acme.rtegroup.ie — user guide

← Back to app
Only reachable from the corporate network/VPN — same as the app itself.

1. Get access

  1. 1Sign in at acme.rtegroup.ie (Entra ID SSO).
  2. 2Request the hostname you need (e.g. dev.rtegroup.ie). This goes to an admin for approval — you'll get a Teams notification either way.
  3. 3Once approved, a team admin generates an API key from the same page (Team → API keys → Create new API key). The raw key is shown once — save it somewhere safe (a password manager, not a text file on your desktop). You'll paste this key into whichever tool you pick below.

That key only works for hostnames your team has been granted — anything else is rejected before it ever reaches Cloudflare.

2. Pick the tool you're using to get your certificate

Not sure which one? If you're not sure, win-acme is the most common choice on Windows, and acme.sh is the most common choice on Linux/macOS.

Troubleshooting

Building something custom? (API reference)

If your ACME client isn't one of the four above, or you're integrating something of your own, two endpoints do all the work — both need Authorization: Bearer <your API key>, both only reachable from the corporate network:

HTTP
POST https://acme.rtegroup.ie/api/dns/present
POST https://acme.rtegroup.ie/api/dns/cleanup
Content-Type: application/json

{ "hostname": "_acme-challenge.dev.rtegroup.ie", "value": "<the TXT record content your ACME client gives you>" }

Both are idempotent (safe to call more than once) and return {"ok": true, ...} on success, or a 4xx with {"error": "..."} explaining why (wrong hostname, revoked key, etc). Allow ~20–30 seconds after present before asking Let's Encrypt to validate, so the TXT record has time to propagate.

Both endpoints also accept two optional fields, leAccountUri and leIssuer (defaults to letsencrypt.org if omitted). These aren't used for authorization or validation — they're recorded server-side against the hostname so that once DNS-PERSIST-01 is available, we already know which ACME account(s) have been issuing for it. Each client page above shows how to set this if you want to.