ACME providers¶
In the console: Settings › TLS › ACME Providers
Services like Let’s Encrypt that issue and renew certificates automatically.
ACME provider¶
Directory URL¶
The URL of the ACME directory endpoint.
An address (URL). Default: https://acme-v02.api.letsencrypt.org/directory. Set when it’s created; can’t be changed afterwards. Name in the API: directory.
Challenge type¶
The ACME challenge type used to validate domain ownership.
One of: TLS-ALPN-01 (TlsAlpn01), DNS-PERSIST-01 (DnsPersist01), DNS-01 (Dns01), HTTP-01 (Http01). Default: TLS-ALPN-01. Name in the API: challengeType.
Contact Email¶
Contact email address, which is used for important communications regarding your ACME account and certificates.
A list. Each one: an email address. Name in the API: contact.
Renew before¶
How long before expiration the certificate should be renewed.
One of: 1/2 of the remaining time until expiration (R12), 2/3 of the remaining time until expiration (R23), 3/4 of the remaining time until expiration (R34), 4/5 of the remaining time until expiration (R45). Default: 2/3 of the remaining time until expiration. Name in the API: renewBefore.
Preferred chain¶
Preferred certificate chain to use when multiple chains are available.
Text. Name in the API: preferredChain.
External Account Binding¶
Key ID¶
The External Account Binding (EAB) key ID.
Text. Set when it’s created; can’t be changed afterwards. Name in the API: eabKeyId.
HMAC Key¶
The External Account Binding (EAB) HMAC key.
A secret: stored, and never shown again once saved. Set when it’s created; can’t be changed afterwards. Name in the API: eabHmacKey.
Account¶
Account URI¶
The account URI returned by the ACME server after registration. Used for CAA record accounturi binding.
An address (URL). Read only. Name in the API: accountUri.
Account Key¶
The account key used to authenticate with the ACME provider.
A secret: stored, and never shown again once saved. Read only. Name in the API: accountKey.
Renewal Settings¶
Max retries¶
Maximum number of retry attempts for failed challenges.
A number. Default: 10. Name in the API: maxRetries.
Tenant¶
Identifier for the tenant this ACME provider belongs to.
One of your Tenants, chosen from a list. Name in the API: memberTenantId.
Reuse key¶
Whether to reuse the existing private key when renewing a certificate.
On or off. Name in the API: reuseKey.
Set by the server¶
Description¶
Descriptive label for this provider, built from the directory URL and the contact address.
Text. Read only. Name in the API: description.