Configuring ACME Renewal ARI ACME Client

Learn how to configure the AppViewX ACME Client to use ACME Renewal Information (ARI) according to RFC 9773 for dynamic certificate renewal scheduling and retry management.

Overview

Traditionally, certificate renewal with Automated Certificate Management Environment (ACME) clients relies on static cron schedules or fixed threshold days (for example, initiating renewal 30 days before expiration). This static model can create renewal traffic spikes across large certificate fleets and fails to adapt to early revocations, server-side policy changes, or Certificate Authority (CA) maintenance windows.

With ACME ARI (RFC 9773) enabled on the AppViewX ACME Server endpoint, the AppViewX ACME Client dynamically queries the server's renewalInfo endpoint to retrieve a server-suggested renewal window (suggestedWindow.start and suggestedWindow.end) for each managed certificate.

Key advantages of client-side ARI support include:

  • Dynamic Scheduling: Automatically coordinates certificate renewals within the server-recommended window.
  • Smart Retry Handling: Automatically honors the Retry-After duration if an initial renewal attempt fails or if the server requests a deferral.
  • Resilient Fallback: Automatically falls back to standard static expiry threshold monitoring if the ARI endpoint is disabled or unreachable.
Note: A sample config.json file is available for download directly from the AppViewX GUI as part of the client ZIP package.
Tip: The --days parameter functions as a safe fallback. When ARI is enabled, the client prioritizes the server-suggested renewal window. If ARI is unavailable or disabled, the client defaults to the --days value.

Client Renewal Evaluation Logic

Failed Renewal Attempt: The renewal window refreshes only during scheduled cron runs, not immediately when a retry-after windows is over. During the next cron execution, if the retry-after window has elapsed, the system fetches the refreshes the window and the renewal is triggered based on the refreshed window.

When a scheduled renewal job executes, the AppViewX ACME Client evaluates certificate status using the following sequential logic:

  1. ARI Capability Check: The client inspects whether ARI is enabled in the configuration and supported by the server directory (renewalInfo endpoint).
  2. Metadata Retrieval: If cached ARI metadata is absent or stale, the client sends an HTTP GET request to /acme/renewal-info/{certificateID}.
  3. Window Evaluation:
    • Before Window Start: The client skips renewal and logs the next window opening timestamp.
    • Within Window: The client initiates the certificate renewal transaction.
    • Failed Renewal Attempt: If renewal encounters a temporary failure, the client honors the Retry-After interval before re-attempting.
  4. Fallback Execution: If ARI is disabled on the server or the endpoint is unreachable, the client evaluates whether the certificate expiration is within the configured fallbackDays threshold.
  5. Post-Renewal Update: Upon successful renewal, the newly issued certificate and updated ARI metadata are cached locally.