Understanding ACME Endpoints and Directory Options

Every Trustico® Certificate as a Service (CaaS) license connects to an Automatic Certificate Management Environment (ACME) endpoint. The endpoint is the web address your software contacts to request, install, and reissue your SSL Certificates without manual work.

Understanding that address makes everything else straightforward. This page explains what the endpoint contains, what each part means, and what your software finds when it visits the directory. Learn About The ACME Protocol 🔗

Endpoint Address Structure

An ACME endpoint address follows a consistent pattern. Reading it from left to right tells you which Certificate Authority (CA) issues your SSL Certificate and which product line the license belongs to.

The Trustico® Domain Validation (DV) endpoint is a clear example :

https://acme.trust-provider.com/v2/TrusticoDV

The host name identifies the issuing service. The path segment that follows the version marks the product profile, which decides whether a Domain Validation (DV) or Organization Validation (OV) SSL Certificate is issued.

The matching Organization Validation (OV) endpoint changes only the final segment.

https://acme.trust-provider.com/v2/TrusticoOV

Both addresses behave the same way. The one practical difference is that an Organization Validation (OV) license verifies your organization identity before the license is issued, which happens once at purchase.

Sectigo® Endpoints Alongside Trustico® Endpoints

Trustico® offers two distinct product lines, and each has its own ACME endpoint. Your External Account Binding (EAB) credentials are matched to the correct endpoint for the license you hold, so your software always connects to the right service.

Sectigo® is the Certificate Authority (CA) that issues and validates the SSL Certificates offered through the Trustico® website. The Sectigo® Domain Validation (DV) endpoint uses its own host name.

https://acme.sectigo.com/v2/DV

Always use the endpoint that Trustico® supplies with your credentials. The credentials and the endpoint work as a pair, and a mismatch between them prevents registration. Explore Certificate as a Service (CaaS) 🔗

Directory Options Within Your Endpoint

Each endpoint address points to a directory. The directory is the starting point that your software reads first, and it lists every other address the software needs.

Two directories are available across the product lines : Domain Validation (DV) and Organization Validation (OV). The directory you use is set by the endpoint in your credentials, so you do not choose it manually at each request.

Domain Validation (DV) confirms that you control the domain name. Organization Validation (OV) adds a verified organization identity, completed when the license is purchased. Learn About The Validation Procedure 🔗

Directory Discovery Document

When your software visits the endpoint, it receives a small document that lists the address for each type of request. This document needs no login, and visiting it issues nothing on its own.

The document tells your software where to register an account, where to request an SSL Certificate, and where to revoke one. It also names the agreement your software accepts on your behalf, and it confirms that External Account Binding (EAB) credentials are required.

Your software reads this document automatically, so you never work with it by hand. The detail matters only when you want to understand what your client is doing. Learn About Endpoint Configuration Detail 🔗

Ways Trustico® Delivers Automation

You can use your endpoint in whichever way suits your environment. Trustico® supports three approaches, and all of them connect to the same endpoint with the same credentials.

Trustico® provides the license and the credentials, while the setup takes place in your own environment. Configuring your chosen approach and completing validation are done at your end, so you keep full control of your servers and your software.

The first approach uses an ACME client installed on your own server, which gives you the most control. The second uses the Trustico® cPanel Plugin, which brings the whole process into your hosting control panel. Explore the Trustico® cPanel Plugin 🔗

The third approach needs no software at all. Where a client cannot be installed, the same credentials issue an SSL Certificate directly in a browser. Explore the Hosted Issuance Tool 🔗

Whichever approach you choose, configuration is a one-time step. Afterward, your SSL Certificates are handled for you. Compare the supported clients before you decide. Learn About Supported ACME Clients 🔗

External Account Binding Credentials

External Account Binding (EAB) credentials tie your ACME software to your Trustico® license. They are what stops anyone else from requesting SSL Certificates against your account.

After your purchase, Trustico® supplies two values along with the endpoint address : a Key Identifier and a Message Authentication Code (MAC) Key. You enter these once into your software, and it uses them to register.

Warning : Never share your Message Authentication Code (MAC) Key. Anyone who holds it can request SSL Certificates against your license, so store it as securely as you would store a password.

Keeping these values safe is your responsibility, and it is the single most important habit when working with the endpoint. Learn About External Account Binding (EAB) Credentials 🔗

Keeping Your Coverage Active

Once configured, your software reissues each SSL Certificate before it expires, so protection never lapses. Certificate as a Service (CaaS) SSL Certificates use short validity periods, which is why automation matters.

The endpoint can also advise your software of the best time to reissue, so replacements happen inside a sensible window rather than all at once. Your software handles this timing for you.

Reissue works only while your license is active. Keep your license current before it expires, or arrange automatic billing, so your SSL Certificates continue without a gap.

If your domain uses Certification Authority Authorization (CAA) records, make sure they permit Sectigo® to issue. A record that excludes Sectigo® coverage will stop issuance until it is corrected.

Getting Started

Choosing a Certificate as a Service (CaaS) license and configuring your endpoint means your SSL Certificates are handled automatically from that point forward. The move toward shorter validity periods is already under way, so there is little reason to wait.

Compare Certificate as a Service (CaaS) against traditional SSL Certificates to see which suits your needs. Compare Your Options Against Traditional SSL Certificates 🔗

Certificate as a Service (CaaS) - Pricing

Trustico® Certificate as a Service (CaaS) provides automated SSL Certificate issuance through the Automated Certificate Management Environment (ACME) protocol. The table below shows the price for each Certificate as a Service (CaaS) product.

