1. Get access
- 1Sign in at acme.rtegroup.ie (Entra ID SSO).
- 2Request the hostname you need (e.g.
dev.rtegroup.ie). This goes to an admin for approval — you'll get a Teams notification either way. - 3Once approved, a team admin generates an API key from the same page (Team → API keys → Create new API key). The raw key is shown once — save it somewhere safe (a password manager, not a text file on your desktop). You'll paste this key into whichever tool you pick below.
That key only works for hostnames your team has been granted — anything else is rejected before it ever reaches Cloudflare.
2. Pick the tool you're using to get your certificate
Not sure which one? If you're not sure, win-acme is the most common choice on Windows, and acme.sh is the most common choice on Linux/macOS.
Troubleshooting
- 401 Invalid or revoked API key — check the key was copied in full, and hasn't been revoked in the GUI (Team → API keys).
- 403 not authorized for that hostname — your team doesn't have an approved grant for that exact hostname. Request it in the GUI first.
- Can't reach acme.rtegroup.ie at all — the app (and its API) is restricted to the corporate network/VPN by design; confirm you're on it.
- Let's Encrypt says the TXT record wasn't found — DNS propagation delay. Increase the pause your client uses between creating the record and asking Let's Encrypt to check it (20–30s is usually enough; try longer if it keeps failing).
Building something custom? (API reference)
If your ACME client isn't one of the four above, or you're integrating something of
your own, two endpoints do all the work — both need
Authorization: Bearer <your API key>, both only reachable from the
corporate network:
POST https://acme.rtegroup.ie/api/dns/present
POST https://acme.rtegroup.ie/api/dns/cleanup
Content-Type: application/json
{ "hostname": "_acme-challenge.dev.rtegroup.ie", "value": "<the TXT record content your ACME client gives you>" }Both are idempotent (safe to call more than once) and return
{"ok": true, ...} on success, or a 4xx with
{"error": "..."} explaining why (wrong hostname, revoked key, etc). Allow
~20–30 seconds after present before asking Let's Encrypt to validate, so
the TXT record has time to propagate.
Both endpoints also accept two optional fields, leAccountUri
and leIssuer (defaults to letsencrypt.org if omitted). These
aren't used for authorization or validation — they're recorded server-side against the
hostname so that once DNS-PERSIST-01
is available, we already know which ACME account(s) have been issuing for it. Each
client page above shows how to set this if you want to.