Skip to content

ACME providers

In the console: Settings › TLS › ACME Providers

Services like Let’s Encrypt that issue and renew certificates automatically.

ACME provider

Directory URL

The URL of the ACME directory endpoint.

An address (URL). Default: https://acme-v02.api.letsencrypt.org/directory. Set when it’s created; can’t be changed afterwards. Name in the API: directory.

Challenge type

The ACME challenge type used to validate domain ownership.

One of: TLS-ALPN-01 (TlsAlpn01), DNS-PERSIST-01 (DnsPersist01), DNS-01 (Dns01), HTTP-01 (Http01). Default: TLS-ALPN-01. Name in the API: challengeType.

Contact Email

Contact email address, which is used for important communications regarding your ACME account and certificates.

A list. Each one: an email address. Name in the API: contact.

Renew before

How long before expiration the certificate should be renewed.

One of: 1/2 of the remaining time until expiration (R12), 2/3 of the remaining time until expiration (R23), 3/4 of the remaining time until expiration (R34), 4/5 of the remaining time until expiration (R45). Default: 2/3 of the remaining time until expiration. Name in the API: renewBefore.

Preferred chain

Preferred certificate chain to use when multiple chains are available.

Text. Name in the API: preferredChain.

External Account Binding

Key ID

The External Account Binding (EAB) key ID.

Text. Set when it’s created; can’t be changed afterwards. Name in the API: eabKeyId.

HMAC Key

The External Account Binding (EAB) HMAC key.

A secret: stored, and never shown again once saved. Set when it’s created; can’t be changed afterwards. Name in the API: eabHmacKey.

Account

Account URI

The account URI returned by the ACME server after registration. Used for CAA record accounturi binding.

An address (URL). Read only. Name in the API: accountUri.

Account Key

The account key used to authenticate with the ACME provider.

A secret: stored, and never shown again once saved. Read only. Name in the API: accountKey.

Renewal Settings

Max retries

Maximum number of retry attempts for failed challenges.

A number. Default: 10. Name in the API: maxRetries.

Tenant

Identifier for the tenant this ACME provider belongs to.

One of your Tenants, chosen from a list. Name in the API: memberTenantId.

Reuse key

Whether to reuse the existing private key when renewing a certificate.

On or off. Name in the API: reuseKey.

Set by the server

Description

Descriptive label for this provider, built from the directory URL and the contact address.

Text. Read only. Name in the API: description.