Built-in ACME Client

bbp
bbp Posts: 68  Ally Member
First Answer First Comment Friend Collector Fifth Anniversary

As you know, CA/B Forum has voted to shorten validity period for SSL/TLS certificates.

Current:
Public SSL/TLS certificates currently have a maximum validity of 13 months (approximately 398 days).

Upcoming Changes:
2026: Maximum validity will be reduced to 200 days.
2027: Maximum validity will be further reduced to 100 days.
2029: Maximum validity will be 1.5 months (approximately 47 days).

With shorter validity periods, automation will be the key, therefore ACME client (Certbot, etc) in Zyxel uOS is paramount to efficient and secure management.

This should be integrated rather sooner than later.

1 votes

Active · Last Updated

Comments

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,116  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @bbp ,

    Thank you for sharing this information.

    Please note that our certificates are self-signed by default, not a public Certificate Authority (CA).

    In other words, if there is such an application, it is applied in the public CA, not through the Firewall.

  • bbp
    bbp Posts: 68  Ally Member
    First Answer First Comment Friend Collector Fifth Anniversary

    Yes, but many organizations are using CA signed and issued certificates for their assets like routers, switches, printers, etc. Installing certificates once per year is not a problem, but doing that manually every 47 days is not feasible. We need "Automatic Certificate Management Environment" (ACME) for renewal and installation of certificates.

    There are great many open source ACME clients that could easily be implemented into uOS.

    ACME info: https://datatracker.ietf.org/doc/html/rfc8555

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,116  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @bbp ,

    Thank you for your feedback. We will evaluate this feature.