1. Install acme.sh
If it isn't already installed on the machine you're issuing certificates from (Linux, macOS, or Windows via WSL):
curl https://get.acme.sh | sh -s email=you@rte.ieSee the acme.sh project page if you'd rather install a different way.
Then set Let's Encrypt as the default CA and turn on auto-upgrade (one-time, recommended):
acme.sh --set-default-ca --server letsencrypt
acme.sh --upgrade --auto-upgrade2. Add the RTÉ DNS hook
acme.sh looks for DNS provider hooks in a dnsapi folder inside its home
directory (usually ~/.acme.sh/dnsapi). You need to put one file there:
- 1Click Copy code below.
- 2Create a new file at
~/.acme.sh/dnsapi/dns_rtedns.sh(create thednsapifolder first if it doesn't exist yet) and paste the copied text into it. - 3Make it executable:
chmod +x ~/.acme.sh/dnsapi/dns_rtedns.sh
# acme.sh dnsapi hook for acme.rtegroup.ie
#
# Install: create ~/.acme.sh/dnsapi/dns_rtedns.sh and paste this file's contents into
# it. Step-by-step instructions: https://acme.rtegroup.ie/docs/acme-sh
# (If you're working from this repo directly, cp hooks/dns_rtedns.sh
# ~/.acme.sh/dnsapi/dns_rtedns.sh does the same thing.)
#
# Configure:
# export RTEDNS_API_KEY="rtdns_..." # team API key from the acme.rtegroup.ie GUI
# export RTEDNS_API_BASE="https://acme.rtegroup.ie" # optional, this is the default
# export RTEDNS_LE_ACCOUNT_URI="https://acme-v02.api.letsencrypt.org/acme/acct/..."
# # optional — see note below
# export RTEDNS_LE_ISSUER="letsencrypt.org" # optional, defaults to letsencrypt.org
# # if RTEDNS_LE_ACCOUNT_URI is set
#
# Use:
# acme.sh --issue -d dev.rtegroup.ie --dns dns_rtedns
#
# Requires network access to acme.rtegroup.ie, which is itself restricted to the
# corporate network by a Cloudflare Access policy — run this from a host on that network.
#
# About RTEDNS_LE_ACCOUNT_URI: not required for normal DNS-01 issuance. If set, it's
# recorded server-side against this hostname so that once DNS-PERSIST-01
# (https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00) is available,
# we already know which ACME account(s) have been issuing for it. Easiest way to get it:
# acme.sh --make-dns-persist-value -d dev.rtegroup.ie
# which prints a line like:
# TXT persist value :"letsencrypt.org; accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/123456789"
# — copy the accounturi= value. (You don't need to actually publish that TXT record or
# use --dns-persist for issuance yet; this is just the easiest way acme.sh will tell you
# your account URI today.)
RTEDNS_API_BASE_DEFAULT="https://acme.rtegroup.ie"
dns_rtedns_add() {
fulldomain=$1
txtvalue=$2
_rtedns_call "present" "$fulldomain" "$txtvalue"
}
dns_rtedns_rm() {
fulldomain=$1
txtvalue=$2
_rtedns_call "cleanup" "$fulldomain" "$txtvalue"
}
_rtedns_call() {
action="$1"
fulldomain="$2"
txtvalue="$3"
if [ -z "$RTEDNS_API_KEY" ]; then
_err "RTEDNS_API_KEY is not set."
return 1
fi
api_base="${RTEDNS_API_BASE:-$RTEDNS_API_BASE_DEFAULT}"
url="${api_base}/api/dns/${action}"
_info "rtedns: ${action} ${fulldomain}"
le_fields=""
if [ -n "$RTEDNS_LE_ACCOUNT_URI" ]; then
le_fields=$(printf ',"leAccountUri":"%s","leIssuer":"%s"' \
"$RTEDNS_LE_ACCOUNT_URI" "${RTEDNS_LE_ISSUER:-letsencrypt.org}")
fi
body=$(printf '{"hostname":"%s","value":"%s"%s}' "$fulldomain" "$txtvalue" "$le_fields")
response=$(curl -s -w '\n%{http_code}' -X POST "$url" \
-H "Authorization: Bearer ${RTEDNS_API_KEY}" \
-H "Content-Type: application/json" \
-d "$body")
http_code=$(printf '%s' "$response" | tail -n1)
http_body=$(printf '%s' "$response" | sed '$d')
if [ "$http_code" -ge 200 ] 2>/dev/null && [ "$http_code" -lt 300 ] 2>/dev/null; then
_info "rtedns: ${action} succeeded"
return 0
fi
_err "rtedns: ${action} failed (HTTP ${http_code}): ${http_body}"
return 1
}3. Set your API key
Add this to your shell (or ~/.bashrc/~/.zshrc so it persists):
export RTEDNS_API_KEY="rtdns_your_team_key_here"4. Request the certificate
acme.sh --issue -d dev.rtegroup.ie --dns dns_rtedns \
--keylength ec-384 \
--preferred-profile tlsserveracme.sh will call your hook automatically to create and clean up the
_acme-challenge TXT record — nothing else to do. Renewals (acme.sh
--renew or the cron job it installs) reuse the same hook, API key, and flags from
this first run.
--keylength ec-384 issues an EC-384 key instead of the RSA default.
--preferred-profile tlsserver opts into Let's Encrypt's short-lived
(45-day) certificate profile now, while renewal is still on your terms — rather than
having it forced on you later when short-lived certs become the default and your
renewal automation hasn't been tested against a tighter cycle.
Optional: link this to your ACME account for DNS-PERSIST-01
Not required for normal issuance. If you want to set RTEDNS_LE_ACCOUNT_URI,
the easiest way to find your account URI is:
acme.sh --make-dns-persist-value -d dev.rtegroup.iewhich prints a line like TXT persist value :"letsencrypt.org;
accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/123456789" — copy the
accounturi= value into RTEDNS_LE_ACCOUNT_URI. You don't need to
publish that TXT record or use --dns-persist for issuance today.