|
|
|
|
|
by Ayesh
2682 days ago
|
|
ACME protocol is fairly straight forward to implement, and you can easily write your own implementation with existing code (OpenSSL, Apache/nginx, etc). With many commercial registrar's, although they offer a valid and long certificate, their technical aspects aren't very good. Many CAs don't support ECC certificates, the must-staple flag or CT SCTs embedded in the certificate. I work a lot with web PKI, and every time I have to deal with a CA that's not LE or Digicert, I sigh out loud. |
|