Skip to content

CertIntel plugin for simple-acme

Use CertIntel delegated DNS-01 with simple-acme. The native DLL publishes and removes challenge TXT values; simple-acme owns certificate issuance, storage, installation and renewal. A CertIntel Agent is not required.

Download: use verified downloads, selecting simple-acme.

Install

Use the Windows x64 pluggable simple-acme release. The plugin was tested with 2.4.0.2350. Download the DLL for this client; simple-acme and win-acme use different builds despite the identical filename.

After verification succeeds, copy PKISharp.WACS.Plugins.ValidationPlugins.CertIntel.dll from the matching package into the directory containing wacs.exe. Unblock the downloaded DLL if Windows marked it as downloaded (Unblock-File '.\PKISharp.WACS.Plugins.ValidationPlugins.CertIntel.dll'), then restart the client. Do not copy host libraries from a build's bin folder, and do not put both DLL variants in the same client directory. A trimmed client cannot load this plugin. Releases use Authenticode-signed DLLs and signed manifests. Unblocking a file is not signature verification.

Follow delegation setup to create the delegation and permanent _acme-challenge CNAME in CertIntel and your DNS provider first. Configure one or more delegations entirely in the client, using its built-in credential handling. No separate JSON file is needed.

Confirm discovery without creating an order:

.\wacs.exe --help --validation certintel

The help should show CertIntel, --certintelapikey, and the configuration arguments.

Interactive use

Create a certificate with full options, select the desired names, choose DNS-01 validation, and select Create DNS-01 verification records in CertIntel. The plugin asks for each delegation's certificate domain, API base, delegation UUID and full CNAME target. The API base defaults to https://api.certin.tel/api/v1: press Enter to accept it, or enter a different HTTPS endpoint including /api/v1. Additional delegations reuse the previous entry's endpoint as their default. At the API key prompt, select an existing vault secret or enter a key through the client's password prompt. The key uses the host's ProtectedString handling and is stored according to its Security.EncryptConfig setting; leave encryption enabled.

After the first entry, the plugin shows a menu to Add, Edit, or Remove delegations. Add an entry for every distinct certificate name that needs a mapping. Choose Use these delegations when finished. During editing, Enter keeps the displayed field value; credentials use the host's secret selection menu.

Complete the certificate setup normally. The ACME client automatically saves the delegation list and protected keys or vault references in its own renewal settings. The DLL does not create a separate configuration file, and users do not edit JSON. Scheduled renewals load the saved settings without prompting.

To create a reusable vault entry first, use More options → Manage secrets in the host. A secret named certintel-example is referenced as vault://json/certintel-example. The plugin resolves it through the host's secret manager at runtime, so the actual key does not need to appear in command-line arguments. Each delegation can use a different key. The client manages its own renewal and vault files. See the official simple-acme secrets guide and win-acme secrets guide.

Choose certificate storage and installation options in the host client. The CertIntel plugin performs only DNS validation. example.com also covers its wildcard, but other certificate names require their own exact mappings.

To change mappings later, use Manage renewals → Edit renewal and reconfigure the CertIntel validation step. The host starts a fresh validation setup, so enter the full desired list again; it saves the replacement when you complete the edit. To rotate a vault-backed key, update that secret through Manage secrets. The plugin resolves the current vault value on each operation, without changing mappings.

Staging test from PowerShell

Replace the domains, email and paths. This creates a staging certificate in the client's file store; it does not install it into a web server.

$arguments = @(
    '--source', 'manual',
    '--host', 'example.com,*.example.com',
    '--validationmode', 'dns-01',
    '--validation', 'certintel',
    '--certinteldomain', 'example.com',
    '--certinteldelegationid', '11111111-1111-1111-1111-111111111111',
    '--certintelcnametarget', 'YOUR-LABEL.dns01.certin.tel',
    '--certintelapikey', 'vault://json/certintel-example',
    '--store', 'pemfiles',
    '--pemfilespath', 'C:\CertIntel\staging-certs',
    '--installation', 'none',
    '--accepttos', '--emailaddress', '[email protected]',
    '--baseuri', 'https://acme-staging-v02.api.letsencrypt.org/'
)
New-Item -ItemType Directory -Force 'C:\CertIntel\staging-certs' | Out-Null
.\wacs.exe @arguments

Check that validation succeeds, certificate files appear, and CertIntel no longer contains either challenge. Leave Validation.AllowDnsSubstitution and Validation.PreValidateDns enabled. The plugin accepts the exact configured CNAME target when the host follows the alias. Configure Validation.DnsPropagationDelay if your simple-acme version needs an additional wait.

