
dns-persist has been adopted by the WG, switch link (#2089)
Link to the rendered html of the current draft, as adopted by the WG, instead of the previous individual draft.
1 parent 5ce2811 commit 9a89c33

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

content/en/post/2025-12-02-from-90-to-45.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
author: Matthew McPherrin
3-
date: 2025-12-02T00:00:00Z
3+
date: 2025-12-03T00:00:00Z
44
slug: from-90-to-45
55
title: "Decreasing Certificate Lifetimes to 45 Days"
66
excerpt: "Improving security for active and revoked certificates."
@@ -44,7 +44,7 @@ For many of our users, the hardest part of automatically issuing certificates is
4444

4545
All validation methods today require that the ACME client have live access to your infrastructure, either to serve the correct HTTP-01 token, perform the right TLS-ALPN-01 handshake, or update the right DNS-01 TXT record. For a long time, people have wanted a way to run an ACME client without granting it access to these sensitive systems.
4646

47-
These challenges are why we are working with our partners at the CA/Browser Forum and IETF to standardize a new validation method called [DNS-PERSIST-01](https://datatracker.ietf.org/doc/html/draft-sheurich-acme-dns-persist-01). The key advantage of this new method is that the DNS TXT entry used to demonstrate control does not have to change every renewal.
47+
These challenges are why we are working with our partners at the CA/Browser Forum and IETF to standardize a new validation method called [DNS-PERSIST-01](https://www.ietf.org/archive/id/draft-ietf-acme-dns-persist-00.html). The key advantage of this new method is that the DNS TXT entry used to demonstrate control does not have to change every renewal.
4848

4949
This means you can set up the DNS entry once and begin automatically renewing certificates without needing a way to automatically update DNS. This should allow even more people to automate their certificate renewals. It will also reduce reliance on authorization reuse, since the DNS records can stay unchanged without any further ACME client involvement.
5050

0 commit comments

Comments
 (0)