ACME Certificate Providers

AZExecute can order and renew certificates through Let's Encrypt, GlobalSign Atlas, DigiCert CertCentral, or another explicitly allowed RFC 8555-compatible ACME service. Select the issuer that matches your certificate policy, commercial agreement, and validation requirements.

Supported providers

Provider Account requirements Directory Recommended use
Let's Encrypt - Production
Email and subscriber agreement; EAB is normally not required. Built in Publicly trusted certificates without a commercial CA profile.
Let's Encrypt - Staging
Email and subscriber agreement; EAB is normally not required. Built in Testing account registration, DNS validation, and ordering without trusted issuance.
GlobalSign Atlas
Atlas API key / EAB key ID and ACME MAC. Built-in GlobalSign Atlas directory GlobalSign commercial certificate services provisioned through Atlas.
DigiCert CertCentral
Unique CertCentral directory URL, EAB KID, and HMAC key. Copied from CertCentral DigiCert commercial certificate profiles configured in CertCentral.
Custom ACME v2
HTTPS directory and optional EAB values. Explicitly configured Another approved RFC 8555-compatible ACME service.
External Account Binding (EAB) connects the ACME account created by AZExecute to the commercial account and certificate profile configured at the issuer. GlobalSign Atlas and DigiCert CertCentral require EAB during account registration.

GlobalSign Atlas

Use the GlobalSign Atlas ACME service for certificates covered by your Atlas account. This integration uses the ACME protocol and does not use the separate TrustZone SSL API or its SOAP/XML interface.

Prepare the Atlas credentials

1. Sign in to GlobalSign Atlas and confirm that the required certificate service, organization, and domains are available.

2. Open Access Credentials, then API Credentials.

3. Select an API credential and request an ACME MAC.

4. Copy the API key / EAB key ID and the ACME MAC immediately. The MAC is used as the EAB HMAC key.

Values entered in AZExecute
Field Value
ACME provider GlobalSign Atlas
ACME directory URL Filled automatically with https://emea.acme.atlas.globalsign.com/directory
EAB key ID The Atlas API key / key ID associated with the ACME MAC
EAB HMAC / MAC key The ACME MAC copied from Atlas
Copy a newly generated ACME MAC before leaving the Atlas credential screen. If it is lost, expired, revoked, or suspected to be compromised, generate a replacement before registering a new ACME account.

DigiCert CertCentral

DigiCert creates a unique ACME directory URL and EAB credential set for a specific certificate configuration. That configuration can include the certificate product, organization, division, validity, and other product options.

Create CertCentral ACME credentials

1. Sign in to CertCentral and open Automation > ACME Directory URLs.

2. Select Add ACME Directory URL.

3. Choose the product, organization, division, validity, and any additional certificate options required by your policy.

4. Create the credential set and copy the unique directory URL, EAB key identifier (KID), and HMAC key.

Values entered in AZExecute
Field Value
ACME provider DigiCert CertCentral
ACME directory URL The complete unique directory URL generated by CertCentral
EAB key ID The KID generated with the CertCentral ACME credential set
EAB HMAC / MAC key The HMAC key generated with the same credential set
CertCentral displays the new directory URL and EAB values only when the credential set is created. Store them securely until registration is complete. If they are lost or compromised, revoke that credential set in CertCentral and create another.

Register the account

1. Open System Settings and locate ACME Certificate Accounts.

2. Select Add and choose the certificate provider.

3. Enter a shared operational email address for account ownership and issuer notifications.

4. Enter the provider-specific directory and EAB values shown above.

5. Review and accept the issuer's subscriber agreement, then add the account.

6. Create or update a certificate template, select the account, configure DNS authorization, and place one manual order before relying on scheduled renewal.

The EAB MAC/HMAC value is sent only during ACME account registration and is not retained by AZExecute. The generated ACME account signing key is encrypted at rest.

Credential lifecycle and troubleshooting

Registration is rejected: Verify that the key ID and MAC/HMAC value came from the same issuer credential set and have not expired or been revoked.

DigiCert directory is rejected: Copy the complete unique HTTPS directory URL issued by CertCentral. Do not substitute a documentation example or another region's URL.

The certificate profile must change: Create new issuer credentials and register a new ACME account instead of trying to reuse EAB values from another profile.

DNS validation fails: Review the certificate activity log and the DNS Authorization guide.

An account is no longer needed: Move dependent templates first. Deleting it from AZExecute removes the local configuration; manage deactivation or revocation separately at the issuer.

An unhandled error has occurred. Reload 🗙
An unhandled error has occurred. Reload 🗙