Only reachable from the corporate network/VPN — same as the app itself. You'll also
need an approved hostname and a team API key before starting below.
On Windows, run certbot inside WSL.
1. Install certbot
Usually available via your distro's package manager, e.g.:
shell
sudo apt install certbotSee the certbot install instructions if that doesn't apply to you.
2. Create the two hook scripts
certbot's manual plugin runs one script to create the TXT record and another to
delete it. Pick a folder to keep them in, e.g. ~/rtedns-hooks, then create
both files below inside it.
rtedns-auth-hook.sh
- 1Click Copy code below.
- 2Create a new file at
~/rtedns-hooks/rtedns-auth-hook.shand paste the copied text into it. - 3Make it executable:
chmod +x ~/rtedns-hooks/rtedns-auth-hook.sh
rtedns-auth-hook.sh
#!/usr/bin/env bash
# certbot --manual-auth-hook for acme.rtegroup.ie.
#
# Install: create rtedns-auth-hook.sh and rtedns-cleanup-hook.sh (see the companion
# file) anywhere on the machine running certbot, paste each one in, and
# chmod +x both. Step-by-step instructions: https://acme.rtegroup.ie/docs/certbot
#
# Usage:
# export RTEDNS_API_KEY="rtdns_..."
# certbot certonly --manual --preferred-challenges dns \
# --manual-auth-hook /path/to/rtedns-auth-hook.sh \
# --manual-cleanup-hook /path/to/rtedns-cleanup-hook.sh \
# -d dev.rtegroup.ie
#
# certbot sets $CERTBOT_DOMAIN and $CERTBOT_VALIDATION for manual hooks.
#
# Optionally set RTEDNS_LE_ACCOUNT_URI (and RTEDNS_LE_ISSUER, default letsencrypt.org).
# Not required for normal issuance — if set, it's recorded server-side against this
# hostname so that once DNS-PERSIST-01 is available
# (https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00), we already
# know which ACME account(s) have been issuing for it. Find yours with
# `certbot show_account` or in /etc/letsencrypt/accounts//directory//regr.json.
set -euo pipefail
: "${RTEDNS_API_KEY:?RTEDNS_API_KEY is not set}"
API_BASE="${RTEDNS_API_BASE:-https://acme.rtegroup.ie}"
RECORD="_acme-challenge.${CERTBOT_DOMAIN}"
LE_FIELDS=""
if [ -n "${RTEDNS_LE_ACCOUNT_URI:-}" ]; then
LE_FIELDS=$(printf ',"leAccountUri":"%s","leIssuer":"%s"' \
"$RTEDNS_LE_ACCOUNT_URI" "${RTEDNS_LE_ISSUER:-letsencrypt.org}")
fi
curl -fsS -X POST "${API_BASE}/api/dns/present" \
-H "Authorization: Bearer ${RTEDNS_API_KEY}" \
-H "Content-Type: application/json" \
-d "{\"hostname\":\"${RECORD}\",\"value\":\"${CERTBOT_VALIDATION}\"${LE_FIELDS}}"
# DNS propagation isn't instant — give it a moment before certbot validates.
sleep 20 rtedns-cleanup-hook.sh
- 1Click Copy code below.
- 2Create a new file at
~/rtedns-hooks/rtedns-cleanup-hook.shand paste the copied text into it. - 3Make it executable:
chmod +x ~/rtedns-hooks/rtedns-cleanup-hook.sh
rtedns-cleanup-hook.sh
#!/usr/bin/env bash
# certbot --manual-cleanup-hook for acme.rtegroup.ie. See rtedns-auth-hook.sh.
# Install: create rtedns-cleanup-hook.sh next to rtedns-auth-hook.sh and paste this in,
# then chmod +x it. Step-by-step instructions: https://acme.rtegroup.ie/docs/certbot
set -euo pipefail
: "${RTEDNS_API_KEY:?RTEDNS_API_KEY is not set}"
API_BASE="${RTEDNS_API_BASE:-https://acme.rtegroup.ie}"
RECORD="_acme-challenge.${CERTBOT_DOMAIN}"
LE_FIELDS=""
if [ -n "${RTEDNS_LE_ACCOUNT_URI:-}" ]; then
LE_FIELDS=$(printf ',"leAccountUri":"%s","leIssuer":"%s"' \
"$RTEDNS_LE_ACCOUNT_URI" "${RTEDNS_LE_ISSUER:-letsencrypt.org}")
fi
curl -fsS -X POST "${API_BASE}/api/dns/cleanup" \
-H "Authorization: Bearer ${RTEDNS_API_KEY}" \
-H "Content-Type: application/json" \
-d "{\"hostname\":\"${RECORD}\",\"value\":\"${CERTBOT_VALIDATION}\"${LE_FIELDS}}"3. Set your API key
shell
export RTEDNS_API_KEY="rtdns_your_team_key_here"4. Request the certificate
shell
certbot certonly --manual --preferred-challenges dns \
--manual-auth-hook ~/rtedns-hooks/rtedns-auth-hook.sh \
--manual-cleanup-hook ~/rtedns-hooks/rtedns-cleanup-hook.sh \
-d dev.rtegroup.iecertbot calls both hooks automatically. For renewals, add
--preferred-challenges dns and the same two --manual-*-hook
flags to your renewal config (or let certbot renew reuse the settings it
saved from this first run).
Optional: link this to your ACME account for DNS-PERSIST-01
Not required for normal issuance. If you want to set
RTEDNS_LE_ACCOUNT_URI, find your account with:
shell
certbot show_accountor look in /etc/letsencrypt/accounts/<server>/directory/<id>/regr.json,
then export it alongside your API key:
shell
export RTEDNS_LE_ACCOUNT_URI="https://acme-v02.api.letsencrypt.org/acme/acct/123456789"