Skip to content

ACME / Let's Encrypt

SSL-CLM integrates with ACME-compatible CAs including Let’s Encrypt, ZeroSSL, and Google Trust Services for automated, free certificate issuance.


SSL-CLM Platform (ACME Client)
│
│ (ACME Protocol over HTTPS)
▼
ACME CA (Let's Encrypt / ZeroSSL / Google Trust Services)
│
│ (Domain Validation Challenge)
▼
DNS Provider (Cloudflare, Route53, Azure DNS) ← for DNS-01

The platform acts as a fully automated ACME client. No agent is required — all operations run from the backend.


  • Network access from SSL-CLM platform to the ACME CA directory URL
  • For DNS-01 validation: a DNS provider configured in Infrastructure → DNS Providers
  • For HTTP-01 validation: the target server must be accessible on port 80 from the internet

Step 1 — Add the Certificate Authority in SSL-CLM

Section titled “Step 1 — Add the Certificate Authority in SSL-CLM”
  1. Navigate to Infrastructure → Certificate Authorities
  2. Click + Add CA
  3. Select Let’s Encrypt / ACME from the type cards
  4. Fill in the configuration:
FieldDescriptionExample
NameFriendly display nameLet's Encrypt Production
Contact EmailEmail for Let’s Encrypt expiry notifications and account recoveryadmin@yourcompany.com
EnvironmentStaging (test, no rate limits) or Production (real trusted certs)production
Default DNS Names(Optional) Default domains, comma-separatedexample.com, www.example.com
Discovery IntervalHours between inventory syncs24
  1. Click Save

About the Environment setting:

  • Staging — Issues untrusted test certificates. Use for testing your setup without hitting rate limits.
  • Production — Issues real, browser-trusted certificates. Subject to Let’s Encrypt rate limits.

The platform automatically resolves the correct ACME directory URL based on your environment choice:

  • Staging: https://acme-staging-v02.api.letsencrypt.org/directory
  • Production: https://acme-v02.api.letsencrypt.org/directory

Step 2 — Configure DNS Provider (for DNS-01)

Section titled “Step 2 — Configure DNS Provider (for DNS-01)”

If you plan to use DNS-01 validation (required for wildcards and internal servers):

  1. Navigate to Infrastructure → DNS Providers
  2. Click + Add DNS Provider
  3. Select your provider (Cloudflare, AWS Route53, Azure DNS, Hostinger)
  4. Enter API credentials
  5. Save and verify

→ See DNS Providers for detailed setup.


  1. Navigate to Certificates → + New Certificate
  2. Select Issue from CA
  3. Choose the Let’s Encrypt CA
  4. Enter domain name(s) as Common Name and/or SANs
  5. Click Submit
  1. Platform generates a key pair and CSR
  2. Platform creates an ACME order with the CA
  3. CA responds with a DNS-01 (or HTTP-01) challenge
  4. Platform automatically creates the _acme-challenge TXT record via your DNS provider
  5. Platform notifies the CA that the challenge is ready
  6. CA verifies the DNS record
  7. Platform finalizes the order and submits the CSR
  8. CA issues the certificate
  9. Platform downloads the certificate and stores it in inventory
  10. Platform cleans up the DNS record

The entire flow is automated — no manual DNS intervention required.


MethodHow It WorksWhen to Use
DNS-01Platform creates _acme-challenge.domain.com TXT recordWildcards (*.example.com), internal servers, any domain
HTTP-01Platform serves a challenge token on port 80Public servers with port 80 accessible

DNS-01 is required for:

  • Wildcard certificates (*.example.com)
  • Internal/private servers not accessible from the internet
  • Domains where port 80 is not available

Let’s Encrypt certificates are valid for 90 days. SSL-CLM handles renewal automatically:

  1. Policy renewal threshold triggers (default: 30 days before expiry)
  2. Platform creates a new ACME order
  3. Same DNS-01/HTTP-01 validation is performed
  4. New certificate is issued
  5. Stores are re-deployed automatically (if auto-deploy is configured)
  6. Old certificate is archived

No manual intervention needed for the entire 90-day renewal cycle.


The platform automatically manages the ACME account:

  • On first use, an EC P-256 key pair is generated
  • The private key is stored encrypted in the vault
  • The key is used to authenticate all subsequent ACME requests
  • No manual key management required

LimitValue
Certificates per registered domain50 per week
Duplicate certificates5 per week
Failed validations5 per hour
New orders300 per 3 hours
Accounts per IP10 per 3 hours

Recommendation: Use the Staging environment for testing. Switch to Production only when your setup is verified.


Using with ZeroSSL or Google Trust Services

Section titled “Using with ZeroSSL or Google Trust Services”

The same integration type supports any ACME-compatible CA. To use a different CA:

  1. Add a new CA with type “Let’s Encrypt / ACME”
  2. In Advanced settings, override the Directory URL:
    • ZeroSSL: https://acme.zerossl.com/v2/DV90
    • Google Trust Services: https://dv.acme-v02.api.pki.goog/directory
  3. For CAs that require EAB (External Account Binding), provide the EAB KID and HMAC key

IssuePossible CauseResolution
Challenge timeoutDNS propagation delayCheck DNS provider config; ensure TXT record is created
Rate limit hitToo many requests to productionUse staging for testing; wait for rate limit reset
”Unauthorized”Account key issueCheck vault; try re-creating the CA to generate a fresh account
DNS record not createdDNS provider credentials expiredUpdate credentials in Infrastructure → DNS Providers
Wildcard failsNot using DNS-01Wildcards require DNS-01 — configure a DNS provider
CAA record blockingDomain has a CAA DNS record that doesn’t allow Let’s EncryptAdd letsencrypt.org to your CAA record

  • Account key is stored encrypted in vault — never exposed
  • DNS provider credentials are also in vault
  • Short-lived challenge tokens (cleaned up after validation)
  • Certificates are DV (Domain Validated) only — no OV/EV from Let’s Encrypt
  • Consider enabling CAA DNS records to restrict which CAs can issue for your domains