Subsequent renewals reuse the native settings and protected key or vault reference. The command line also defaults to https://api.certin.tel/api/v1; add --certintelapibase 'https://your-server.example/api/v1' to override it. Test a staging renewal using your client's renewal management menu. Keep staging and production renewal definitions separate; when satisfied, create a production renewal without the staging --baseuri.

Multiple delegations

Use Add in the interactive delegation menu. For unattended setup, pass comma-separated values in matching domain order:

# Use these validation arguments with the other issuance arguments above.
$validationArguments = @(
    '--validationmode', 'dns-01', '--validation', 'certintel',
    '--certinteldomain', 'example.com,www.example.com',
    '--certinteldelegationid', '11111111-1111-1111-1111-111111111111,22222222-2222-2222-2222-222222222222',
    '--certintelcnametarget', 'FIRST-LABEL.dns01.certin.tel,SECOND-LABEL.dns01.certin.tel',
    '--certintelapikey', 'vault://json/certintel-example,vault://json/certintel-www'
)

The API base and API key may each be a single shared value or one value per domain. A shared CertIntel DNS API key must have access to every delegation. Domain, delegation ID and CNAME target lists must have equal lengths. Unattended setup saves the same native renewal settings as interactive setup. An unresolved vault reference fails before any HTTP request.

Restrict write access to the client's configuration directory to the renewal account and administrators. Native settings use that directory for locks. Do not mix independent issuing clients/configuration directories against one delegation, see delegation ownership.

Troubleshooting

Symptom Check
CertIntel does not appear in validation help Use the matching x64 pluggable client, unblock the DLL beside wacs.exe, and restart.
API 401/403 Verify the update secret or DNS API key grants, delegation status and HTTPS API base.
CNAME mismatch or missing mapping Use the full CNAME target from CertIntel and an exact mapping for each certificate name.
Vault reference cannot be resolved Check that the named secret exists in this client's vault and is accessible to the renewal account.
DNS validation fails Verify the permanent CNAME and public TXT answers; allow for propagation and keep DNS substitution/prevalidation enabled.
Delegation already has two TXT values Check for another issuer; remove stale values only after confirming that no issuance is active.

Invalid identifier at order creation

If the CA rejects an order with Domain name contains an invalid character, check the requested certificate hostname. Underscores are not allowed in certificate hostnames: use certintel-plugin.example.com, for example, instead of certintel_plugin.example.com. This rejection happens before the CertIntel plugin publishes a TXT value.

For an IIS source, update the Host name in the site's binding and select that binding in the renewal. The site's display name can stay unchanged. Update the CertIntel domain mapping and the permanent DNS CNAME owner to match the corrected hostname. For example, the challenge owner becomes _acme-challenge.certintel-plugin.example.com; the underscore in _acme-challenge is required and valid. Use the delegation's full CNAME target from CertIntel as the CNAME destination, not as the certificate hostname.

Native setup now rejects underscores and leading/trailing hyphens in configured certificate domain labels. This checks plugin mappings; the client still controls which identifiers it submits to the CA. See the IIS source guide.

Scheduled renewal and reporting

Complete the client's scheduled-task setup and test it under the actual renewal account. Keep the DLL in the client directory and retain access to the client's configuration and credential store. After updating the DLL, restart the client and repeat discovery and a staging renewal test.

DNS validation does not send CertIntel check-ins or certificate inventory. Add the existing simple-acme reporting scripts if you want those reports. The DLL replaces only DNS validation; keep the installation, notification and scheduled check-in scripts with their separate write-scoped reporting key.

Migrating from the custom DNS script

Install the DLL, then edit the renewal's validation step to use CertIntel instead of Custom script. Enter every delegation again, save, and test with a staging renewal. The DLL uses protected native settings or vault references, so it does not read CertIntel-Dns01.delegations.json. Keep the old script and mapping only while another renewal still uses them; retire the old plaintext secrets when migration is complete. Do not configure both validation methods for the same renewal. Leave Validation.AllowDnsSubstitution and Validation.PreValidateDns enabled.