Product Name Supplier List Price Your Price
Trustico® CaaS DV Single Site 🔗
$168.624,00 ARS
$94.966,00 ARS Save 44%
Trustico® CaaS DV + Wildcard 🔗
$843.120,00 ARS
$379.864,00 ARS Save 55%
Trustico® CaaS DV + Multi Domain 🔗
$168.624,00 ARS
$94.966,00 ARS Save 44%
Trustico® CaaS DV + Wildcard + Multi Domain 🔗
$843.119,50 ARS
$379.864,00 ARS Save 55%
Sectigo® CaaS DV Single Site 🔗
$153.295,00 ARS
$111.062,00 ARS Save 28%
Sectigo® CaaS DV + Wildcard 🔗
$766.473,00 ARS
$444.248,00 ARS Save 42%
Sectigo® CaaS DV + Multi Domain 🔗
$153.294,67 ARS
$111.062,00 ARS Save 28%
Sectigo® CaaS DV + Wildcard + Multi Domain 🔗
$766.472,33 ARS
$444.247,33 ARS Save 42%

*Multi-Domain SSL Certificate pricing is displayed per Subject Alternative Name (SAN). Each Multi-Domain product has its own minimum number of Subject Alternative Names (SANs) that are included or required to be purchased, and this minimum differs between products.

Sectigo® CaaS DV Single Site vs Wildcard Comparison

Certificate as a Service (CaaS) provides automated SSL Certificate management through APIs. Choose Single Site for individual domain automation, or Wildcard for comprehensive subdomain coverage with full API-driven SSL Certificate lifecycle management.

Feature Sectigo® CaaS DV Single Site Sectigo® CaaS DV + Wildcard
Service Type Certificate as a Service (CaaS) Certificate as a Service (CaaS)
Coverage Single Domain Only Unlimited Subdomains
Domains Covered www.example.com + example.com *.example.com + example.com
Automation Level Fully Automated Fully Automated
API Access Full RESTful API Full RESTful API
Validation Level Domain Validation (DV) Domain Validation (DV)
Validation Methods E-Mail / DNS / HTTP / HTTPS E-Mail / DNS / HTTP / HTTPS
Issuance Time Very Fast! Issued Within Minutes Very Fast! Issued Within Minutes
Auto-Renewal Automated Renewal Available Automated Renewal Available
Certificate Management Centralized Dashboard Centralized Dashboard
Integration Options API, Webhooks, SDK API, Webhooks, SDK
Ideal For SaaS Platforms, Single Domain Apps Multi-Tenant SaaS, Complex Infrastructures
Scalability Per-Domain Scaling Automatic Subdomain Coverage
Warranty $500,000 USD $500,000 USD
Encryption Strength 256-bit SSL Encryption 256-bit SSL Encryption
Browser Compatibility 99.9% Browser Trust 99.9% Browser Trust
Dual Domain Coverage Includes Root Domain SAN Free! Includes Root Domain SAN Free!
Reissues Unlimited Unlimited
Deployment Options Cloud, On-Premise, Hybrid Cloud, On-Premise, Hybrid
Information Page Product Information Page 🔗 Product Information Page 🔗
Your Trustico® Price $111.062,00 ARS $444.248,00 ARS
Purchase Options Instant - Buy Now 🔗 Instant - Buy Now 🔗

Most Popular Questions

Frequently asked questions covering how Trustico® Certificate as a Service (CaaS) ACME endpoints work, what each part of the endpoint address means, the directory options available, and how External Account Binding (EAB) credentials keep issuance secure

ACME Endpoint Explained

An ACME endpoint is the web address your software contacts to request and reissue SSL Certificates automatically. Every Trustico® Certificate as a Service (CaaS) license connects to one. The address tells your software which service issues the SSL Certificate and which product line the license belongs to.

Reading Your Endpoint Address

The host name identifies the issuing service, and the final path segment selects the product profile. That profile decides whether a Domain Validation (DV) or Organization Validation (OV) SSL Certificate is issued. Your credentials are matched to the correct address, so the choice is made for you.

Sectigo® Endpoints Compared With Trustico® Endpoints

Trustico® offers two product lines, each with its own endpoint, and Sectigo® is the Certificate Authority (CA) that issues the SSL Certificates. Your External Account Binding (EAB) credentials are matched to the correct endpoint. Always use the address supplied with your credentials, because the two work as a pair.

Visiting Your Endpoint Directory

Visiting the endpoint returns a small public document that lists the addresses your software uses. It needs no login, and visiting it issues nothing on its own. Your software reads this document automatically, so you never work with it by hand.

Domain Validation Compared With Organization Validation

Domain Validation (DV) confirms that you control the domain name. Organization Validation (OV) adds a verified organization identity, which is completed once when the license is purchased. Both types behave the same way through the endpoint.

Keeping Your External Account Binding Credentials Safe

Your Message Authentication Code (MAC) Key is a secret, much like a password. Anyone who holds it can request SSL Certificates against your license. Store it securely, and never share it or place it where others can read it.

Reissue While Your License Stays Active

Your software reissues each SSL Certificate before it expires, so protection never lapses. This works only while your Certificate as a Service (CaaS) license is active. Keep the license current before it expires, or arrange automatic billing, to avoid any gap.