Admin: ACME Certificate Accounts

ACME accounts are tenant-scoped certificate identities used for ACME certificate operations. Administrators can list, add, and delete Let's Encrypt, GlobalSign Atlas, DigiCert CertCentral, and approved custom ACME v2 accounts from the System Settings panel.


What You Can Configure

• View configured accounts by email, provider, directory host, and creation date

• Search/filter accounts in the table

• Add Let's Encrypt, GlobalSign Atlas, DigiCert CertCentral, or custom ACME v2 accounts

• Delete existing accounts

See ACME Certificate Providers for the GlobalSign Atlas and DigiCert CertCentral credential preparation steps.

Add Account Workflow

1. Click Add in the ACME section toolbar

2. Select ACME provider

3. Enter account email (required, validated format)

4. For GlobalSign, enter the Atlas key ID and ACME MAC

5. For DigiCert, enter the unique CertCentral directory URL, EAB KID, and HMAC key

6. Accept the issuer agreement and submit the account registration

Use shared operational mailboxes for ACME account ownership when possible, rather than individual user addresses.

Commercial issuer MAC/HMAC values are used only during registration and are not retained. The generated ACME account signing key is encrypted at rest.


Deletion Guidance

Deletion removes the ACME account configuration from the tenant. Confirm no active certificate workflows depend on the account before deleting. Deactivate or revoke the corresponding account or credentials separately in GlobalSign Atlas or DigiCert CertCentral when required.

An unhandled error has occurred. Reload 🗙
An unhandled error has occurred. Reload 🗙