Certificate Authority
CMU is transitioning its Certificate Authority service from a manual process to the Automated Certificate Management Environment (ACME) protocol. While certificates currently have longer lifecycles, their duration is moving to 100 days and will eventually decrease to 45 days. The current manual process (which requires generating a Certificate Signing Request (CSR) and submitting it to the ISO for verification) becomes unsustainable.
Starting in mid-July, CMU server administrators can use the ACME protocol via certproxy to completely automate the certificate request, issuance, and renewal process. Because the process is automated through a central university account, individual email notifications for upcoming expirations will no longer be sent; administrators must rely on their ACME client's built-in monitoring features.
Key Features
- Touch-Free Management: Leverage ACME clients to automatically build, submit, and renew certificate requests without manual intervention.
- Automated Validation: Uses an HTTP-01 challenge via a dedicated certproxy to verify domain ownership in seconds.
- Native Integration: Supported by popular clients like Certbot, acme.sh, and Simple-ACME for automated installation on Apache, Nginx, and IIS.
- Self-Service Modality: Standardized protocol allows users to manage their own certificate lifecycles directly from their servers.
Eligibility
Any CMU user with a registered server (NetReg or SCS RAMS) or demonstrated administrative control over a university domain
Fees
None
Request
ACME Request Form (TBD)