Posh-ACME — acme.rtegroup.ie

← Back to app
← Back to the user guide
Only reachable from the corporate network/VPN — same as the app itself. You'll also need an approved hostname and a team API key before starting below.

1. Install Posh-ACME

powershell
Install-Module -Name Posh-ACME -Scope CurrentUser

2. Add the RTÉ DNS plugin

  1. 1Create a folder to hold custom plugins, e.g. C:\PoshAcmePlugins.
  2. 2Click Copy code below.
  3. 3Create a new file named RteDns.ps1 inside that folder and paste the copied text into it.
  4. 4Point Posh-ACME at the folder (add this to your PowerShell profile so it persists across sessions):
powershell
$env:POSHACME_PLUGINS = 'C:\PoshAcmePlugins'
RteDns.ps1
<#
Custom Posh-ACME DNS plugin for acme.rtegroup.ie.

Install: create a folder (e.g. C:\PoshAcmePlugins), create a file named RteDns.ps1
inside it, and paste this in. Then point Posh-ACME at that folder:
  $env:POSHACME_PLUGINS = 'C:\PoshAcmePlugins'
Step-by-step instructions: https://acme.rtegroup.ie/docs/posh-acme

Use:
  $key = ConvertTo-SecureString 'rtdns_...' -AsPlainText -Force
  New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{ RteDnsApiKey = $key } -DnsSleep 30

Optionally pass RteDnsLeAccountUri (and RteDnsLeIssuer, default letsencrypt.org) in
PluginArgs. Not required for normal issuance — if set, it's recorded server-side against
this hostname so that once DNS-PERSIST-01 is available
(https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00), we already know
which ACME account(s) have been issuing for it. Your account URI is available via
(Get-PAAccount).location once you've registered:
  New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{
    RteDnsApiKey = $key
    RteDnsLeAccountUri = (Get-PAAccount).location
  } -DnsSleep 30

See https://acme.rtegroup.ie/docs/posh-acme for the full walkthrough.
#>

function Get-CurrentPluginType { 'dns-01' }

function Add-DnsTxt {
    [CmdletBinding()]
    param(
        [Parameter(Mandatory, Position = 0)][string]$RecordName,
        [Parameter(Mandatory, Position = 1)][string]$TxtValue,
        [Parameter(Mandatory)][securestring]$RteDnsApiKey,
        [Parameter()][string]$RteDnsLeAccountUri,
        [Parameter()][string]$RteDnsLeIssuer,
        [Parameter(ValueFromRemainingArguments)]$ExtraParams
    )
    Invoke-RteDns -Action present -RecordName $RecordName -TxtValue $TxtValue -ApiKey $RteDnsApiKey `
        -LeAccountUri $RteDnsLeAccountUri -LeIssuer $RteDnsLeIssuer
}

function Remove-DnsTxt {
    [CmdletBinding()]
    param(
        [Parameter(Mandatory, Position = 0)][string]$RecordName,
        [Parameter(Mandatory, Position = 1)][string]$TxtValue,
        [Parameter(Mandatory)][securestring]$RteDnsApiKey,
        [Parameter()][string]$RteDnsLeAccountUri,
        [Parameter()][string]$RteDnsLeIssuer,
        [Parameter(ValueFromRemainingArguments)]$ExtraParams
    )
    Invoke-RteDns -Action cleanup -RecordName $RecordName -TxtValue $TxtValue -ApiKey $RteDnsApiKey `
        -LeAccountUri $RteDnsLeAccountUri -LeIssuer $RteDnsLeIssuer
}

function Save-DnsTxt {
    [CmdletBinding()]
    param([Parameter(ValueFromRemainingArguments)]$ExtraParams)
    # No batching needed — present/cleanup take effect immediately.
}

function Invoke-RteDns {
    param(
        [Parameter(Mandatory)][ValidateSet('present', 'cleanup')][string]$Action,
        [Parameter(Mandatory)][string]$RecordName,
        [Parameter(Mandatory)][string]$TxtValue,
        [Parameter(Mandatory)][securestring]$ApiKey,
        [Parameter()][string]$LeAccountUri,
        [Parameter()][string]$LeIssuer
    )
    $plainKey = [pscredential]::new('a', $ApiKey).GetNetworkCredential().Password
    $base = if ($env:RTEDNS_API_BASE) { $env:RTEDNS_API_BASE } else { 'https://acme.rtegroup.ie' }

    $payload = @{ hostname = $RecordName; value = $TxtValue }
    if ($LeAccountUri) {
        $payload.leAccountUri = $LeAccountUri
        $payload.leIssuer = if ($LeIssuer) { $LeIssuer } else { 'letsencrypt.org' }
    }
    $body = $payload | ConvertTo-Json

    Invoke-RestMethod -Uri "$base/api/dns/$Action" -Method Post `
        -Headers @{ Authorization = "Bearer $plainKey" } `
        -ContentType 'application/json' -Body $body @script:UseBasic | Out-Null
}

3. Request the certificate

Your API key gets passed in as a secure string, not an environment variable, for this client:

powershell
$key = ConvertTo-SecureString 'rtdns_your_team_key_here' -AsPlainText -Force
New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{ RteDnsApiKey = $key } -DnsSleep 30

-DnsSleep 30 gives the TXT record time to propagate before Let's Encrypt checks it. Renew with Submit-Renewal — it reuses the same plugin args automatically.

Optional: link this to your ACME account for DNS-PERSIST-01

Not required for normal issuance. If you want to set RteDnsLeAccountUri, your account URI is available once you've registered:

powershell
New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{
    RteDnsApiKey = $key
    RteDnsLeAccountUri = (Get-PAAccount).location
} -DnsSleep 30