ACME EAB Policies

This section details how to configure External Account Binding policies.

Introduction

An EAB policy is a named, reusable set of constraints attached to EAB accounts. It allows users to define constraints once and apply them to every EAB account attached to the policy, instead of configuring them on each EAB account individually.

The constraints of an EAB policy always apply in combination with the constraints of the attached EAB accounts: when both levels define a constraint, requests must satisfy both of them. Constraints left empty impose no restriction at their level.

How to create an EAB policy

1. Log in to Horizon Administration Interface.

2. Access ACME from the drawer or card: Protocols  ACME, then open EAB Policies from the drawer or card.

3. Click on Add an EAB policy.

4. Fill in the mandatory fields.

General

  • Name* (string input):
    Enter a meaningful EAB policy name. It must be unique for each EAB policy. Horizon uses the name to identify the policy, and EAB accounts reference their policy by name. The name can no longer be edited after creation.

Additional Policy Constraints

The following constraints apply in addition to those of the attached EAB accounts and of the selected ACME profile. Leave a constraint empty to impose no restriction at this level.
  • Allowed Profiles (multiselect):
    Restricts which ACME profiles the associated EAB accounts may use. If no profile is selected, this policy imposes no profile restriction; each EAB account’s own list still applies.

  • Order Identifier Constraint (regex):
    Every identifier in an order must match this regular expression, in addition to any expression set on the associated EAB account.

  • Email Constraint (regex):
    Every contact email address (provided at ACME account creation) must match this regular expression, in addition to any expression set on the associated EAB account.

  • Validation Methods (multiselect):
    Limits the validation methods allowed by this policy, in addition to those of the associated EAB account and the selected ACME profile. Leave empty for no additional restriction.

5. Click on the save button.

You can edit Edit EAB policy, duplicate Duplicate EAB policy or delete Delete EAB policy an EAB policy.

Any change made to a policy immediately applies to all EAB accounts attached to it.

You won’t be able to delete an EAB policy if it is referenced by at least one EAB account.