%% You should probably cite draft-ietf-acme-star-delegation instead of this I-D. @techreport{sheffer-acme-star-delegation-01, number = {draft-sheffer-acme-star-delegation-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sheffer-acme-star-delegation/01/}, author = {Yaron Sheffer and Diego Lopez and Antonio Pastor and Thomas Fossati}, title = {{An ACME Profile for Generating Delegated STAR Certificates}}, pagetotal = 13, year = 2018, month = nov, day = 13, abstract = {This memo proposes a profile of the ACME protocol that allows the owner of an identifier (e.g., a domain name) to delegate to a third party access to a certificate associated with said identifier. A primary use case is that of a CDN (the third party) terminating TLS sessions on behalf of a content provider (the owner of a domain name). The presented mechanism allows the owner of the identifier to retain control over the delegation and revoke it at any time by cancelling the associated STAR certificate renewal with the ACME CA. Another key property of this mechanism is it does not require any modification to the deployed TLS ecosystem.}, }