ACME Accounts

This section details how to manage the ACME accounts registered on Horizon.

Introduction

An ACME account is created by an ACME client when it registers on an ACME profile, as described in RFC 8555, section 7.3. An ACME account is identified by:

  • its Key ID, a public identifier: the SHA-256 thumbprint of the account key, displayed in the Horizon Administration Interface;

  • its account key, the private key of the key pair held by the client, used to sign its subsequent requests.

In the ACME protocol, the client identifies its account in the kid field of the JWS header of each request: this kid is the account URL returned by Horizon at registration. It is distinct from the Key ID displayed in the Horizon Administration Interface, which is the SHA-256 thumbprint of the account key.

The account key must be kept secret by the ACME client: any party holding it can act as the account, reusing its valid authorizations to enroll certificates without re-validating challenges. If the account key is suspected to be disclosed, compromise the ACME account to revoke the certificates issued to it.

ACME accounts cannot be created from the Horizon Administration Interface: this page allows administrators to audit the accounts registered on the ACME profiles and to manage their status.

An ACME account can be bound to an EAB account at registration, as described in EAB accounts. Changing the status of an EAB account can impact the ACME accounts bound to it, and compromising an EAB account also compromises the accounts bound to it.

Account details

1. Log in to Horizon Administration Interface.

2. Access ACME from the drawer or card: Protocols  ACME, then open ACME Accounts from the drawer or card.

Click on the Key ID or the view icon to display the account details.

The account details page displays:

  • Key ID (string): the account public identifier;

  • Account key (JWK) (string): the public JWK of the account key pair held by the client;

  • Contact (string): the contact email address(es) provided at registration;

  • Terms of service accepted (boolean): whether the client explicitly agreed to the terms of service;

  • EAB (string): the EAB account the account is bound to, if any;

  • Created at (date): the account creation date;

  • Initial IP (string): the IP address the account was registered from;

  • Status (chip): the account status, that can be changed with the Change status action;

  • Compromised at / Compromise reason (date / select): the compromise information, when relevant;

  • Orders (list): the orders placed by the account, with their identifier, the requested identifiers, the validation type, the enrolled certificate (when available) and the order status (Pending, Ready, Processing, Valid, Invalid). The certificate reference navigates to the certificate page.

You can delete an ACME account Delete ACME account from the ACME Accounts list.

You won’t be able to delete an ACME account if:

  • One of its orders is not in a final status (Valid or Invalid);

  • One of the certificates it enrolled is still valid.

Deleting an ACME account also deletes its orders.

ACME account statuses

The status of an ACME account can be changed by clicking on Change status from the account details or the ACME Accounts list. The following statuses are available:

Status

Description

Valid

Can request certificates and manage its orders and authorizations.

Deactivated

Temporarily disables this account for any reason. Blocks certificate requests and access to its orders and authorizations. Can be set back to Valid.

Suspended

Temporarily disables the account in case of a suspected compromise. Blocks certificate requests and access to its orders and authorizations. Can be set back to Valid.

Revoked

Revocation is final and will block this account. Once revoked, it can only be compromised.

Compromised

Certificates issued to this account will be revoked. This status is irreversible.

Compromise pending

Transitional status automatically set while a compromise is being processed and the certificates are being revoked.

ACME clients only see the statuses defined by RFC 8555: Suspended accounts are reported as deactivated and Revoked / Compromised accounts as revoked.

Compromising an ACME account

When setting the status to Compromised, the following fields are requested:

  • Revoke certificates issued after (date input):
    Certificates issued after this date and time will be revoked. Leave empty to revoke all certificates issued to this account.

  • Revocation reason (select):
    The revocation reason applied to every certificate revoked through this compromise.

Compromising an ACME account is irreversible and triggers the revocation of the certificates issued to this account.

The ACME Accounts list can be searched using the search bar, in intermediate or expert mode.

The intermediate search allows filtering the list by Key ID, contact or EAB account name.

The expert mode allows building HAQL (Horizon ACME Query Language) queries, by combining elements, conditions and operators. The query structure is the following:

  • <element> <condition> <"value"> (<operator> [<element> <condition> <"value">])

Table 1. Table element
Element Description Available conditions

id

Account ID

equals, not equals

contact

Account contact

equals, not equals, contains, not contains, in, not in, exists, not exists

eab.name

Name of the EAB account the ACME account is bound to

equals, not equals, contains, not contains, in, not in, exists, not exists

status

Account status

equals, not equals, in, not in

created.at

Account creation date

equals, not equals, before, after, not before, not after

Table 2. Table operator
Operator Description

or

The account matches at least one of the combined criteria

and

The account matches all the combined criteria