Skip to content

Commit

Permalink
Add explanation on implementation consideration (#28)
Browse files Browse the repository at this point in the history
  • Loading branch information
daknob authored Sep 7, 2023
1 parent 1c4af1a commit 5f35544
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions draft-ietf-acme-dns-account-01.mkd
Original file line number Diff line number Diff line change
Expand Up @@ -182,6 +182,8 @@ If the server is unable to find a `TXT` record for the validation domain name, i

As this challenge creates strong dependency on the `kid` account identifier, the server SHOULD ensure that the account identifier is not changed during the lifetime of the account.

If this change occurs, the existing long-term `CNAME` records created by all account holders will no longer be valid. The clients will not be able to issue certificates automatically moving forward.

# Security Considerations

As this challenge that is introduced only differs in the left-most label of the domain name from the existing `dns-01` challenge, the same security considerations apply.
Expand Down

0 comments on commit 5f35544

Please sign in to comment.