Prerequisites for ACME certificate use

This topic provides the requirements for using ACME certificates with supported devices and ACME servers. Requirements are grouped as follows:

General prerequisites for device configuration

  • The Firewall Threat Defense device is Version 10.0 or later.

  • DNS must be configured in Firewall Threat Defense platform settings to resolve the ACME server’s domain name.

  • Your domain must map to a public IP address. Configure the device interface with this IP address and set it as the authentication interface in the ACME certificate enrollment.

  • An ACME CA certificate (manually installed CA-only certificate) must be enrolled on the device to authenticate the ACME server.

    • If you use Let's Encrypt as the ACME server, you must get the Internet Security Research Group (ISRG) root certificate from https://letsencrypt.org/certificates/ and enroll it as a manual CA-only certificate on the device. For example, you can use the root certificate from https://letsencrypt.org/certs/isrgrootx1.pem.txt.

    • If you configure object overrides for any device, ensure that you enroll an ACME CA certificate on that device too.

  • The same NTP server must be configured for both the ACME server and the Firewall Threat Defense device.

Prerequisites for ACME server

  • Access to an ACME server such as Let's Encrypt, or any other public or on-prem ACME server.

  • The ACME server must be reachable from the Firewall Threat Defense device.

  • The ACME server must be able to validate the domain name and the alternate FQDNs.

  • If the authentication interface is different from the source interface, ensure the ACME server is reachable from the device’s source interface.

VPN load balancing prerequisite

  • When configuring an ACME enrollment object for a VPN load balancing group, include both director and member FQDNs in the Alternate FQDN field.

  • ACME certificates do not support wildcard certificates.