Configuring the ACME account profiles

There are two ACME Account profile documents in certstore.nsf to configure before you submit your first certificate request to the Let's Encrypt CA.

About this task

In each ACME Account profile (LetsEncryptProduction and LetsEncryptStaging) you provide an email address to use to receive notifications about requests and you accept the required Let's Encrypt Terms of Agreement.

Note: It's possible to create new ACME account documents to request certificates from other CAs that support the ACME protocol, such as ZeroSSL, ByPass, Boulder, or Pebble. However use of these CAs is not formally supported.


  1. Open certstore.nsf.
  2. In the Configurations view, click ACME Accounts.
  3. Open and edit the LetsEncryptStaging account.
  4. In the Email Address field, provide the email address to use to receive important information about your certificate requests.
  5. Select Accept terms of service.
  6. Optional: In the Key Algorithm, select RSA or ECDSA and then a Key Size or Curve Name value, depending on your algorithm selection.
    Note: This options specifies the size and algorithm of the key pair that is generated, registered with, and subsequently used to authenticate your ACME account to the CA. Most administrators should use the default values.
  7. Click Save & Close.
  8. Repeat Steps 3 through 7 to configure the LetsEncryptProduction profile.

What to do next

Complete the procedure Requesting a certificate from the Let's Encrypt CA