ACME / Let's Encrypt
ACME / Let’s Encrypt Integration
Section titled “ACME / Let’s Encrypt Integration”SSL-CLM integrates with ACME-compatible CAs including Let’s Encrypt, ZeroSSL, and Google Trust Services for automated, free certificate issuance.
Architecture
Section titled “Architecture”SSL-CLM Platform (ACME Client)││ (ACME Protocol over HTTPS)▼ACME CA (Let's Encrypt / ZeroSSL / Google Trust Services)││ (Domain Validation Challenge)▼DNS Provider (Cloudflare, Route53, Azure DNS) ← for DNS-01The platform acts as a fully automated ACME client. No agent is required — all operations run from the backend.
Prerequisites
Section titled “Prerequisites”- Network access from SSL-CLM platform to the ACME CA directory URL
- For DNS-01 validation: a DNS provider configured in Infrastructure → DNS Providers
- For HTTP-01 validation: the target server must be accessible on port 80 from the internet
Step 1 — Add the Certificate Authority in SSL-CLM
Section titled “Step 1 — Add the Certificate Authority in SSL-CLM”- Navigate to Infrastructure → Certificate Authorities
- Click + Add CA
- Select Let’s Encrypt / ACME from the type cards
- Fill in the configuration:
| Field | Description | Example |
|---|---|---|
| Name | Friendly display name | Let's Encrypt Production |
| Contact Email | Email for Let’s Encrypt expiry notifications and account recovery | admin@yourcompany.com |
| Environment | Staging (test, no rate limits) or Production (real trusted certs) | production |
| Default DNS Names | (Optional) Default domains, comma-separated | example.com, www.example.com |
| Discovery Interval | Hours between inventory syncs | 24 |
- Click Save
About the Environment setting:
- Staging — Issues untrusted test certificates. Use for testing your setup without hitting rate limits.
- Production — Issues real, browser-trusted certificates. Subject to Let’s Encrypt rate limits.
The platform automatically resolves the correct ACME directory URL based on your environment choice:
- Staging:
https://acme-staging-v02.api.letsencrypt.org/directory - Production:
https://acme-v02.api.letsencrypt.org/directory
Step 2 — Configure DNS Provider (for DNS-01)
Section titled “Step 2 — Configure DNS Provider (for DNS-01)”If you plan to use DNS-01 validation (required for wildcards and internal servers):
- Navigate to Infrastructure → DNS Providers
- Click + Add DNS Provider
- Select your provider (Cloudflare, AWS Route53, Azure DNS, Hostinger)
- Enter API credentials
- Save and verify
→ See DNS Providers for detailed setup.
Step 3 — Issue a Certificate
Section titled “Step 3 — Issue a Certificate”- Navigate to Certificates → + New Certificate
- Select Issue from CA
- Choose the Let’s Encrypt CA
- Enter domain name(s) as Common Name and/or SANs
- Click Submit
What happens behind the scenes:
Section titled “What happens behind the scenes:”- Platform generates a key pair and CSR
- Platform creates an ACME order with the CA
- CA responds with a DNS-01 (or HTTP-01) challenge
- Platform automatically creates the
_acme-challengeTXT record via your DNS provider - Platform notifies the CA that the challenge is ready
- CA verifies the DNS record
- Platform finalizes the order and submits the CSR
- CA issues the certificate
- Platform downloads the certificate and stores it in inventory
- Platform cleans up the DNS record
The entire flow is automated — no manual DNS intervention required.
Domain Validation Methods
Section titled “Domain Validation Methods”| Method | How It Works | When to Use |
|---|---|---|
| DNS-01 | Platform creates _acme-challenge.domain.com TXT record | Wildcards (*.example.com), internal servers, any domain |
| HTTP-01 | Platform serves a challenge token on port 80 | Public servers with port 80 accessible |
DNS-01 is required for:
- Wildcard certificates (
*.example.com) - Internal/private servers not accessible from the internet
- Domains where port 80 is not available
Automated Renewal
Section titled “Automated Renewal”Let’s Encrypt certificates are valid for 90 days. SSL-CLM handles renewal automatically:
- Policy renewal threshold triggers (default: 30 days before expiry)
- Platform creates a new ACME order
- Same DNS-01/HTTP-01 validation is performed
- New certificate is issued
- Stores are re-deployed automatically (if auto-deploy is configured)
- Old certificate is archived
No manual intervention needed for the entire 90-day renewal cycle.
ACME Account Key
Section titled “ACME Account Key”The platform automatically manages the ACME account:
- On first use, an EC P-256 key pair is generated
- The private key is stored encrypted in the vault
- The key is used to authenticate all subsequent ACME requests
- No manual key management required
Rate Limits (Let’s Encrypt Production)
Section titled “Rate Limits (Let’s Encrypt Production)”| Limit | Value |
|---|---|
| Certificates per registered domain | 50 per week |
| Duplicate certificates | 5 per week |
| Failed validations | 5 per hour |
| New orders | 300 per 3 hours |
| Accounts per IP | 10 per 3 hours |
Recommendation: Use the Staging environment for testing. Switch to Production only when your setup is verified.
Using with ZeroSSL or Google Trust Services
Section titled “Using with ZeroSSL or Google Trust Services”The same integration type supports any ACME-compatible CA. To use a different CA:
- Add a new CA with type “Let’s Encrypt / ACME”
- In Advanced settings, override the Directory URL:
- ZeroSSL:
https://acme.zerossl.com/v2/DV90 - Google Trust Services:
https://dv.acme-v02.api.pki.goog/directory
- ZeroSSL:
- For CAs that require EAB (External Account Binding), provide the EAB KID and HMAC key
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Challenge timeout | DNS propagation delay | Check DNS provider config; ensure TXT record is created |
| Rate limit hit | Too many requests to production | Use staging for testing; wait for rate limit reset |
| ”Unauthorized” | Account key issue | Check vault; try re-creating the CA to generate a fresh account |
| DNS record not created | DNS provider credentials expired | Update credentials in Infrastructure → DNS Providers |
| Wildcard fails | Not using DNS-01 | Wildcards require DNS-01 — configure a DNS provider |
| CAA record blocking | Domain has a CAA DNS record that doesn’t allow Let’s Encrypt | Add letsencrypt.org to your CAA record |
Security Considerations
Section titled “Security Considerations”- Account key is stored encrypted in vault — never exposed
- DNS provider credentials are also in vault
- Short-lived challenge tokens (cleaned up after validation)
- Certificates are DV (Domain Validated) only — no OV/EV from Let’s Encrypt
- Consider enabling CAA DNS records to restrict which CAs can issue for your domains
Related Pages
Section titled “Related Pages”- DNS Providers — Required for DNS-01 challenges
- ACME Server — SSL-CLM’s built-in ACME server (the inverse — serving ACME)
- CA Capability Matrix
- Certificate Authorities