CertIntel plugin for win-acme¶
Use CertIntel delegated DNS-01 with win-acme. The native DLL publishes and removes challenge TXT values; win-acme owns certificate issuance, storage, installation and renewal. A CertIntel Agent is not required.
Download: use verified downloads, selecting win-acme.
Install¶
Use the Windows x64 pluggable win-acme release. The plugin was tested with 2.2.9.1701. Download the DLL for this client; simple-acme and win-acme use different builds despite the identical filename.
After verification succeeds, copy PKISharp.WACS.Plugins.ValidationPlugins.CertIntel.dll from the matching
package into the directory containing wacs.exe. Unblock the downloaded DLL if
Windows marked it as downloaded (Unblock-File '.\PKISharp.WACS.Plugins.ValidationPlugins.CertIntel.dll'), then restart the client.
Do not copy host libraries from a build's bin folder, and do not put both DLL
variants in the same client directory. A trimmed client cannot load this plugin.
Releases use Authenticode-signed DLLs and signed manifests. Unblocking a file is not signature verification.
Follow delegation setup to create the delegation
and permanent _acme-challenge CNAME in CertIntel and your DNS provider first. Configure one or more delegations entirely in the client,
using its built-in credential handling. No separate JSON file is needed.
Confirm discovery without creating an order:
The help should show CertIntel, --certintelapikey, and the configuration arguments.
Interactive use¶
Create a certificate with full options, select the desired names, choose DNS-01
validation, and select Create DNS-01 verification records in CertIntel.
The plugin asks for each delegation's certificate domain, API base,
delegation UUID and full CNAME target. The API base defaults to
https://api.certin.tel/api/v1: press Enter to accept it, or enter a different
HTTPS endpoint including /api/v1. Additional delegations reuse the previous
entry's endpoint as their default. At the API key
prompt, select an existing vault secret or enter a key through the client's
password prompt. The key uses the host's ProtectedString handling and is stored
according to its Security.EncryptConfig setting; leave encryption enabled.
After the first entry, the plugin shows a menu to Add, Edit, or Remove delegations. Add an entry for every distinct certificate name that needs a mapping. Choose Use these delegations when finished. During editing, Enter keeps the displayed field value; credentials use the host's secret selection menu.
Complete the certificate setup normally. The ACME client automatically saves the delegation list and protected keys or vault references in its own renewal settings. The DLL does not create a separate configuration file, and users do not edit JSON. Scheduled renewals load the saved settings without prompting.
To create a reusable vault entry first, use More options → Manage secrets in
the host. A secret named certintel-example is referenced as
vault://json/certintel-example. The plugin resolves it through the host's secret
manager at runtime, so the actual key does not need to appear in command-line
arguments. Each delegation can use a different key. The client manages its own renewal
and vault files. See the official simple-acme secrets guide
and win-acme secrets guide.
Choose certificate storage and installation options in the host client. The
CertIntel plugin performs only DNS validation. example.com also covers its
wildcard, but other certificate names require their own exact mappings.
To change mappings later, use Manage renewals → Edit renewal and reconfigure the CertIntel validation step. The host starts a fresh validation setup, so enter the full desired list again; it saves the replacement when you complete the edit. To rotate a vault-backed key, update that secret through Manage secrets. The plugin resolves the current vault value on each operation, without changing mappings.
Staging test from PowerShell¶
Replace the domains, email and paths. This creates a staging certificate in the client's file store; it does not install it into a web server.
$arguments = @(
'--source', 'manual',
'--host', 'example.com,*.example.com',
'--validationmode', 'dns-01',
'--validation', 'certintel',
'--certinteldomain', 'example.com',
'--certinteldelegationid', '11111111-1111-1111-1111-111111111111',
'--certintelcnametarget', 'YOUR-LABEL.dns01.certin.tel',
'--certintelapikey', 'vault://json/certintel-example',
'--store', 'pemfiles',
'--pemfilespath', 'C:\CertIntel\staging-certs',
'--installation', 'none',
'--accepttos', '--emailaddress', '[email protected]',
'--baseuri', 'https://acme-staging-v02.api.letsencrypt.org/'
)
New-Item -ItemType Directory -Force 'C:\CertIntel\staging-certs' | Out-Null
.\wacs.exe @arguments
Check that validation succeeds, certificate files appear, and CertIntel no longer
contains either challenge. Leave Validation.AllowDnsSubstitution and
Validation.PreValidateDns enabled. The plugin accepts the exact configured CNAME
target when the host follows the alias. Allow time for public DNS propagation before retrying a failed validation.
