acme.sh — acme.rtegroup.ie

← Back to app
← Back to the user guide
Only reachable from the corporate network/VPN — same as the app itself. You'll also need an approved hostname and a team API key before starting below.

1. Install acme.sh

If it isn't already installed on the machine you're issuing certificates from (Linux, macOS, or Windows via WSL):

shell
curl https://get.acme.sh | sh -s email=you@rte.ie

See the acme.sh project page if you'd rather install a different way.

Then set Let's Encrypt as the default CA and turn on auto-upgrade (one-time, recommended):

shell
acme.sh --set-default-ca --server letsencrypt
acme.sh --upgrade --auto-upgrade

2. Add the RTÉ DNS hook

acme.sh looks for DNS provider hooks in a dnsapi folder inside its home directory (usually ~/.acme.sh/dnsapi). You need to put one file there:

  1. 1Click Copy code below.
  2. 2Create a new file at ~/.acme.sh/dnsapi/dns_rtedns.sh (create the dnsapi folder first if it doesn't exist yet) and paste the copied text into it.
  3. 3Make it executable: chmod +x ~/.acme.sh/dnsapi/dns_rtedns.sh
dns_rtedns.sh
# acme.sh dnsapi hook for acme.rtegroup.ie
#
# Install: create ~/.acme.sh/dnsapi/dns_rtedns.sh and paste this file's contents into
# it. Step-by-step instructions: https://acme.rtegroup.ie/docs/acme-sh
# (If you're working from this repo directly, cp hooks/dns_rtedns.sh
# ~/.acme.sh/dnsapi/dns_rtedns.sh does the same thing.)
#
# Configure:
#   export RTEDNS_API_KEY="rtdns_..."          # team API key from the acme.rtegroup.ie GUI
#   export RTEDNS_API_BASE="https://acme.rtegroup.ie"   # optional, this is the default
#   export RTEDNS_LE_ACCOUNT_URI="https://acme-v02.api.letsencrypt.org/acme/acct/..."
#                                               # optional — see note below
#   export RTEDNS_LE_ISSUER="letsencrypt.org"  # optional, defaults to letsencrypt.org
#                                               # if RTEDNS_LE_ACCOUNT_URI is set
#
# Use:
#   acme.sh --issue -d dev.rtegroup.ie --dns dns_rtedns
#
# Requires network access to acme.rtegroup.ie, which is itself restricted to the
# corporate network by a Cloudflare Access policy — run this from a host on that network.
#
# About RTEDNS_LE_ACCOUNT_URI: not required for normal DNS-01 issuance. If set, it's
# recorded server-side against this hostname so that once DNS-PERSIST-01
# (https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00) is available,
# we already know which ACME account(s) have been issuing for it. Easiest way to get it:
#   acme.sh --make-dns-persist-value -d dev.rtegroup.ie
# which prints a line like:
#   TXT persist value :"letsencrypt.org; accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/123456789"
# — copy the accounturi= value. (You don't need to actually publish that TXT record or
# use --dns-persist for issuance yet; this is just the easiest way acme.sh will tell you
# your account URI today.)

RTEDNS_API_BASE_DEFAULT="https://acme.rtegroup.ie"

dns_rtedns_add() {
  fulldomain=$1
  txtvalue=$2
  _rtedns_call "present" "$fulldomain" "$txtvalue"
}

dns_rtedns_rm() {
  fulldomain=$1
  txtvalue=$2
  _rtedns_call "cleanup" "$fulldomain" "$txtvalue"
}

_rtedns_call() {
  action="$1"
  fulldomain="$2"
  txtvalue="$3"

  if [ -z "$RTEDNS_API_KEY" ]; then
    _err "RTEDNS_API_KEY is not set."
    return 1
  fi

  api_base="${RTEDNS_API_BASE:-$RTEDNS_API_BASE_DEFAULT}"
  url="${api_base}/api/dns/${action}"

  _info "rtedns: ${action} ${fulldomain}"

  le_fields=""
  if [ -n "$RTEDNS_LE_ACCOUNT_URI" ]; then
    le_fields=$(printf ',"leAccountUri":"%s","leIssuer":"%s"' \
      "$RTEDNS_LE_ACCOUNT_URI" "${RTEDNS_LE_ISSUER:-letsencrypt.org}")
  fi
  body=$(printf '{"hostname":"%s","value":"%s"%s}' "$fulldomain" "$txtvalue" "$le_fields")

  response=$(curl -s -w '\n%{http_code}' -X POST "$url" \
    -H "Authorization: Bearer ${RTEDNS_API_KEY}" \
    -H "Content-Type: application/json" \
    -d "$body")

  http_code=$(printf '%s' "$response" | tail -n1)
  http_body=$(printf '%s' "$response" | sed '$d')

  if [ "$http_code" -ge 200 ] 2>/dev/null && [ "$http_code" -lt 300 ] 2>/dev/null; then
    _info "rtedns: ${action} succeeded"
    return 0
  fi

  _err "rtedns: ${action} failed (HTTP ${http_code}): ${http_body}"
  return 1
}

3. Set your API key

Add this to your shell (or ~/.bashrc/~/.zshrc so it persists):

shell
export RTEDNS_API_KEY="rtdns_your_team_key_here"

4. Request the certificate

shell
acme.sh --issue -d dev.rtegroup.ie --dns dns_rtedns \
  --keylength ec-384 \
  --preferred-profile tlsserver

acme.sh will call your hook automatically to create and clean up the _acme-challenge TXT record — nothing else to do. Renewals (acme.sh --renew or the cron job it installs) reuse the same hook, API key, and flags from this first run.

--keylength ec-384 issues an EC-384 key instead of the RSA default. --preferred-profile tlsserver opts into Let's Encrypt's short-lived (45-day) certificate profile now, while renewal is still on your terms — rather than having it forced on you later when short-lived certs become the default and your renewal automation hasn't been tested against a tighter cycle.

Optional: link this to your ACME account for DNS-PERSIST-01

Not required for normal issuance. If you want to set RTEDNS_LE_ACCOUNT_URI, the easiest way to find your account URI is:

shell
acme.sh --make-dns-persist-value -d dev.rtegroup.ie

which prints a line like TXT persist value :"letsencrypt.org; accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/123456789" — copy the accounturi= value into RTEDNS_LE_ACCOUNT_URI. You don't need to publish that TXT record or use --dns-persist for issuance today.