Automatic Certificate Management Environment (ACME) automates the provisioning and renewal of TLS certificates.
It is used by the Let's Encrypt CA.
It appears extremely useful for highly-available, secure federated SIP and SIP over the public Internet.
To support automatic provisioning and certificate renewal, server processes (such as SIP proxies and HTTPS servers) need to support one of the mechanisms for Domain Validation in the ACME spec:
The DVSNI method may be a good choice for reSIProcate / repro
One specific concern is that DVSNI validates the names having A/AAAA records. In a SIP environment, there are usually NAPTR and SRV records, they are not currently supported in the ACME spec.