Only reachable from the corporate network/VPN — same as the app itself. You'll also
need an approved hostname and a team API key before starting below.
1. Install Posh-ACME
powershell
Install-Module -Name Posh-ACME -Scope CurrentUser2. Add the RTÉ DNS plugin
- 1Create a folder to hold custom plugins, e.g.
C:\PoshAcmePlugins. - 2Click Copy code below.
- 3Create a new file named
RteDns.ps1inside that folder and paste the copied text into it. - 4Point Posh-ACME at the folder (add this to your PowerShell profile so it persists across sessions):
powershell
$env:POSHACME_PLUGINS = 'C:\PoshAcmePlugins'RteDns.ps1
<#
Custom Posh-ACME DNS plugin for acme.rtegroup.ie.
Install: create a folder (e.g. C:\PoshAcmePlugins), create a file named RteDns.ps1
inside it, and paste this in. Then point Posh-ACME at that folder:
$env:POSHACME_PLUGINS = 'C:\PoshAcmePlugins'
Step-by-step instructions: https://acme.rtegroup.ie/docs/posh-acme
Use:
$key = ConvertTo-SecureString 'rtdns_...' -AsPlainText -Force
New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{ RteDnsApiKey = $key } -DnsSleep 30
Optionally pass RteDnsLeAccountUri (and RteDnsLeIssuer, default letsencrypt.org) in
PluginArgs. Not required for normal issuance — if set, it's recorded server-side against
this hostname so that once DNS-PERSIST-01 is available
(https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00), we already know
which ACME account(s) have been issuing for it. Your account URI is available via
(Get-PAAccount).location once you've registered:
New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{
RteDnsApiKey = $key
RteDnsLeAccountUri = (Get-PAAccount).location
} -DnsSleep 30
See https://acme.rtegroup.ie/docs/posh-acme for the full walkthrough.
#>
function Get-CurrentPluginType { 'dns-01' }
function Add-DnsTxt {
[CmdletBinding()]
param(
[Parameter(Mandatory, Position = 0)][string]$RecordName,
[Parameter(Mandatory, Position = 1)][string]$TxtValue,
[Parameter(Mandatory)][securestring]$RteDnsApiKey,
[Parameter()][string]$RteDnsLeAccountUri,
[Parameter()][string]$RteDnsLeIssuer,
[Parameter(ValueFromRemainingArguments)]$ExtraParams
)
Invoke-RteDns -Action present -RecordName $RecordName -TxtValue $TxtValue -ApiKey $RteDnsApiKey `
-LeAccountUri $RteDnsLeAccountUri -LeIssuer $RteDnsLeIssuer
}
function Remove-DnsTxt {
[CmdletBinding()]
param(
[Parameter(Mandatory, Position = 0)][string]$RecordName,
[Parameter(Mandatory, Position = 1)][string]$TxtValue,
[Parameter(Mandatory)][securestring]$RteDnsApiKey,
[Parameter()][string]$RteDnsLeAccountUri,
[Parameter()][string]$RteDnsLeIssuer,
[Parameter(ValueFromRemainingArguments)]$ExtraParams
)
Invoke-RteDns -Action cleanup -RecordName $RecordName -TxtValue $TxtValue -ApiKey $RteDnsApiKey `
-LeAccountUri $RteDnsLeAccountUri -LeIssuer $RteDnsLeIssuer
}
function Save-DnsTxt {
[CmdletBinding()]
param([Parameter(ValueFromRemainingArguments)]$ExtraParams)
# No batching needed — present/cleanup take effect immediately.
}
function Invoke-RteDns {
param(
[Parameter(Mandatory)][ValidateSet('present', 'cleanup')][string]$Action,
[Parameter(Mandatory)][string]$RecordName,
[Parameter(Mandatory)][string]$TxtValue,
[Parameter(Mandatory)][securestring]$ApiKey,
[Parameter()][string]$LeAccountUri,
[Parameter()][string]$LeIssuer
)
$plainKey = [pscredential]::new('a', $ApiKey).GetNetworkCredential().Password
$base = if ($env:RTEDNS_API_BASE) { $env:RTEDNS_API_BASE } else { 'https://acme.rtegroup.ie' }
$payload = @{ hostname = $RecordName; value = $TxtValue }
if ($LeAccountUri) {
$payload.leAccountUri = $LeAccountUri
$payload.leIssuer = if ($LeIssuer) { $LeIssuer } else { 'letsencrypt.org' }
}
$body = $payload | ConvertTo-Json
Invoke-RestMethod -Uri "$base/api/dns/$Action" -Method Post `
-Headers @{ Authorization = "Bearer $plainKey" } `
-ContentType 'application/json' -Body $body @script:UseBasic | Out-Null
}3. Request the certificate
Your API key gets passed in as a secure string, not an environment variable, for this client:
powershell
$key = ConvertTo-SecureString 'rtdns_your_team_key_here' -AsPlainText -Force
New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{ RteDnsApiKey = $key } -DnsSleep 30-DnsSleep 30 gives the TXT record time to propagate before Let's Encrypt
checks it. Renew with Submit-Renewal — it reuses the same plugin args
automatically.
Optional: link this to your ACME account for DNS-PERSIST-01
Not required for normal issuance. If you want to set RteDnsLeAccountUri,
your account URI is available once you've registered:
powershell
New-PACertificate dev.rtegroup.ie -Plugin RteDns -PluginArgs @{
RteDnsApiKey = $key
RteDnsLeAccountUri = (Get-PAAccount).location
} -DnsSleep 30