ACME Certificate Providers
AZExecute can order and renew certificates through Let's Encrypt, GlobalSign Atlas, DigiCert CertCentral, or another explicitly allowed RFC 8555-compatible ACME service. Select the issuer that matches your certificate policy, commercial agreement, and validation requirements.
Supported providers
| Provider | Account requirements | Directory | Recommended use |
|---|---|---|---|
Let's Encrypt - Production |
Email and subscriber agreement; EAB is normally not required. | Built in | Publicly trusted certificates without a commercial CA profile. |
Let's Encrypt - Staging |
Email and subscriber agreement; EAB is normally not required. | Built in | Testing account registration, DNS validation, and ordering without trusted issuance. |
GlobalSign Atlas |
Atlas API key / EAB key ID and ACME MAC. | Built-in GlobalSign Atlas directory | GlobalSign commercial certificate services provisioned through Atlas. |
DigiCert CertCentral |
Unique CertCentral directory URL, EAB KID, and HMAC key. | Copied from CertCentral | DigiCert commercial certificate profiles configured in CertCentral. |
Custom ACME v2 |
HTTPS directory and optional EAB values. | Explicitly configured | Another approved RFC 8555-compatible ACME service. |
GlobalSign Atlas
Use the GlobalSign Atlas ACME service for certificates covered by your Atlas account. This integration uses the ACME protocol and does not use the separate TrustZone SSL API or its SOAP/XML interface.
Prepare the Atlas credentials
1. Sign in to GlobalSign Atlas and confirm that the required certificate service, organization, and domains are available.
2. Open Access Credentials, then API Credentials.
3. Select an API credential and request an ACME MAC.
4. Copy the API key / EAB key ID and the ACME MAC immediately. The MAC is used as the EAB HMAC key.
Values entered in AZExecute
| Field | Value |
|---|---|
| ACME provider | GlobalSign Atlas |
| ACME directory URL | Filled automatically with https://emea.acme.atlas.globalsign.com/directory |
| EAB key ID | The Atlas API key / key ID associated with the ACME MAC |
| EAB HMAC / MAC key | The ACME MAC copied from Atlas |
DigiCert CertCentral
DigiCert creates a unique ACME directory URL and EAB credential set for a specific certificate configuration. That configuration can include the certificate product, organization, division, validity, and other product options.
Create CertCentral ACME credentials
1. Sign in to CertCentral and open Automation > ACME Directory URLs.
2. Select Add ACME Directory URL.
3. Choose the product, organization, division, validity, and any additional certificate options required by your policy.
4. Create the credential set and copy the unique directory URL, EAB key identifier (KID), and HMAC key.
Values entered in AZExecute
| Field | Value |
|---|---|
| ACME provider | DigiCert CertCentral |
| ACME directory URL | The complete unique directory URL generated by CertCentral |
| EAB key ID | The KID generated with the CertCentral ACME credential set |
| EAB HMAC / MAC key | The HMAC key generated with the same credential set |
Register the account
1. Open System Settings and locate ACME Certificate Accounts.
2. Select Add and choose the certificate provider.
3. Enter a shared operational email address for account ownership and issuer notifications.
4. Enter the provider-specific directory and EAB values shown above.
5. Review and accept the issuer's subscriber agreement, then add the account.
6. Create or update a certificate template, select the account, configure DNS authorization, and place one manual order before relying on scheduled renewal.
Credential lifecycle and troubleshooting
Registration is rejected: Verify that the key ID and MAC/HMAC value came from the same issuer credential set and have not expired or been revoked.
DigiCert directory is rejected: Copy the complete unique HTTPS directory URL issued by CertCentral. Do not substitute a documentation example or another region's URL.
The certificate profile must change: Create new issuer credentials and register a new ACME account instead of trying to reuse EAB values from another profile.
DNS validation fails: Review the certificate activity log and the DNS Authorization guide.
An account is no longer needed: Move dependent templates first. Deleting it from AZExecute removes the local configuration; manage deactivation or revocation separately at the issuer.