IoT News

GMO GlobalSign enhances ACME service for internal domain certificates

July 17, 2024

Posted by: Magda Dabrowska

Website hosting concept with domains

Image by Freepik

GMO GlobalSign has announced updates to its Automated Certificate Management Environment (ACME) service for internal domain certificates, enabling customers to issue GlobalSign IntranetSSL certificates through its ACME service.

ACME is an internet protocol designed to enable enterprises to communicate with a CA like GlobalSign to automate important lifecycle functions for TLS certificates at a low cost and high speed. With the introduction of this upgrade, GMO GlobalSign is unlocking the ability to issue certificates via ACME for internal/non-public domains using unofficial domain suffixes, such as .internal or .lan. Organisations might use these internal domains for development networks or other non-production environments; they are also used for private device networks and Active Directory domains, though recommended practice for AD domains is to use a subdomain of a publicly registered domain controlled by your organisation.

“Some users choose self-signed certificates, however, that requires an understanding of your organisation’s Public Key Infrastructure (PKI), but not every business employs these specialists,” said Julie Gaunt, the product manager at GMO GlobalSign. “Because we are a publicly trusted, WebTrust audited certificate authority, we have domain expertise that is now being paired with ACME. By automating the issuance and renewal of non-public TLS certificates, organisations can be confident that internal endpoints will maintain encryption standards and meet internal compliance mandates, preventing unauthorized access, data breaches and potential disruptions to operations.”

Further updates to GlobalSign ACME service include subdomain validation re-use, support of the ACME KeyChange endpoint and backend ACME Nonce updates. By using ACME’s inbuilt capabilities, subdomain validation reuse removes the requirement for domain validation for subdomains so long as the parent domain has already been verified. In addition, the ACME Nonce update enables our ACME service to handle more certificate requests than ever before. In total, these updates will better serve our customers and improve user experience.

Comment on this article below or via X: @IoTGN and visit our website IoT Global Network