1. Install win-acme
Download the latest release from the
win-acme releases page
and unzip it somewhere on the machine you're issuing certificates from, e.g.
C:\win-acme.
2. Create the DNS script
win-acme's Script DNS validation plugin can run a single combined
script for both creating and deleting the TXT record, via its --dnsscript
argument. Create a folder to keep it in, e.g. C:\win-acme\rtedns, then
create the file below inside it.
rtedns-dns.ps1
- 1Click Copy code below.
- 2Create a new file named
rtedns-dns.ps1inC:\win-acme\rtednsand paste the copied text into it.
<#
.SYNOPSIS
win-acme DNS validation script (create + delete) for acme.rtegroup.ie.
.NOTES
Install: create a file named rtedns-dns.ps1 anywhere on the machine running
win-acme and paste this in. Step-by-step instructions: https://acme.rtegroup.ie/docs/win-acme
.DESCRIPTION
Used as a single combined script with win-acme's Script DNS validation
plugin via --dnsscript, so win-acme only needs one script path instead of
a create script and a delete script. It relies on win-acme's default
argument templates ("create {Identifier} {RecordName} {Token}" and
"delete {Identifier} {RecordName} {Token}") — no --dnscreatescriptarguments
or --dnsdeletescriptarguments override is needed.
Reads the API key from the RTEDNS_API_KEY environment variable (set it once
with `setx RTEDNS_API_KEY "..." /M` from an elevated prompt so the SYSTEM-run
renewal task can see it, or set it directly on the calling scheduled task)
rather than passing it on the command line.
Optionally reads RTEDNS_LE_ACCOUNT_URI (and RTEDNS_LE_ISSUER, default
letsencrypt.org). Not required for normal issuance — if set, it's recorded
server-side against this hostname so that once DNS-PERSIST-01 is available
(https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-persist-00), we already
know which ACME account(s) have been issuing for it.
.PARAMETER Action
"create" or "delete", supplied automatically by win-acme as the first
argument.
.PARAMETER Identifier
The hostname being validated, e.g. dev.rtegroup.ie. Not used by rtedns, but
accepted so win-acme's default argument layout works unmodified.
.PARAMETER RecordName
Full TXT record name win-acme wants created/deleted, e.g. _acme-challenge.dev.rtegroup.ie
.PARAMETER Token
The TXT record content (the ACME challenge token).
#>
param(
[Parameter(Mandatory = $true, Position = 0)][string]$Action,
[Parameter(Mandatory = $true, Position = 1)][string]$Identifier,
[Parameter(Mandatory = $true, Position = 2)][string]$RecordName,
[Parameter(Mandatory = $true, Position = 3)][string]$Token
)
$ErrorActionPreference = 'Stop'
if (-not $env:RTEDNS_API_KEY) {
Write-Error "RTEDNS_API_KEY environment variable is not set."
exit 1
}
$base = if ($env:RTEDNS_API_BASE) { $env:RTEDNS_API_BASE } else { 'https://acme.rtegroup.ie' }
$payload = @{ hostname = $RecordName; value = $Token }
if ($env:RTEDNS_LE_ACCOUNT_URI) {
$payload.leAccountUri = $env:RTEDNS_LE_ACCOUNT_URI
$payload.leIssuer = if ($env:RTEDNS_LE_ISSUER) { $env:RTEDNS_LE_ISSUER } else { 'letsencrypt.org' }
}
$body = $payload | ConvertTo-Json
switch ($Action.ToLowerInvariant()) {
'create' {
Invoke-RestMethod -Uri "$base/api/dns/present" -Method Post `
-Headers @{ Authorization = "Bearer $($env:RTEDNS_API_KEY)" } `
-ContentType 'application/json' -Body $body -UseBasicParsing | Out-Null
Write-Host "rtedns: created $RecordName"
}
'delete' {
Invoke-RestMethod -Uri "$base/api/dns/cleanup" -Method Post `
-Headers @{ Authorization = "Bearer $($env:RTEDNS_API_KEY)" } `
-ContentType 'application/json' -Body $body -UseBasicParsing | Out-Null
Write-Host "rtedns: cleaned up $RecordName"
}
default {
Write-Error "Unknown action '$Action' (expected create or delete)."
exit 1
}
}3. Set your API key
The renewal scheduled task win-acme creates usually runs as the machine's
SYSTEM account, not as you, so set the key machine-wide. Open Command
Prompt as administrator and run (only needs doing once — this
writes to the machine environment in the registry, so it persists across reboots
and is visible to every account, including the scheduled task):
setx RTEDNS_API_KEY "rtdns_your_team_key_here" /MOpen a new Command Prompt window afterwards so it picks up the change.
Only do this on a machine dedicated to certificate issuance — /M makes
the key readable to every user on the box. If you deliberately configured the
renewal task to run as your own user, drop the /M and use a normal
Command Prompt.
4. Request the certificate
Run wacs.exe from an elevated Command Prompt (Run as
administrator) — it needs admin rights to write certificates to the store and to
register its renewal scheduled task. From C:\win-acme, point
--dnsscript at the one file — no create/delete argument overrides
needed, since the script already accepts win-acme's default arguments:
wacs.exe --target manual --host dev.rtegroup.ie ^
--validationmode dns-01 --validation script ^
--dnsscript "C:\win-acme\rtedns\rtedns-dns.ps1"Prefer the interactive menu? Run wacs.exe (still elevated) with no arguments, choose
M (create certificate) → manual input → validation mode
Script, and point both the create and delete script prompts at
rtedns-dns.ps1, leaving the argument prompts on their defaults. win-acme's
built-in scheduled task handles renewals automatically from then on, reusing the same
script.
Optional: link this to your ACME account for DNS-PERSIST-01
Not required for normal issuance. If you want to set
RTEDNS_LE_ACCOUNT_URI, add it the same way as the API key:
setx RTEDNS_LE_ACCOUNT_URI "https://acme-v02.api.letsencrypt.org/acme/acct/123456789" /MYou can find your account URI in win-acme's registration output, or under
%programdata%\win-acme\...\Registration.