Definition · TLS & Certificates
What is ACME?
ACME (Automatic Certificate Management Environment) is the protocol, defined in RFC 8555, that automates the entire lifecycle of TLS certificates — requesting, validating domain control, issuing, and renewing — without human intervention. It was developed for Let’s Encrypt and is now supported by most major certificate authorities.
How ACME works
An ACME client (such as Certbot, acme.sh, or Caddy’s built-in client) registers with a certificate authority, requests a certificate for one or more domains, and proves control of each domain by completing a challenge:
- HTTP-01 — serve a specific token at
http://example.com/.well-known/acme-challenge/ - DNS-01 — publish a specific TXT record at
_acme-challenge.example.com; required for wildcard certificates - TLS-ALPN-01 — present a special self-signed certificate during a TLS handshake on port 443
Once validated, the CA issues the certificate, and the client renews it automatically before expiry.
Why ACME matters
Before ACME, certificates were purchased and installed manually, and expiry-related outages were routine. Automation made short-lived certificates practical — Let’s Encrypt certificates last 90 days — which limits the damage from key compromise and mistaken issuance. Industry rules are progressively shortening maximum certificate lifetimes, making automated renewal via ACME effectively mandatory.
Related concepts
Domain owners can restrict which CAs may issue for their domains using CAA records, and every ACME issuance is publicly recorded in Certificate Transparency logs.