aethercert
Certificate authorities

Public and private ACME certificate authorities

Let's Encrypt is set up on every organization. Google Trust Services, ZeroSSL, SSL.com and Actalis are presets you add with an external account binding, and any other ACME directory - including an internal one such as step-ca - works the same way.

At a glance

Let's Encrypt
Seeded on every organization; staging preset available. No EAB.
Google Trust Services
Production and staging presets. EAB from Google Cloud Certificate Manager.
ZeroSSL
Preset. EAB from the ZeroSSL developer console.
SSL.com
Separate RSA and ECC presets. EAB from the SSL.com dashboard.
Actalis
Preset. EAB issued by Actalis.
Custom ACME
Any directory URL, for example step-ca or another internal ACME server.

What it does

The agent speaks ACME directly to the authority: it registers a per-CA account key, places the order, answers the domain validation challenge and downloads the certificate. Account keys are kept on the agent.

For authorities that require it, you paste the external account binding (key ID and HMAC key) from the CA's own console. Staging directories for Let's Encrypt and Google Trust Services are available as presets for testing deploy targets without burning production rate limits.

How it runs

  1. 01

    Account

    The agent registers or reuses its ACME account for that authority, with EAB if required.

  2. 02

    Order

    An order is opened for the certificate's names.

  3. 03

    Validate

    DNS-01, HTTP-01 or TLS-ALPN-01 is answered automatically.

  4. 04

    Finalize

    The CSR generated on the agent is submitted and the certificate downloaded.

What you configure

  • Provider preset or custom directory URL
  • EAB key ID and HMAC key, where the CA requires them
  • Per certificate: key type, names and challenge type

Prerequisites

  • For DNS-01: a verified domain with a connected DNS provider
  • For HTTP-01 / TLS-ALPN-01: the host reachable from the internet on port 80 / 443

Limitations

  • Community organizations use Let's Encrypt only; other authorities require Standard or higher.
  • Public ACME CAs issue server-authentication certificates; targets that need client authentication require an internal CA.

Frequently asked questions

ACME certificate authorities

Do I need an EAB for Let's Encrypt?

No. Let's Encrypt needs no external account binding and is configured on every organization automatically.

Can I use an internal ACME server?

Yes. Add a custom ACME authority with its directory URL; DNS-01, HTTP-01 and TLS-ALPN-01 work the same as with a public CA.

Automate ACME certificate authorities

Connect it once in the dashboard; every issuance and renewal uses it from then on.

Community plan, no card required. Open registration - your account is ready in a few minutes.