How Can I Get Sectigo ACME EAB Credentials Without Buying SCM?

0
0
Asked By MellowQuasar47 On

We manage several Sectigo certificates purchased through SSL247 and want to automate issuance and renewal through our existing certificate management platform. Sectigo documents ACME support, but the information appears to target Sectigo Certificate Manager (SCM). We also confirmed that ACME works through a separate Sectigo CaaS partner.

The difficulty is obtaining the ACME External Account Binding credentials: the EAB Key ID and EAB HMAC Key. SSL247 says its portal does not currently expose them and that customers were supposed to be moved to Sectigo's portal. We cannot find the credentials in Sectigo's store either. Sectigo support has directed us toward SCM or suggested that the credentials might become available in a future portal update around December 2026 or January 2027.

Buying SCM solely to obtain ACME credentials is difficult to justify because we already operate a certificate management platform. A CaaS partner may be a workaround, but it seems likely that we would need to issue replacement certificates instead of transferring our current certificates or subscriptions.

Has anyone obtained ACME EAB credentials for SSL247-purchased certificates without subscribing to SCM? If so, which team or process provided them? I'd also appreciate experiences migrating an existing SSL247 certificate portfolio to a Sectigo CaaS partner.

2 Answers

Answered By RiverOtter63 On

Before paying for another Sectigo service, it may be worth evaluating a different ACME-compatible issuer. Let’s Encrypt, Actalis, ZeroSSL, Google Trust Services, and Amazon all offer automated certificate options, and switching issuers could avoid the SCM or CaaS restrictions altogether.

Answered By CopperPine8 On

There does not appear to be a documented way to obtain EAB credentials for standard retail orders. Sectigo’s ACME access outside SCM is handled as a separate CaaS subscription, usually priced per domain or as a bundle.

The reseller normally creates the ACME account through the CaaS API, using an administrative preregistration operation that returns the EAB Key ID and HMAC key. With the per-domain model, the charge may be deducted from the reseller balance when the first domain is added. I’d ask SSL247 specifically whether they can sell or provision a CaaS subscription. If they cannot, using the partner where you already tested ACME may be the most practical route, allowing the existing certificates to remain valid until they expire.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.