RFC 8739: Support for Short-Term, Automatically Renewed (STAR) Certificates in the Automated Certificate Management Environment (ACME)
Recent RFCs 2020-03-11
Summary:
Public key certificates need to be revoked when they are compromised,
that is, when the associated private key is exposed to an
unauthorized entity. However, the revocation process is often
unreliable. An alternative to revocation is issuing a sequence of
certificates, each with a short validity period, and terminating the
sequence upon compromise. This memo proposes an Automated
Certificate Management Environment (ACME) extension to enable the
issuance of Short-Term, Automatically Renewed (STAR) X.509
certificates.