ACME providers and external account binding¶
In the Windows Agent, choose Names & authority → ACME account → Create a new account. Enter an account name and contact email, select the authority, and review its terms. The presets fill in the directory URL. Custom ACME directory accepts another HTTPS directory and optional EAB credentials.
For a provider requiring External Account Binding, enter EAB KID (key ID) and EAB HMAC Key during setup. Both are required together. The HMAC field is masked and the Agent stores it encrypted before enabling automatic renewal or requesting issuance. It is not included in workflow configuration or the review summary. Existing accounts can be reused without entering EAB again. To rotate a saved key, use the account controls under Edit workflow….
| Authority choice | ACME directory |
|---|---|
| Let's Encrypt — production | https://acme-v02.api.letsencrypt.org/directory |
| Let's Encrypt — staging | https://acme-staging-v02.api.letsencrypt.org/directory |
| ZeroSSL.com | https://acme.zerossl.com/v2/DV90 |
| SSL.com — ECC | https://acme.ssl.com/sslcom-dv-ecc |
| SSL.com — RSA | https://acme.ssl.com/sslcom-dv-rsa |
| Actalis.com | https://acme-api.actalis.com/acme/directory |
| Google Trust Services — production | https://dv.acme-v02.api.pki.goog/directory |
| Google Trust Services — staging | https://dv.acme-v02.test-api.pki.goog/directory |
Staging certificates are for testing and are not publicly trusted. Let's Encrypt profiles are shown only for Let's Encrypt directories. Provider presets configure account setup; issuance still depends on CA eligibility and successful DNS-01 validation through the Agent's delegated DNS workflow.
ZeroSSL.com¶
Create a ZeroSSL account, then generate EAB credentials in the dashboard's Developer section. Copy the KID and HMAC key into setup. A ZeroSSL API access key is a different credential and cannot replace these EAB values. See ZeroSSL ACME documentation.
SSL.com¶
In your SSL.com dashboard, open API credentials under developers and integration. Use the Account/ACME Key as EAB KID and the HMAC Key as EAB HMAC Key. Choose ECC for an ECDSA certificate or RSA for an RSA certificate; the wizard selects a compatible key type and rejects mismatches. Check account and product charges with SSL.com. See SSL.com ACME instructions.
Actalis.com¶
Enable ACME for an eligible certificate in the Actalis Customer Area. Under Manage with ACME → ACME Credentials, copy KID and KEY into the two EAB fields. Confirm your certificate product's eligibility and supported validation methods before issuance. See Actalis activation instructions and ACME eligibility FAQ.
Google Trust Services¶
Google Public CA requires a Google Cloud project, the Public CA API enabled,
and permission to create external account keys
(roles/publicca.externalAccountKeyCreator). The EAB credentials bind the ACME
account to that project. The application can be hosted outside Google Cloud.
Domain control is verified through ACME challenges; the documented process does
not require prior Search Console verification or Google-hosted DNS.
See Public CA overview
and Google's setup tutorial.
After selecting the project in Google Cloud CLI, enable the API and generate a production credential:
Copy keyId into EAB KID and b64MacKey into EAB HMAC Key. A credential
registers one account and expires after seven days if unused. Reuse the registered
account for renewals; retain its Google Cloud project.
For staging, generate separate credentials using the staging API:
gcloud config set api_endpoint_overrides/publicca https://preprod-publicca.googleapis.com/
gcloud publicca external-account-keys create
gcloud config unset api_endpoint_overrides/publicca
Select the matching Google staging directory in the Agent. Production and staging credentials are not interchangeable.