mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-02 18:25:45 +00:00
Add docs for acme enrollment method
This commit is contained in:
@@ -3,6 +3,62 @@ title: "Certificate Enrollment via ACME"
|
||||
sidebarTitle: "ACME"
|
||||
---
|
||||
|
||||
<Info>
|
||||
ACME-based certificate enrollment is currently under development and will be included in a future release.
|
||||
</Info>
|
||||
## Concept
|
||||
|
||||
The ACME enrollment method allows you to issue and manage certificates against a specific [certificate profile](/documentation/platform/pki/certificates/profiles) using the [ACME protocol](https://en.wikipedia.org/wiki/Automatic_Certificate_Management_Environment).
|
||||
This method is suitable for web servers, load balancers, and other general-purpose servers that can run an [ACME client](https://letsencrypt.org/docs/client-options/) for automated certificate management.
|
||||
|
||||
Infisical's ACME enrollment method is based on [RFC 8555](https://datatracker.ietf.org/doc/html/rfc8555/).
|
||||
|
||||
## Prerequisites
|
||||
|
||||
Install an [ACME client](https://letsencrypt.org/docs/client-options/) onto your server. This client will handle [ACME challenges](https://letsencrypt.org/docs/challenge-types/) and request/renew certificates from Infisical.
|
||||
|
||||
## Guide to Certificate Enrollment via ACME
|
||||
|
||||
In the following steps, we explore how to issue a X.509 certificate using the ACME enrollment method.
|
||||
|
||||
<Steps>
|
||||
<Step title="Create a certificate profile in Infisical">
|
||||
Create a [certificate
|
||||
profile](/documentation/platform/pki/certificates/profiles) with **ACME**
|
||||
selected as the enrollment method.
|
||||
|
||||

|
||||
|
||||
</Step>
|
||||
<Step title="Obtain the ACME configuration">
|
||||
Once you've created the certificate profile, you can obtain its ACME configuration details by clicking the **Reveal ACME EAB** option on the profile.
|
||||
|
||||

|
||||
|
||||
From the ACME configuration, gather the following values:
|
||||
|
||||
- ACME Directory URL: The URL that the ACME client will use to communicate with Infisical's ACME server.
|
||||
- EAB Key Identifier (KID): A unique identifier that tells Infisical which ACME account is making the request.
|
||||
- EAB Secret: A secret key that authenticates your ACME client with Infisical.
|
||||
|
||||
</Step>
|
||||
<Step title="Configure your ACME client">
|
||||
Provide the **ACME Directory URL**, **EAB KID**, and **EAB Secret** from Step 2 to your ACME client to authenticate with Infisical and request a certificate.
|
||||
|
||||
For example, if using [Certbot](https://certbot.eff.org/) as an ACME client, you can configure and start requesting certificates with the following command:
|
||||
|
||||
```bash
|
||||
sudo certbot certonly \
|
||||
--standalone \
|
||||
--server "https://your-infisical-instance.com/api/v1/pki/certificate-profiles/{profile-id}/acme/directory" \
|
||||
--eab-kid "your-eab-kid" \
|
||||
--eab-hmac-key "your-eab-secret" \
|
||||
-d example.infisical.com \
|
||||
--email [email protected] \
|
||||
--agree-tos \
|
||||
--non-interactive
|
||||
```
|
||||
|
||||
Certbot stores the private key and resulting leaf certificate and full certificate chain in `/etc/letsencrypt/live/{domain-name}/`.
|
||||
|
||||
For client-specific setup and usage instructions, refer to the documentation for your ACME client.
|
||||
|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
@@ -5,7 +5,7 @@ sidebarTitle: "API"
|
||||
|
||||
## Concept
|
||||
|
||||
The API enrollment method allows you to issue certificates against a specific certificate profile over Web UI or by making an API request to Infisical.
|
||||
The API enrollment method allows you to issue certificates against a specific [certificate profile](/documentation/platform/pki/certificates/profiles) over Web UI or by making an API request to Infisical.
|
||||
|
||||
## Guide to Certificate Enrollment via API
|
||||
|
||||
@@ -15,7 +15,7 @@ In the following steps, we explore how to issue a X.509 certificate using the AP
|
||||
<Tab title="Infisical UI">
|
||||
|
||||
<Steps>
|
||||
<Step title="Create a certificate profile">
|
||||
<Step title="Create a certificate profile in Infisical">
|
||||
Create a [certificate
|
||||
profile](/documentation/platform/pki/certificates/profiles) with **API**
|
||||
selected as the enrollment method.
|
||||
@@ -54,7 +54,7 @@ Here, select the certificate profile from step 1 that will be used to issue the
|
||||
<Tab title="API">
|
||||
|
||||
<Steps>
|
||||
<Step title="Create a certificate profile">
|
||||
<Step title="Create a certificate profile in Infisical">
|
||||
|
||||
To create a certificate [profile](/documentation/platform/pki/certificates/profiles), make an API request to the [Create Certificate Profile](/api-reference/endpoints/certificate-profiles/create) API endpoint.
|
||||
|
||||
|
||||
@@ -5,7 +5,7 @@ sidebarTitle: "EST"
|
||||
|
||||
## Concept
|
||||
|
||||
The API enrollment method allows you to issue and manage certificates against a specific certificate profile using the [EST protocol](https://en.wikipedia.org/wiki/Enrollment_over_Secure_Transport).
|
||||
The EST enrollment method allows you to issue and manage certificates against a specific [certificate profile](/documentation/platform/pki/certificates/profiles) using the [EST protocol](https://en.wikipedia.org/wiki/Enrollment_over_Secure_Transport).
|
||||
This method is suitable for environments requiring strong authentication and encrypted communication, such as in IoT, enterprise networks, and secure web services.
|
||||
|
||||
Infisical's EST service is based on [RFC 7030](https://datatracker.ietf.org/doc/html/rfc7030) and implements the following endpoints:
|
||||
@@ -32,7 +32,7 @@ and structured under `https://app.infisical.com:8443/.well-known/est/{profile_id
|
||||
In the following steps, we explore how to issue a X.509 certificate using the EST enrollment method.
|
||||
|
||||
<Steps>
|
||||
<Step title="Set up up a certificate profile">
|
||||
<Step title="Create a certificate profile in Infisical">
|
||||
Create a [certificate
|
||||
profile](/documentation/platform/pki/certificates/profiles) with **EST**
|
||||
selected as the enrollment method and fill in EST-specific configuration.
|
||||
|
||||
@@ -5,7 +5,10 @@ sidebarTitle: "Overview"
|
||||
|
||||
Enrollment methods determine how certificates are issued and managed for a [certificate profile](/documentation/platform/pki/certificates/profiles).
|
||||
|
||||
Refer to the documentation for each enrollment method to learn more about how to enroll certificates using it.
|
||||
Refer to the documentation for each enrollment method below to learn more about how to enroll certificates using it.
|
||||
|
||||
- [API](/documentation/platform/pki/enrollment-methods/api): Enroll certificates via API.
|
||||
- [EST](/documentation/platform/pki/enrollment-methods/est): Enroll certificates via EST protocol.
|
||||
- [ACME](/documentation/platform/pki/enrollment-methods/acme): Enroll certificates using the ACME protocol.
|
||||
- [EST](/documentation/platform/pki/enrollment-methods/est): Enroll certificates using the EST protocol.
|
||||
|
||||
Note that beyond using an enrollment method, you can also deliver a certificate to a target destination using supported [certificate syncs](https://infisical.com/docs/documentation/platform/pki/certificate-syncs/overview).
|
||||
|
||||
Reference in New Issue
Block a user