An ACME issuer connects ActivCERT to a certificate authority and identifies how domain control will be validated. Open the intended service in CERTCOM and configure the selected DNS provider before creating an issuer that references it. Choose the example for your ACME service, substitute your account and provider values, then verify and inspect the issuer before issuing certificates.
Let's Encrypt
Validate with the Let's Encrypt staging service before creating the production issuer. Staging and production use separate ACME accounts.
ADD ISSUER letsencrypt-staging, TYPE ACME, &
DIRECTORY https://acme-staging-v02.api.letsencrypt.org/directory, &
DCV <provider-name>, GENERATE-ACCOUNT-KEY, &
CONTACT mailto:<contact-email>, TRUST-ANCHOR CACERT
VERIFY ISSUER letsencrypt-staging, WAIT
INFO ISSUER letsencrypt-staging, DETAIL
ZeroSSL
ZeroSSL requires external account binding. Copy the EAB key identifier and base64url HMAC value from the ZeroSSL account, removing leading or trailing spaces.
Store the HMAC value in a protected EAB-SECRET credential, reference it from the issuer, and verify the resulting account configuration:
ADD CREDENTIAL zerossl-eab, TYPE EAB-SECRET, PROMPT
ADD ISSUER zerossl, TYPE ACME, &
DIRECTORY https://acme.zerossl.com/v2/DV90, &
DCV <provider-name>, GENERATE-ACCOUNT-KEY, &
EAB-KEY-ID <key-id>, EAB-CREDENTIAL zerossl-eab, &
CONTACT mailto:<contact-email>, TRUST-ANCHOR CACERT
VERIFY ISSUER zerossl, WAIT
INFO ISSUER zerossl, DETAIL
Sectigo with prevalidated domains
A Sectigo ACME account with prevalidated domains uses external account binding and DCV EXTERNAL. Remove leading or trailing spaces from the Sectigo key identifier and HMAC value. The certificate SANs must contain the prevalidated DNS names.
Store the HMAC value in a protected credential and configure the issuer to use external domain validation. Then verify and inspect the account configuration:
ADD CREDENTIAL sectigo-eab, TYPE EAB-SECRET, PROMPT
ADD ISSUER sectigo-dv, TYPE ACME, &
DIRECTORY https://acme.sectigo.com/v2/DV, DCV EXTERNAL, &
GENERATE-ACCOUNT-KEY, EAB-KEY-ID <key-id>, &
EAB-CREDENTIAL sectigo-eab, TRUST-ANCHOR CACERT
VERIFY ISSUER sectigo-dv, WAIT
INFO ISSUER sectigo-dv, DETAIL