Compare the state of ACME specifications to the current LetsEncrypt deployment

LetsEncrypt is currently the most important X.509 CA issueing (free) certificates for web servers. Web servers interact with LetsEncrypt via the ACME protocol (RFC8555). Since the basic ACME RFC was published (in 2019) a number of extensions and profiles have been defined by the IETF’s ACME working group. The project here is to survey those and check what is and is not supported by the current LetsEncrypt deployment. In particular, we want to establish what ACME challenge type restrictions are enforced by LetsEncrypt, when it reads the CAA resource record for a domain when issuing wild-card certificates using DNS challenges.