An ACME server (or any remote service) whose security policy requires that CA signing keys never leave a local HSM should be able to obtain a Dogtag-signed sub-CA certificate without transferring the private key.
The server generates the key pair on its own HSM, submits the CSR to Dogtag, and receives a signed sub-CA certificate. Dogtag tracks the authority for chain-building and revocation purposes but does not participate in subsequent signing operations.
An ACME server (or any remote service) whose security policy requires that CA signing keys never leave a local HSM should be able to obtain a Dogtag-signed sub-CA certificate without transferring the private key.
The server generates the key pair on its own HSM, submits the CSR to Dogtag, and receives a signed sub-CA certificate. Dogtag tracks the authority for chain-building and revocation purposes but does not participate in subsequent signing operations.