| security.acme.defaults.group | Group running the ACME client.
|
| security.acme.defaults.keyType | Key type to use for private keys
|
| security.acme.defaults.postRun | Commands to run after new certificates go live
|
| security.acme.defaults.email | Email address for account creation and correspondence from the CA
|
| security.acme.defaults.validMinDays | Minimum remaining validity before renewal in days.
|
| security.acme.defaults.profile | The certificate profile to choose if the CA offers multiple profiles.
|
| security.acme.defaults.server | ACME Directory Resource URI
|
| security.acme.defaults.extraLegoFlags | Additional global flags to pass to all lego commands.
|
| security.acme.defaults.listenHTTP | Interface and port to listen on to solve HTTP challenges
in the form [INTERFACE]:PORT
|
| security.acme.defaults.extraLegoRunFlags | Additional flags to pass to lego run.
|
| security.acme.defaults.ocspMustStaple | Turns on the OCSP Must-Staple TLS extension
|
| security.acme.defaults.enableDebugLogs | Whether to enable debug logging for this certificate.
|
| security.acme.defaults.webroot | Where the webroot of the HTTP vhost is located.
.well-known/acme-challenge/ directory
will be created below the webroot if it doesn't exist.
http://example.org/.well-known/acme-challenge/ must also
be available (notice unencrypted HTTP).
|
| security.acme.defaults.extraLegoRenewFlags | Additional flags to pass to lego renew.
|
| security.acme.defaults.dnsProvider | DNS Challenge provider
|
| security.acme.defaults.dnsResolver | Set the resolver to use for performing recursive DNS queries
|
| security.acme.defaults.renewInterval | Systemd calendar expression when to check for renewal
|
| security.acme.defaults.reloadServices | The list of systemd services to call systemctl try-reload-or-restart
on.
|
| security.acme.defaults.credentialFiles | Environment variables suffixed by "_FILE" to set for the cert's service
for your selected dnsProvider
|
| security.acme.defaults.environmentFile | Path to an EnvironmentFile for the cert's service containing any required and
optional environment variables for your selected dnsProvider
|
| security.acme.defaults.dnsPropagationCheck | Toggles lego DNS propagation check, which is used alongside DNS-01
challenge to ensure the DNS entries required are available.
|