Skip to main contentSkip to search
Powered by Zoomin Software. For more details please contactZoomin
Progress DocumentationProgress Documentation
Progress Documentation
  • Home
  • Home
  • EnglishČeštinaDeutsch (Germany)Español (Spain)ФранцузскийItaliano (Italy)Português (Brasil)日本語Русский (Russia)中文 (简体) (China)中文 (繁體, 台灣) (Taiwan)ar-AR
  • Login

Feature Description Lets Encrypt

Link the LoadMaster with a Let's Encrypt Account

Save PDF
Save selected topicSave selected topic and subtopicsSave all topics
Share
Share to emailCopy topic URL
Print
Table of Contents
  • Introduction
  • Prerequisites
  • How It Works
  • Link the LoadMaster with a Let's Encrypt Account
  • Request a New Certificate
    • Request a Wildcard Certificate
  • Convert a Virtual Service with Real Servers to one with SubVSs
  • Logs Relating to Let's Encrypt
Table of Contents

Link the LoadMaster with a Let's Encrypt Account

Save PDF
Save selected topicSave selected topic and subtopicsSave all topics
Share
Share to emailCopy topic URL
Print
  • Last Updated: October 8, 2024
  • 4 minute read
    • LoadMaster
    • LoadMaster GA
    • Documentation

When initially configuring Let's Encrypt functionality on the LoadMaster, you must either create a new Let's Encrypt account or link to an existing account. To do this, follow the steps below in the LoadMaster User Interface (UI):

  1. In the main menu, go to Certificates & Security > ACME Certificates.

  2. Select Let's Encrypt.

  3. Enter the URL of the Automated Certificate Management Environment (ACME) server in the Directory URL field and click Set Directory URL.
    Note: The default URL is the Let's Encrypt production ACME server: https://acme-v02.api.letsencrypt.org/directory. This can be changed as needed.The LoadMaster supports API version 2 of the ACME protocol.
  4. If you do not already have a Let's Encrypt account, you can register for one by optionally entering your Email Address and clicking Register Account.

    When you register a Let's Encrypt account through the LoadMaster, a private key (account key) is generated. To reuse the same Let's Encrypt account key on another LoadMaster, take a backup of the LoadMaster (System Configuration > System Administration > Backup/Restore) and its related Certificates (Certificates & Security > Backup/Restore Certs), if available.To restore the backup on the other LoadMaster with account information only, follow the below steps:

    • Go to System Configuration > System Administration > Backup/Restore.

    • Click Choose File, browse to and select the created backup file.

    • Select the LoadMaster Base Configuration checkbox and then click Restore Configuration to restore the backup.

    If the created backup includes the account details, certificates and connected virtual services information, then follow the below steps to restore the backup:

    • Go to System Configuration > System Administration > Backup/Restore.

    • Click Choose File, browse to and select the created backup file.

    • Select the LoadMaster Base Configuration and VS Configuration checkbox and then click Restore Configuration to restore the backup.

    • Then, go to Certificates & Security > Backup/Restore Certs.

    • Click Choose File, browse to and select the certificate backup file.

    • Select the type of certificates from drop-down list provided.

    • Enter the passphrase associated with the certificate backup file and click Restore Certificates.

  5. If you have an existing Let's Encrypt account, you can upload the Account Key File, enter the Pass Phrase, and click Upload Account Key to link to your existing account.
    Note: You can retrieve the account key file from other ACME clients that you registered the account with (like Certbot).
  6. Once you have successfully registered or linked to your existing Let's Encrypt account, the Manage ACME Certificates screen appears.

  7. You can set the Renew Period for the Let's Encrypt certificates.
Note: Let's Encrypt certificates are valid for 90 days. The Renew Period value specifies how many days in advance of certificate expiry you would like the certificate to be renewed. The Renew Period is an account-wide setting. Per-certificate renewal periods are not supported at this time.The Renew Period is set to 30 days by default. Let's Encrypt recommends renewing certificates 30 days before expiry. Valid values for the Renew Period field range from 1 to 60 (days). The old certificates are replaced and assigned to the HTTPS Virtual Service when the renewal is successful.

The next step is to request a new certificate. Refer to the section below for instructions on how to do this.

You can click Delete ACME Configuration Parameters to remove the ACME account settings (which allows you to configure the ACME account settings from the start).

Note: You can only delete the configuration if there are no ACME certificates.
Note: If you downgrade the LoadMaster from version 7.2.53 (or above) to 7.2.52 (or below), any Let's Encrypt certificates that exist at the time of downgrade are preserved in the downgraded system so that Virtual Service connectivity is not inadvertently affected by the downgrade. However, the automatic certificate management functionality is not available in earlier versions. These certificates are listed on the SSL Certificates page and can be deleted after the downgrade, if needed.
TitleResults for “How to create a CRG?”Also Available inAlert