{% extends "base.html" %} {% block content %}
Automation

ACME certificate enrollment

Issue and renew certificates with Certbot, lego, and other ACME clients. Client private keys stay on their hosts.

Service

Directory URL: {{ directory_url }}

Loopback, link-local, metadata, multicast and reserved addresses remain blocked. HTTP-01 requires a direct HTTP 200 response; redirects are not followed. DNS-01 uses this server's configured DNS resolvers.

Issuance requires a valid Issuing CA, fresh parent CRLs, and an enabled certificate template that allows the ACME role. Account enrollment always requires a one-use credential.

{% if credential %}

New enrollment credential

Copy the HMAC key now. It is displayed once, expires after seven days, and can enroll one account.

EAB key ID
{{ credential.id }}
EAB HMAC key
{{ credential.secret }}

Store these values securely on the client, then supply them as its external account binding credentials.

{% endif %}

Authorize a client

One name per line. A wildcard grant permits subdomains and wildcard certificates; add the domain itself separately when needed. Certificate template restrictions also apply. Create or edit a certificate template to allow the ACME role before generating credentials.

Enrollment credentials

{% for item in credentials %}{% else %}{% endfor %}
ClientPermitted namesExpiresStatusAction
{{ item.label }}{{ item.domains }}{{ item.expires }}{{ 'Used' if item.used_at else 'Revoked' if item.revoked else 'Available until expiry' }}{% if not item.used_at and not item.revoked %}
{% endif %}
No enrollment credentials yet.

Accounts

{% for item in accounts %}{% else %}{% endfor %}
AccountPermitted namesStatusAction
{{ item.id }}
{{ item.contacts }}
{{ item.domains }}{{ item.status }}{% if item.status == 'valid' %}
{% endif %}
No ACME accounts yet.

Recent orders

{% for item in recent_orders %}{% else %}{% endfor %}
CreatedIdentifiersStatus
{{ item.created_at }}{{ item.identifiers }}{{ item.status }}
No orders yet.
{% endblock %}