Technical Summary
This document specifies an extension to the Automated Certificate
Management Environment (ACME) protocol which allows an ACME server to
validate the Delay-Tolerant Networking (DTN) Node ID for an ACME
client. The DTN Node ID is encoded as a certificate Subject
Alternative Name (SAN) of type otherName with a name form of
BundleEID and as an ACME Identifier type "bundleEID".
Working Group Summary
This document was developed in support of work in the DTN WG. This draft was originally in IESG review as Experimental in 2021. It was eventually returned to the working group in early 2024 to wait for referenced specifications in DTN WG to be stable. Now, in 2025, all the normative specifications have been completed in the DTN WG.
There is concensus within the ACME WG for this draft.
Document Quality
There aren't any known implementations of this mechanism as of yet.
As the document points out:
| The emergent properties of DTN naming and BP security are still
| being developed and explored, especially between different
| organizational and administrative domains, so the
| "experimental" status of this document is related more to the
| practical utility of this kind of Node ID validation than to
| the validation method itself.
Personnel
Yoav Nir is the document shepherd.
Deb Cooley is the responsible Area Director.