<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-acme-openid-federation" target="https://datatracker.ietf.org/doc/html/draft-ietf-acme-openid-federation-00">
   <front>
      <title>Automatic Certificate Management Environment (ACME) with OpenID Federation 1.0</title>
      <author initials="G." surname="De Marco" fullname="Giuseppe De Marco">
         <organization>independent</organization>
      </author>
      <author initials="B." surname="Pitman" fullname="Brandon Pitman">
         </author>
      <author initials="T." surname="Geoghegan" fullname="Tim Geoghegan">
         <organization>ISRG</organization>
      </author>
      <author initials="D." surname="Cook" fullname="David Cook">
         <organization>ISRG</organization>
      </author>
      <author initials="J." surname="Jones" fullname="J.C. Jones">
         <organization>ISRG</organization>
      </author>
      <date month="December" day="16" year="2025" />
      <abstract>
	 <t>   The Automatic Certificate Management Environment (ACME) protocol
   allows server operators to obtain TLS certificates for their
   websites, based on a demonstration of control over the website&#x27;s
   domain via a fully-automated challenge/response protocol.

   OpenID Federation 1.0 defines how to build a trust infrastructure
   using a trusted third-party model.  It uses a trust evaluation
   mechanism to attest to the possession of private keys, protocol
   specific metadata and miscellaneous administrative and technical
   information related to a specific entity.

   This document defines how X.509 certificates associated with a given
   OpenID Federation Entity can be issued by an X.509 Certification
   Authority through the ACME protocol to the organizations which are
   part of a federation built on top of OpenID Federation 1.0.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-acme-openid-federation-00" />
   
</reference>
