Skip to main contentSkip to search
Powered by Zoomin Software. For more details please contactZoomin
Progress DocumentationProgress Documentation
Progress Documentation
  • Home
  • Home
  • EnglishČeštinaDeutsch (Germany)Español (Spain)FrancêsItaliano (Italy)Português (Brasil)日本語Русский (Russia)中文 (简体) (China)中文 (繁體, 台灣) (Taiwan)ar-AR
  • Login

Feature Description DigiCert

Link the LoadMaster with a DigiCert Account

Save PDF
Save selected topicSave selected topic and subtopicsSave all topics
Share
Share to emailCopy topic URL
Print
Table of Contents
  • Introduction
  • Prerequisites
  • How It Works
  • Link the LoadMaster with a DigiCert Account
  • Request a New Certificate
    • Request a Wildcard Certificate
  • Convert a Virtual Service with Real Servers to one with SubVSs
  • Logs Relating to DigiCert
  • Notes about LoadMaster Downgrades
Table of Contents

Link the LoadMaster with a DigiCert Account

Save PDF
Save selected topicSave selected topic and subtopicsSave all topics
Share
Share to emailCopy topic URL
Print
  • Last Updated: July 27, 2026
  • 4 minute read
    • LoadMaster
    • LoadMaster GA
    • Documentation
When initially configuring DigiCert functionality on the LoadMaster, you must link the LoadMaster to your existing DigiCert account. This registers the LoadMaster as an ACME client with DigiCert and generates a private key (account key) on the LoadMaster.
Note: Before you begin, ensure you have retrieved the following from your DigiCert account's ACME automation setup:
  • The Directory URL of the DigiCert ACME server
  • Your Key ID
  • Your HMAC key

For information on obtaining these values, refer to the DigiCert documentation for your account's ACME automation setup.

  1. Go to Certificates & Security > ACME Certificates.

  2. Select DigiCert.

  3. Enter the URL of the Automated Certificate Management Environment (ACME) server in the Directory URL field and click Set Directory URL.
    Note: The default URL is the DigiCert production ACME server: https://one.digicert.com/mpki/api/v1/acme/v2/directory. This can be changed as needed.The LoadMaster supports API version 2 of the ACME protocol.
  4. Enter the Key ID used for identification on the DigiCert account and click Set Key ID.
  5. Enter the Hash-Based Message Authentication Code (HMAC) key used to authenticate to the DigiCert account and click Set HMAC Key.
  6. If you do not have an account key already, you can register for one by entering your Email Address, which is mandatory in this case. If you have an account key already, you can import the account key file that yo obtained from a previous registration with DigiCert.

    Clicking Register Account registers the LoadMaster as an ACME client with DigiCert and generates a private key (account key) on the LoadMaster. To reuse the same DigiCert account key on another LoadMaster, take a backup of the LoadMaster (System Configuration > System Administration > Backup/Restore) and its related certificates (Certificates & Security > Backup/Restore Certs), if available. To restore the backup on the other LoadMaster with account information only, follow the below steps:

    • Go to System Configuration > System Administration > Backup/Restore.

    • Click Choose File, browse to and select the created backup file.

    • Select the LoadMaster Base Configuration checkbox and then click Restore Configuration to restore the backup.

    If the created backup includes the account details, certificates and connected virtual services information, then follow the below steps to restore the backup:

    • Go to System Configuration > System Administration > Backup/Restore.

    • Click Choose File, browse to and select the created backup file.

    • Select the LoadMaster Base Configuration and VS Configuration checkbox and then click Restore Configuration to restore the backup.

    • Then, go to Certificates & Security > Backup/Restore Certs.

    • Click Choose File, browse to and select the certificate backup file.

    • Select the type of certificates from drop-down list provided.

    • Enter the passphrase associated with the certificate backup file and click Restore Certificates.

  7. If you have an existing DigiCert account, you can upload the Account Key File, enter the Pass Phrase, and click Upload Account Key to link to your existing account.
    Note: You can retrieve the account key file from other ACME clients that you registered the account with.
  8. Once you have successfully registered or linked to your existing DigiCert account, the Manage ACME Certificates screen appears.

  9. You can set the Renew Period for the DigiCert certificates.
Note: The Renew Period value specifies how many days in advance of certificate expiry you would like the certificate to be renewed. The Renew Period is an account-wide setting. Per-certificate renewal periods are not supported at this time.
Note: The Renew Period is set to 30 days by default. Progress Kemp recommends renewing certificates 30 days before expiry. Valid values for the Renew Period field range from 1 to 60 (days). The old certificates are replaced and assigned to the HTTPS Virtual Service when the renewal is successful.

The next step is to request a new certificate. Refer to the section below for instructions on how to do this.

You can click Delete ACME Configuration Parameters to remove the ACME account settings (which allows you to configure the ACME account settings from the start).

Note: You can only delete the configuration if there are no ACME certificates.
Alert