Is a 'Location' header required to be in the response to a finalize
order request? Section 7.4 of RFC 8555 makes no mention of the
'Location' header like section 7.3 for a new account response, but the
example response at the end of Section 7.4 includes it. Likewise, there
is no mention of it for new order responses but it is present in the
example.

Pebble[1] & Boulder[2] considers it to be in the spec, but some ACME
providers (like Buypass.com) do not include the 'Location' in their
finalize responses. It seems like it has to be a requirement for new
order responses. But for finalize responses it's more of an optimization
because the client should know the order location from the order
creation response.

Cheers,
-Ben


[1] https://github.com/letsencrypt/pebble/pull/85
[2] https://github.com/letsencrypt/boulder/pull/3336

_______________________________________________
Acme mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to