Prerequisites for ACME certificate use
General prerequisites for device configuration
-
The Firewall Threat Defense device is Version 10.0 or later.
-
DNS must be configured in Firewall Threat Defense platform settings to resolve the ACME server’s domain name.
-
Your domain must map to a public IP address. Configure the device interface with this IP address and set it as the authentication interface in the ACME certificate enrollment.
-
An ACME CA certificate (manually installed CA-only certificate) must be enrolled on the device to authenticate the ACME server.
-
If you use Let's Encrypt as the ACME server, you must get the Internet Security Research Group (ISRG) root certificate from https://letsencrypt.org/certificates/ and enroll it as a manual CA-only certificate on the device. For example, you can use the root certificate from https://letsencrypt.org/certs/isrgrootx1.pem.txt.
-
If you configure object overrides for any device, ensure that you enroll an ACME CA certificate on that device too.
-
-
The same NTP server must be configured for both the ACME server and the Firewall Threat Defense device.
Prerequisites for ACME server
-
Access to an ACME server such as Let's Encrypt, or any other public or on-prem ACME server.
-
The ACME server must be reachable from the Firewall Threat Defense device.
-
The ACME server must be able to validate the domain name and the alternate FQDNs.
-
If the authentication interface is different from the source interface, ensure the ACME server is reachable from the device’s source interface.
VPN load balancing prerequisite
-
When configuring an ACME enrollment object for a VPN load balancing group, include both director and member FQDNs in the Alternate FQDN field.
-
ACME certificates do not support wildcard certificates.