Subsequent renewals reuse the native settings and protected key or vault reference.
The command line also defaults to https://api.certin.tel/api/v1; add
--certintelapibase 'https://your-server.example/api/v1' to override it.
Test a staging renewal using your client's
renewal management menu. Keep staging and production renewal definitions separate;
when satisfied, create a production renewal without the staging --baseuri.
Multiple delegations¶
Use Add in the interactive delegation menu. For unattended setup, pass comma-separated values in matching domain order:
# Use these validation arguments with the other issuance arguments above.
$validationArguments = @(
'--validationmode', 'dns-01', '--validation', 'certintel',
'--certinteldomain', 'example.com,www.example.com',
'--certinteldelegationid', '11111111-1111-1111-1111-111111111111,22222222-2222-2222-2222-222222222222',
'--certintelcnametarget', 'FIRST-LABEL.dns01.certin.tel,SECOND-LABEL.dns01.certin.tel',
'--certintelapikey', 'vault://json/certintel-example,vault://json/certintel-www'
)
The API base and API key may each be a single shared value or one value per domain. A shared CertIntel DNS API key must have access to every delegation. Domain, delegation ID and CNAME target lists must have equal lengths. Unattended setup saves the same native renewal settings as interactive setup. An unresolved vault reference fails before any HTTP request.
Restrict write access to the client's configuration directory to the renewal account and administrators. Native settings use that directory for locks. Do not mix independent issuing clients/configuration directories against one delegation, see delegation ownership.
Troubleshooting¶
| Symptom | Check |
|---|---|
| CertIntel does not appear in validation help | Use the matching x64 pluggable client, unblock the DLL beside wacs.exe, and restart. |
| API 401/403 | Verify the update secret or DNS API key grants, delegation status and HTTPS API base. |
| CNAME mismatch or missing mapping | Use the full CNAME target from CertIntel and an exact mapping for each certificate name. |
| Vault reference cannot be resolved | Check that the named secret exists in this client's vault and is accessible to the renewal account. |
| DNS validation fails | Verify the permanent CNAME and public TXT answers; allow for propagation and keep DNS substitution/prevalidation enabled. |
| Delegation already has two TXT values | Check for another issuer; remove stale values only after confirming that no issuance is active. |
Invalid identifier at order creation¶
If the CA rejects an order with Domain name contains an invalid character,
check the requested certificate hostname. Underscores are not allowed in
certificate hostnames: use certintel-plugin.example.com, for example, instead
of certintel_plugin.example.com. This rejection happens before the CertIntel
plugin publishes a TXT value.
For an IIS source, update the Host name in the site's binding and select
that binding in the renewal. The site's display name can stay unchanged.
Update the CertIntel domain mapping and the permanent DNS CNAME owner to match
the corrected hostname. For example, the challenge owner becomes
_acme-challenge.certintel-plugin.example.com; the underscore in
_acme-challenge is required and valid. Use the delegation's full CNAME target
from CertIntel as the CNAME destination, not as the certificate hostname.
Native setup now rejects underscores and leading/trailing hyphens in configured certificate domain labels. This checks plugin mappings; the client still controls which identifiers it submits to the CA. See the IIS source guide.
Scheduled renewal and reporting¶
Complete the client's scheduled-task setup and test it under the actual renewal account. Keep the DLL in the client directory and retain access to the client's configuration and credential store. After updating the DLL, restart the client and repeat discovery and a staging renewal test.
DNS validation does not send CertIntel check-ins or certificate inventory. The wiki's simple-acme notification scripts use simple-acme-specific hooks and placeholders; do not assume they are a tested win-acme reporting bundle. Use the reporting API if you need a separate win-acme reporting integration. The win-acme DNS plugin itself has been tested successfully.