<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-acme-dns-persist" target="https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-01">
   <front>
      <title>Automated Certificate Management Environment (ACME) Challenge for Persistent DNS TXT Record Validation</title>
      <author initials="S." surname="Heurich" fullname="Shiloh Heurich">
         <organization>Fastly</organization>
      </author>
      <author initials="H." surname="Birge-Lee" fullname="Henry Birge-Lee">
         <organization>Crosslayer Labs, Inc.</organization>
      </author>
      <author initials="M." surname="Slaughter" fullname="Michael Slaughter">
         <organization>Amazon Trust Services</organization>
      </author>
      <date month="March" day="23" year="2026" />
      <abstract>
	 <t>   This document specifies &quot;dns-persist-01&quot;, a new validation method for
   the Automated Certificate Management Environment (ACME) protocol.
   This method allows a Certification Authority (CA) to verify control
   over a domain by confirming the presence of a persistent DNS TXT
   record containing CA and account identification information.  This
   method is particularly suited for environments where traditional
   challenge methods are impractical, such as multi-tenant hosting
   platforms, enterprise DNS environments, and IoT deployments.  The
   validation method is designed with a strong focus on security and
   robustness, incorporating widely adopted industry best practices for
   persistent domain control validation.  This design aims to make it
   suitable for Certification Authorities operating under various policy
   environments, including those that align with the CA/Browser Forum
   Baseline Requirements.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-acme-dns-persist-01" />
   
</reference>
