Definition · TLS & Certificates

What is ACME?

ACME (Automatic Certificate Management Environment) is the protocol, defined in RFC 8555, that automates the entire lifecycle of TLS certificates — requesting, validating domain control, issuing, and renewing — without human intervention. It was developed for Let’s Encrypt and is now supported by most major certificate authorities.

How ACME works

An ACME client (such as Certbot, acme.sh, or Caddy’s built-in client) registers with a certificate authority, requests a certificate for one or more domains, and proves control of each domain by completing a challenge:

  • HTTP-01 — serve a specific token at http://example.com/.well-known/acme-challenge/
  • DNS-01 — publish a specific TXT record at _acme-challenge.example.com; required for wildcard certificates
  • TLS-ALPN-01 — present a special self-signed certificate during a TLS handshake on port 443

Once validated, the CA issues the certificate, and the client renews it automatically before expiry.

Why ACME matters

Before ACME, certificates were purchased and installed manually, and expiry-related outages were routine. Automation made short-lived certificates practical — Let’s Encrypt certificates last 90 days — which limits the damage from key compromise and mistaken issuance. Industry rules are progressively shortening maximum certificate lifetimes, making automated renewal via ACME effectively mandatory.

Domain owners can restrict which CAs may issue for their domains using CAA records, and every ACME issuance is publicly recorded in Certificate Transparency logs.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.