Configuring ACME DNS
Choose a DNS authenticator and prepare certificate automation.
ACME automates certificate requests and renewal. FreeCORE uses DNS validation: an authenticator publishes a temporary TXT record to show that you control each domain named in the certificate.
Choose a Provider
FreeCORE 15.0 supports Amazon Route 53. FreeCORE 15.1-RC1 also supports Cloudflare, DigitalOcean, OVHcloud and an executable Shell script for your own DNS integration. Use a provider that can change records in the domain's authoritative public DNS zone.
- Go to System > ACME DNS and click ADD.
- Enter a unique Name and choose the Authenticator. On 15.0, leave the provider at Route53.
- Enter the provider credentials or Shell settings, then click SUBMIT.
The ACME DNS reference lists each provider's fields and required access. Restrict credentials to the DNS zones needed for the certificate. Saving the form checks its fields; the complete provider and DNS validation happens when a certificate is requested.
Request a Certificate
Create or import a certificate signing request under System > Certificates, then select Create ACME Certificate from its actions. Assign an authenticator to each domain name, choose the ACME directory and submit the request. Follow Requesting ACME Certificates for the root account email, staging directory, renewal period and complete procedure.
Keep the authenticator and its credentials available for renewal. Before removing one, replace its assignments in certificates that use it.