Certificate Lifecycle Service  ·  View 12 of 21  ·  Runtime

A Customer Domain from CNAME to Padlock

Sixteen messages, of which the customer is involved in three, once, for the life of the domain.

Editable source SVG draw.io All views
Tenant admin Order manager Delegation checker ACME client Public CA Route 53 zone ACM and edge Endpoint prober 1. add support.acme-corp.com 2. denylist + tenant policy 3. one CNAME to create 4. delegates to our zone 5. resolve _acme-challenge 6. delegation confirmed 7. place order 8. newOrder 9. dns-01 token 10. publish TXT 11. validates via CNAME 12. certificate + SCTs 13. import and bind 14. TLS handshake 15. serial matches — SERVING 16. domain is live Critical Flow — A Customer Domain from CNAME to Padlock The customer acts once, at step 4. Every renewal for the life of the domain re-enters at step 7, because the delegation the tenant created is permanent and the challenge is answered inside our own zone. v 1.0 · owner Security Platform Architecture · date 2026-09

The flow

  • Policy and denylist checks happen before the customer is asked for anything, so a hostname the platform must refuse is refused immediately rather than after a failed validation.
  • The delegation the tenant creates at step 4 is permanent; every renewal re-enters at step 7 and the tenant is never asked again.
  • The flow does not end at issuance: steps 14 and 15 are the probe confirming the serial is actually being presented at the edge.

Targets

  • Order placed to certificate installed, delegation already in place: p95 ≤ 90 seconds, p99 ≤ 10 minutes — DNS propagation dominates the tail (stated assumption).
  • New domain, delegation created to padlock serving: ≤ 15 minutes p95.

Risks

  • Rate limits at the public CA are per registered domain, so a tenant onboarding many subdomains at once can exhaust a shared budget. Queueing rather than failing is a requirement, not an optimisation.
  • A domain pointed at the platform that should not be — a lookalike or a platform-adjacent name — is refused by denylist before validation, and re-proof of control is required on a cadence rather than trusted indefinitely.