certbot — acme.rtegroup.ie

← Back to app
← Back to the user guide
Only reachable from the corporate network/VPN — same as the app itself. You'll also need an approved hostname and a team API key before starting below. On Windows, run certbot inside WSL.

1. Install certbot

Usually available via your distro's package manager, e.g.:

shell
sudo apt install certbot

See the certbot install instructions if that doesn't apply to you.

2. Create the two hook scripts

certbot's manual plugin runs one script to create the TXT record and another to delete it. Pick a folder to keep them in, e.g. ~/rtedns-hooks, then create both files below inside it.

rtedns-auth-hook.sh

  1. 1Click Copy code below.
  2. 2Create a new file at ~/rtedns-hooks/rtedns-auth-hook.sh and paste the copied text into it.
  3. 3Make it executable: chmod +x ~/rtedns-hooks/rtedns-auth-hook.sh
rtedns-auth-hook.sh
#!/usr/bin/env bash
# certbot --manual-auth-hook for acme.rtegroup.ie.
#
# Install: create rtedns-auth-hook.sh and rtedns-cleanup-hook.sh (see the companion
# file) anywhere on the machine running certbot, paste each one in, and
# chmod +x both. Step-by-step instructions: https://acme.rtegroup.ie/docs/certbot
#
# Usage:
#   export RTEDNS_API_KEY="rtdns_..."
#   certbot certonly --manual --preferred-challenges dns \
#     --manual-auth-hook /path/to/rtedns-auth-hook.sh \
#     --manual-cleanup-hook /path/to/rtedns-cleanup-hook.sh \
#     -d dev.rtegroup.ie
#
# certbot sets $CERTBOT_DOMAIN and $CERTBOT_VALIDATION for manual hooks.
#
# Optionally set RTEDNS_LE_ACCOUNT_URI (and RTEDNS_LE_ISSUER, default letsencrypt.org).
# Not required for normal issuance — if set, it's recorded server-side against this
# hostname so that once DNS-PERSIST-01 is available
# (https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00), we already
# know which ACME account(s) have been issuing for it. Find yours with
# `certbot show_account` or in /etc/letsencrypt/accounts//directory//regr.json.
set -euo pipefail

: "${RTEDNS_API_KEY:?RTEDNS_API_KEY is not set}"
API_BASE="${RTEDNS_API_BASE:-https://acme.rtegroup.ie}"
RECORD="_acme-challenge.${CERTBOT_DOMAIN}"

LE_FIELDS=""
if [ -n "${RTEDNS_LE_ACCOUNT_URI:-}" ]; then
  LE_FIELDS=$(printf ',"leAccountUri":"%s","leIssuer":"%s"' \
    "$RTEDNS_LE_ACCOUNT_URI" "${RTEDNS_LE_ISSUER:-letsencrypt.org}")
fi

curl -fsS -X POST "${API_BASE}/api/dns/present" \
  -H "Authorization: Bearer ${RTEDNS_API_KEY}" \
  -H "Content-Type: application/json" \
  -d "{\"hostname\":\"${RECORD}\",\"value\":\"${CERTBOT_VALIDATION}\"${LE_FIELDS}}"

# DNS propagation isn't instant — give it a moment before certbot validates.
sleep 20

rtedns-cleanup-hook.sh

  1. 1Click Copy code below.
  2. 2Create a new file at ~/rtedns-hooks/rtedns-cleanup-hook.sh and paste the copied text into it.
  3. 3Make it executable: chmod +x ~/rtedns-hooks/rtedns-cleanup-hook.sh
rtedns-cleanup-hook.sh
#!/usr/bin/env bash
# certbot --manual-cleanup-hook for acme.rtegroup.ie. See rtedns-auth-hook.sh.
# Install: create rtedns-cleanup-hook.sh next to rtedns-auth-hook.sh and paste this in,
# then chmod +x it. Step-by-step instructions: https://acme.rtegroup.ie/docs/certbot
set -euo pipefail

: "${RTEDNS_API_KEY:?RTEDNS_API_KEY is not set}"
API_BASE="${RTEDNS_API_BASE:-https://acme.rtegroup.ie}"
RECORD="_acme-challenge.${CERTBOT_DOMAIN}"

LE_FIELDS=""
if [ -n "${RTEDNS_LE_ACCOUNT_URI:-}" ]; then
  LE_FIELDS=$(printf ',"leAccountUri":"%s","leIssuer":"%s"' \
    "$RTEDNS_LE_ACCOUNT_URI" "${RTEDNS_LE_ISSUER:-letsencrypt.org}")
fi

curl -fsS -X POST "${API_BASE}/api/dns/cleanup" \
  -H "Authorization: Bearer ${RTEDNS_API_KEY}" \
  -H "Content-Type: application/json" \
  -d "{\"hostname\":\"${RECORD}\",\"value\":\"${CERTBOT_VALIDATION}\"${LE_FIELDS}}"

3. Set your API key

shell
export RTEDNS_API_KEY="rtdns_your_team_key_here"

4. Request the certificate

shell
certbot certonly --manual --preferred-challenges dns \
  --manual-auth-hook ~/rtedns-hooks/rtedns-auth-hook.sh \
  --manual-cleanup-hook ~/rtedns-hooks/rtedns-cleanup-hook.sh \
  -d dev.rtegroup.ie

certbot calls both hooks automatically. For renewals, add --preferred-challenges dns and the same two --manual-*-hook flags to your renewal config (or let certbot renew reuse the settings it saved from this first run).

Optional: link this to your ACME account for DNS-PERSIST-01

Not required for normal issuance. If you want to set RTEDNS_LE_ACCOUNT_URI, find your account with:

shell
certbot show_account

or look in /etc/letsencrypt/accounts/<server>/directory/<id>/regr.json, then export it alongside your API key:

shell
export RTEDNS_LE_ACCOUNT_URI="https://acme-v02.api.letsencrypt.org/acme/acct/123456789"