Is a 'Location' header required to be in the response to a finalize order request? Section 7.4 of RFC 8555 makes no mention of the 'Location' header like section 7.3 for a new account response, but the example response at the end of Section 7.4 includes it. Likewise, there is no mention of it for new order responses but it is present in the example.
Pebble[1] & Boulder[2] considers it to be in the spec, but some ACME providers (like Buypass.com) do not include the 'Location' in their finalize responses. It seems like it has to be a requirement for new order responses. But for finalize responses it's more of an optimization because the client should know the order location from the order creation response. Cheers, -Ben [1] https://github.com/letsencrypt/pebble/pull/85 [2] https://github.com/letsencrypt/boulder/pull/3336 _______________________________________________ Acme mailing list -- [email protected] To unsubscribe send an email to [email protected]
