Skip to main content

Add ACME credentials for Enterprise and non-subscription accounts

To automate certificate issuance and deployment with third-party ACME clients such as Certbot, you first create ACME credentials in CertCentral.

Each set of ACME credentials is for a specific certificate product. When you create the credentials, you select the certificate product and configure the settings that apply to certificate requests made with those credentials, including:

  • Organization

  • Division

  • CertCentral order length

  • Certificate validity length

  • Certificate extensions and other options

When you create the credentials, CertCentral generates:

  • An ACME Directory URL

  • A Key Identifier (KID)

  • An HMAC key

Use the ACME Directory URL to connect your ACME client to CertCentral. The KID and HMAC key are the External Account Binding (EAB) credentials used to authenticate the client.

Avis

These instructions apply to CertCentral Enterprise, Partner, and legacy accounts. If you have an active CertCentral Subscription account, see Add ACME credentials for Subscription accounts

Add ACME credentials

When you create ACME credentials, you can own the credentials, or you can create them for a Service User or another CertCentral user.

  1. In the CertCentral main menu, select Automation > ACME Directory URLs.

  2. On the ACME Directory URLs page, select Add ACME Directory URL.

  3. In the Add ACME Directory URL popup window, in the Name field, enter a name to identify the credentials.

  4. In the Product menu, select the certificate product to request with these credentials.

  5. In the User menu, select who will own these ACME credentials: yourself, another CertCentral user, or a Service User.

    The ACME Directory URL inherits the permissions of the selected user.

    Do one of the following:

    1. Select your name.

    2. Select another CertCentral user.

    3. Select a Service User.

    4. Select Create new Service User.

      To create a new Service User:

      1. In the Service and User name fields, replace the default names or leave them unchanged.

      2. In the Email address field, enter the email address for the Service User.

      3. In the Division restrictions menu, select the divisions to which you want to restrict the Service User, if needed.

        Note: This option appears if divisions are enabled for your account.

  6. Configure the remaining ACME credential settings. The available options depend on your account configuration and the certificate product you selected.

    • Division: In the menu, select the division you want to assign the credentials to.

    • Organization: In the menu, select the organization to be included in the OV and EV TLS certificates. DV certificates don’t include organization information.

    • Multi-year coverage length: In the menu, select the order length.

    • Validity period: Configure the certificate validity period.

      • TLS certificates: 199 days is the maximum validity.

      • Private TLS certificates: Select 1 year, 2 years, 3 years.

      • Custom length: Enter the number of days to configure the certificate validity.

    • Allow validity override by ACME client request: Select this option to allow the ACME client to request certificates with a shorter validity period than the default configured for this ACME Directory URL

    • Additional certificate options:

      • If available, select a certificate profile, such as Include the CanSignHttpExchanges extension in the certificate, learn more about this option.

      • In the Intermediate chains [Intermediate CA] > [Root CA] menu, select the certificate chain you want to use to issue these certificates. Learn how intermediate chains work.

    • Configure ACME URL restrictions:

      Use these options to control which domains can be included in certificate requests and to limit the number of orders that can be created.

      Allowed SANs (optional): Enter the domains that can be included in a certificate request. Enter a domain per line or separate domains with commas. Maximum 250 domains.

      Number of allowed orders (optional): Enter the maximum number of orders that can be placed through the ACME Directory URL. Leave as unlimited for unlimited orders.

  7. Configure ACME URL restrictions.

    Use these options to control which domains can be included in certificate requests and to limit the number of orders that can be created.

    Allowed SANs (optional): Enter the domains that can be included in a certificate request. Enter a domain per line or separate domains with commas. Maximum 250 domains.

    Number of allowed orders (optional): Enter the maximum number of orders that can be placed through the ACME Directory URL. Leave as unlimited for unlimited orders.

  8. Select Add ACME Directory URL to generate your ACME credentials.

  9. In the New ACME Directory URL window, select Copy all to copy the ACME Directory URL, Key Identifier (KID), and HMAC key.

    Your ACME client requires this information to request certificates from CertCentral.

    Avertissement

    Important: CertCentral displays the ACME Directory URL, Key Identifier (KID), and HMAC key one time. After you acknowledge the message, you can’t retrieve them again. Store them in a secure location before continuing.

  10. Select I understand I will not see this again.

Avertissement

If you lose your ACME credentials or suspect they’ve been compromised, revoke them immediately. For more information, see Manage your ACME credentials.

