id: tls-sources
title: A certificate comes from somewhere other than this server's own ACME client
status: open
crates: [didbot-serve]
dependsOn: [agent-accounts]
exitCriterion: >
A deployment serves agent hostnames over TLS from a certificate this server
did not obtain, swaps it without a restart or a dropped connection, and says
which source produced the one it is serving. #
Obtaining a wildcard over ACME DNS-01 is the default and should stay the
default: it needs no operator, renews itself, and works with the zone
credential the deployment already holds. It is not the only place a
certificate can come from, and some of the alternatives are what a deployment
with an existing PKI actually has.
The deliverable is the seam first and the implementations second, the same
way DnsProvider is the seam under
dns-providers. A certificate source has to answer three
things: produce a certificate now, say when it should next be replaced, and
hand over a replacement without interrupting anything.