win-acme — acme.rtegroup.ie

← Back to app
← Back to the user guide
Only reachable from the corporate network/VPN — same as the app itself. You'll also need an approved hostname and a team API key before starting below.

1. Install win-acme

Download the latest release from the win-acme releases page and unzip it somewhere on the machine you're issuing certificates from, e.g. C:\win-acme.

2. Create the DNS script

win-acme's Script DNS validation plugin can run a single combined script for both creating and deleting the TXT record, via its --dnsscript argument. Create a folder to keep it in, e.g. C:\win-acme\rtedns, then create the file below inside it.

rtedns-dns.ps1

  1. 1Click Copy code below.
  2. 2Create a new file named rtedns-dns.ps1 in C:\win-acme\rtedns and paste the copied text into it.
rtedns-dns.ps1
<#
.SYNOPSIS
  win-acme DNS validation script (create + delete) for acme.rtegroup.ie.

.NOTES
  Install: create a file named rtedns-dns.ps1 anywhere on the machine running
  win-acme and paste this in. Step-by-step instructions: https://acme.rtegroup.ie/docs/win-acme

.DESCRIPTION
  Used as a single combined script with win-acme's Script DNS validation
  plugin via --dnsscript, so win-acme only needs one script path instead of
  a create script and a delete script. It relies on win-acme's default
  argument templates ("create {Identifier} {RecordName} {Token}" and
  "delete {Identifier} {RecordName} {Token}") — no --dnscreatescriptarguments
  or --dnsdeletescriptarguments override is needed.

  Reads the API key from the RTEDNS_API_KEY environment variable (set it once
  with `setx RTEDNS_API_KEY "..." /M` from an elevated prompt so the SYSTEM-run
  renewal task can see it, or set it directly on the calling scheduled task)
  rather than passing it on the command line.

  Optionally reads RTEDNS_LE_ACCOUNT_URI (and RTEDNS_LE_ISSUER, default
  letsencrypt.org). Not required for normal issuance — if set, it's recorded
  server-side against this hostname so that once DNS-PERSIST-01 is available
  (https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00), we already
  know which ACME account(s) have been issuing for it.

.PARAMETER Action
  "create" or "delete", supplied automatically by win-acme as the first
  argument.

.PARAMETER Identifier
  The hostname being validated, e.g. dev.rtegroup.ie. Not used by rtedns, but
  accepted so win-acme's default argument layout works unmodified.

.PARAMETER RecordName
  Full TXT record name win-acme wants created/deleted, e.g. _acme-challenge.dev.rtegroup.ie

.PARAMETER Token
  The TXT record content (the ACME challenge token).
#>
param(
    [Parameter(Mandatory = $true, Position = 0)][string]$Action,
    [Parameter(Mandatory = $true, Position = 1)][string]$Identifier,
    [Parameter(Mandatory = $true, Position = 2)][string]$RecordName,
    [Parameter(Mandatory = $true, Position = 3)][string]$Token
)

$ErrorActionPreference = 'Stop'

if (-not $env:RTEDNS_API_KEY) {
    Write-Error "RTEDNS_API_KEY environment variable is not set."
    exit 1
}
$base = if ($env:RTEDNS_API_BASE) { $env:RTEDNS_API_BASE } else { 'https://acme.rtegroup.ie' }

$payload = @{ hostname = $RecordName; value = $Token }
if ($env:RTEDNS_LE_ACCOUNT_URI) {
    $payload.leAccountUri = $env:RTEDNS_LE_ACCOUNT_URI
    $payload.leIssuer = if ($env:RTEDNS_LE_ISSUER) { $env:RTEDNS_LE_ISSUER } else { 'letsencrypt.org' }
}
$body = $payload | ConvertTo-Json

switch ($Action.ToLowerInvariant()) {
    'create' {
        Invoke-RestMethod -Uri "$base/api/dns/present" -Method Post `
            -Headers @{ Authorization = "Bearer $($env:RTEDNS_API_KEY)" } `
            -ContentType 'application/json' -Body $body -UseBasicParsing | Out-Null
        Write-Host "rtedns: created $RecordName"
    }
    'delete' {
        Invoke-RestMethod -Uri "$base/api/dns/cleanup" -Method Post `
            -Headers @{ Authorization = "Bearer $($env:RTEDNS_API_KEY)" } `
            -ContentType 'application/json' -Body $body -UseBasicParsing | Out-Null
        Write-Host "rtedns: cleaned up $RecordName"
    }
    default {
        Write-Error "Unknown action '$Action' (expected create or delete)."
        exit 1
    }
}

3. Set your API key

The renewal scheduled task win-acme creates usually runs as the machine's SYSTEM account, not as you, so set the key machine-wide. Open Command Prompt as administrator and run (only needs doing once — this writes to the machine environment in the registry, so it persists across reboots and is visible to every account, including the scheduled task):

cmd (elevated)
setx RTEDNS_API_KEY "rtdns_your_team_key_here" /M

Open a new Command Prompt window afterwards so it picks up the change. Only do this on a machine dedicated to certificate issuance — /M makes the key readable to every user on the box. If you deliberately configured the renewal task to run as your own user, drop the /M and use a normal Command Prompt.

4. Request the certificate

Run wacs.exe from an elevated Command Prompt (Run as administrator) — it needs admin rights to write certificates to the store and to register its renewal scheduled task. From C:\win-acme, point --dnsscript at the one file — no create/delete argument overrides needed, since the script already accepts win-acme's default arguments:

cmd (elevated)
wacs.exe --target manual --host dev.rtegroup.ie ^
  --validationmode dns-01 --validation script ^
  --dnsscript "C:\win-acme\rtedns\rtedns-dns.ps1"

Prefer the interactive menu? Run wacs.exe (still elevated) with no arguments, choose M (create certificate) → manual input → validation mode Script, and point both the create and delete script prompts at rtedns-dns.ps1, leaving the argument prompts on their defaults. win-acme's built-in scheduled task handles renewals automatically from then on, reusing the same script.

Optional: link this to your ACME account for DNS-PERSIST-01

Not required for normal issuance. If you want to set RTEDNS_LE_ACCOUNT_URI, add it the same way as the API key:

cmd (elevated)
setx RTEDNS_LE_ACCOUNT_URI "https://acme-v02.api.letsencrypt.org/acme/acct/123456789" /M

You can find your account URI in win-acme's registration output, or under %programdata%\win-acme\...\Registration.