What's next

Use your ACME credentials to configure a third-party ACME client on your servers. For setup instructions, see Set up a third-party ACME client.

ACME credentials for Signed HTTP Exchanges certificates

You can use the CertCentral ACME service to get certificates with the Signed HTTP Exchanges extension.

Before you begin

  • The Signed HTTP Exchange certificate profile option must be enabled for your account.

  • Each domain must have a CAA DNS record with the cansignhttpexchanges=yes parameter.

ACME settings

Follow the standard steps to add the ACME credentials, using the following settings to enable the CanSignHttpExchanges extension in certificates issued through the ACME credentials:

  • Product: Select an OV or EV certificate product. Currently, the CanSignHttpExchanges extension is only supported for OV or EV certificates.

  • Validity period: Select Custom length and enter a number from 1 to 90 days. Certificates with the CanSignHttpExchanges extension have a 90-day maximum validity limit.

  • Additional certificate options: Expand this section and select the checkbox to Include the CanSignHttpExchanges extension in the certificate.

After making your selections, select the Add ACME Directory URL button to generate the new ACME credentials. Use the provided URL and EAB credentials to send ACME requests for certificates with the Signed HTTP Exchanges extension and other settings you selected.

Manage your ACME credentials

The ACME Directory URLs page in CertCentral lists the ACME credentials in your account. Select the tooltip next to an ACME credential name to view details about the credentials, including:

  • Certificate type available through the credentials

  • Validity period

  • Order count limits and status (for example, 1/5 used)

  • Allowed SANs

You can also revoke ACME Directory URLs, update their restrictions, and transfer ownership to another CertCentral user or Service User.

Secure your ACME credentials

Always store your ACME credentials in a secure location to help prevent unauthorized certificate requests for your domains.

If you lose your ACME credentials or suspect they’ve been compromised, immediately revoke the existing ACME Directory URL and create new ACME credentials. See Add new ACME credentials.

Revoke an ACME Directory URL

When you revoke an ACME Directory URL, the ACME credentials are permanently disabled, ACME clients can no longer use them to request certificates from CertCentral.

  1. In the CertCentral menu, go to Automation > ACME Directory URLs.

  2. On the ACME Directory URLs page, find the URL and in its Actions menu, select Revoke ACME Directory URL.

    Avertissement

    Important: You can’t restore a revoked ACME Directory URL. Before revoking, make sure you've replaced it in your integrations.

  3. In the Revoke ACME Directory URL window, select Revoke ACME Directory URL.

    ACME clients can no longer use the ACME Directory URL to request certificates from CertCentral.

Update the order and domain restrictions for an ACME Directory URL

After you create an ACME Directory URL, you can update its restrictions by adding or removing allowed domains or increasing the number of allowed orders.

  1. In the CertCentral menu, go to Automation > ACME Directory URLs.

  2. On the ACME Directory URLs page, find the URL and in its Actions menu, select Update ACME Directory URL.

  3. In the Update ACME Directory URL restrictions window, update the following information as required:

    Allowed SANs (optional): Add or remove domains that can be included in a certificate request. Enter a domain per line or separate domains with commas. Maximum 250 domains.

    Number of allowed orders (optional): Enter the maximum number of orders that can be placed through the ACME Directory URL. Leave as unlimited for unlimited orders.

    You can’t decrease the number of orders that can be created. You can only increase it. For example, if the number of allowed orders is 9, increase it to 14 to add five more orders.

  4. Select Update ACME Directory URL.

Transfer ACME Directory URL ownership

When you transfer ownership of an ACME Directory URL to another CertCentral user or Service User, existing copies of the ACME credentials (ACME Directory URL, Key Identifier (KID), and HMAC key) remain valid until the ACME Directory URL is revoked.

You must be an Administrator in CertCentral to create ACME Directory URLs. All ACME Directory URL creations are recorded in your CertCentral audit log (go to Account > Audit Logs).

Avertissement

Important: When you transfer ownership of an ACME Directory URL, the ACME Directory URL inherits the permissions of the user or Service User it’s linked to. API key restrictions can further limit the actions that can be performed by using the ACME Directory URL.

  1. In the CertCentral menu, go to Automation > ACME Directory URLs.

  2. On the ACME Directory URLs page, find the URL and in its Actions menu, select Update ACME Directory URL.

  3. In the Update ACME Directory URL restrictions window, in the User menu, select the CertCentral user or Service User you want to transfer ownership to.

  4. Select Update ACME Directory URL.

    Ownership of the ACME Directory URL has been transferred to the selected user or Service User.