RFC 8739: Support for Short-Term, Automatically Renewed (STAR) Certificates in the Automated Certificate Management Environment (ACME)
In plain English — editorial summary, not part of the RFC
Public key certificates need to be revoked when they are compromised, that is, when the associated private key is exposed to an unauthorized entity. However, the revocation process is often unreliable. An alternative to revocation is issuing a sequence of certificates, each with a short validity period, and terminating the sequence upon compromise. This memo proposes an Automated Certificate Management Environment (ACME) extension to enable the issuance of Short-Term, Automatically Renewed (STAR) X.509 certificates.
Document record
- Document ID
- RFC8739
- Published
- March 2020
- Authors
- Y. Sheffer; D. Lopez; O. Gonzalez de Dios; A. Pastor Perales; T. Fossati
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 22
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4490Using the GOST 28147-89, GOST R 34.11-94, GOST R 34.10-94, and GOST R 34.10-2001 Algorithms with Cryptographic Message Syntax (CMS)Current
May 2006
- RFC 9770Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
June 2025
- RFC 9919The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume EnvironmentsCurrent
July 2026
- RFC 6961The Transport Layer Security (TLS) Multiple Certificate Status Request ExtensionObsoleted
June 2013
- RFC 6960X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSPUpdated
June 2013
- RFC 6664S/MIME Capabilities for Public Key DefinitionsCurrent
July 2012
- RFC 6277Online Certificate Status Protocol Algorithm AgilityObsoleted
June 2011
- RFC 5019The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume EnvironmentsObsoleted
September 2007
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?