πŸ€– ACMEΒΆ

The CA ships with an acme provisioner, which allows any ACME client to issue certificates automatically.

Directory URLΒΆ

Point your ACME client to the following directory URL:

https://{FQDN}/acme/acme/directory

Important

The ACME client must trust the CA’s root certificate, otherwise it can’t connect to the directory URL. Get the root certificate via πŸ‘£ step CLI or as described in πŸš€ Deployment.

Note

ACME certificates are short-lived (24 hours by default), so make sure your ACME client renews them regularly.

certbotΒΆ

To issue a certificate via certbot:

REQUESTS_CA_BUNDLE=/path/to/root_ca.crt \
certbot certonly \
    --standalone \
    --server https://{FQDN}/acme/acme/directory \
    -d {Subject}

Reverse proxiesΒΆ

To issue certificates via a reverse proxy, such as Traefik or Caddy, check out the ACME sections in the πŸ›‘οΈ Reverse proxy chapter.