Create ACME automation profiles
To create a certificate profile in Trust Lifecycle Manager, you start with a base template and customize it for your organization's digital trust needs.
Available base templates
To find base templates that support ACME, look for 3rd-party ACME client integration in the Use cases column on the Policies > Base templates page in Trust Lifecycle Manager. Available templates include those in the following table.
Create an ACME-based certificate profile
To create an ACME-based certificate profile in Trust Lifecycle Manager:
From the Trust Lifecycle Manager menu, go to Policies > Certificate profiles.
Select the Create profile from template button.
Select one of the base templates in the preceding table as the basis for creating the ACME-based profile.
Work through the profile creation wizard, focusing on the ACME-related options described below and making other selections for your business needs. After filling out each screen, select Next to move to the next screen.
Under Primary options:
Connector: If the template you selected requires a CA connector, select the specific connector to use.
Issuing CA: Select the certificate authority (CA) that will issue the certificates.
Enrollment method: Select
3rd-party ACME client.
Under Certificate options and Extensions (if applicable), configure certificate properties including validity lengths.
Under Additional options and Advanced settings (if applicable), configure email communications settings for certificate lifecycle event notifications, and optional metadata to help identify and manage certificates issued from this profile.
Applicable wizard screens and options depend on your starting template and the selections you make on each screen.
On the final wizard screen, select Create to save the new certificate profile and generate the ACME credentials for it. The ACME URL and EAB credentials popup window launches, showing the following fields:
ACME Directory URL: Base URL to use for requesting certificates via ACME. For hosted DigiCert ONE accounts, this should be
https://one.digicert.com/mpki/api/v1/acme/v2/directoryKID: The key identifier associated with your new ACME-based certificate profile.
HMAC key: Used to authenticate ACME clients during account creation on the Trust Lifecycle Manager ACME server, linking each ACME account to the specific profile used for issuing certificates.
Copy your unique external account binding (EAB) credentials and store them somewhere safe. You can use the "copy" icon next to each field to copy it into your clipboard or select the Copy all button to copy them all at once.
After copying the new ACME credentials, Close the popup window.
Anmerkung
When you create an ACME-based certificate profile, the ACME credentials for it are displayed only once. There is no way to retrieve this information once you have navigated away from it. If you ever lose your ACME credentials, you will need to regenerate the ACME credentials for that profile.
What's next
Use your preferred ACME client to automate certificate management on your systems, issuing certificates from the ACME-based certificate profiles you created in Trust Lifecycle Manager. To learn more, see Request and manage certificates with ACME.