How-To: Issue and Manage Certificates via Let's Encrypt and EZCA

Let’s Encrypt is a great option for issuing free public certificates. Learn how you can monitor, manage, and protect your Let’s Encrypt certificates using EZCA.

Overview - How to Centrally Manage Your Let’s Encrypt Certificates in EZCA

While Let’s Encrypt offers free publicly trusted certificates via ACME, you may run into a situation where every team, engineer, or server has their own process and governance for managing certificates. Especially with the upcoming 47-day restriction on public certificates, your organization might be heading straight into waves of outages that you may not be prepared for.

What Are Some of the Most Common Issues Caused by Let’s Encrypt Certificates?

When every server talks to Let’s Encrypt directly for every public certificate, some common issues regularly pop up:

  1. Certificate Validity Length: The CA/Browser forum voted in 2025 to require all public certificates to move to 47-day issuance by 2029, with a staged rollout. If you request certificates for longer durations or forget to renew before they expire, you will have an outage.
  2. Shadow IT & PKI: Since Let’s Encrypt is a public and free service, anyone can use it, including anyone in your organization. Many organizations don’t even know they’re using Let’s Encrypt to issue server certificates if they have a different preferred certificate authority.
  3. Combined Client/Server EKUs: Let’s Encrypt ended support for client EKUs in 2026. If you’re requesting or using this EKU, your certificate will be denied.
  4. DNS Permissions: Completing an ACME DNS challenge requires you to set your DNS records, usually through automation. If you don’t scope your access correctly, you could hand over full control of your DNS records to an attacker if they gain access to a single server.
  5. Broken Automation: If your ACME client crashes or fails to run on your server, your certificate won’t be renewed and will expire. You usually don’t find out until after you have an outage.

How Can EZCA Help Prevent the Most Common Let’s Encrypt Issues?

EZCA provides public certificate authorities (CAs) to sit in between Let’s Encrypt and your organization’s servers to help centrally manage, monitor, and protect your public certificates. Every EZCA public CA allows you to:

  1. Centrally Monitor Your Certificates: In a single view you can see how many certificates you’ve issued and how many are nearing expiry.
  2. Proactive Alerts for Expiring Certificates: If a certificate is nearing expiration, we proactively alert you via email or SIEM integration so you don’t miss any expiring certificates.
  3. Enforce Role-Based Access Control (RBAC) to Your Domains: For large organizations you may have multiple teams each managing separate domains, servers, and certificates. EZCA allows you to control access via Entra ID apps and groups for who can request/issue/manage certificates and domains.
  4. Add Dual Key Approval for New Certificates: Add additional protections to your domains via dual key approvals, where no one person can issue new certificates.
  5. Perform ACME Challenges with No Access to Your DNS: After you set up a one-time DNS delegation (CNAME record) for only ACME challenges (_acme-challenge), EZCA doesn’t need any access to your DNS for ongoing issuance and renewal.

Step-by-Step Guide - How to Issue Let’s Encrypt Certificates Through EZCA

This guide will walk you through how to set up a new EZCA certificate authority which can connect to Let’s Encrypt and help centrally manage your Let’s Encrypt certificates.

Before you begin, make sure you have these pre-requisites in place:

Prerequisites for Setting Up a Let's Encrypt Public CA

Make sure you've completed these steps

For EZCA to talk to your Entra ID tenant, you need to register the EZCA Entra ID application in your tenant.

Collapses this section and completes the checkmark.

A premium subscription is required to set up a Let’s Encrypt public CA in EZCA. Please ensure you have created a premium subscription before proceeding.

Collapses this section and completes the checkmark.

Now that you have the pre-requisites in place, you can create your public certificate authority:

How to Set Up an EZCA Public CA with Let's Encrypt

Follow these steps to create an EZCA public certificate authority

The first step to automating your Let’s Encrypt public certificate issuance is to connect EZCA to Let’s Encrypt via a Public CA. Follow these steps to create one:

  1. Navigate to https://portal.ezca.io (or your private/regional EZCA instance).

  2. From the left sidebar, select Certificate Authorities.

    EZCA Cloud PKI portal with the Certificate Authorities menu highlighted.
  3. At the top of the menu, click + Create CA.

    EZCA Cloud PKI portal with the Create CA button highlighted.
  4. Under Select CA Type select Public CA and click Next.

    EZCA Cloud PKI Create CA type selection with Public CA option highlighted.
  5. Under Select CA Provider select Let’s Encrypt CA and click Next.

    EZCA Cloud PKI Create CA Configure CA connection with Let's Encrypt option highlighted.
  6. Enter a Notification Email and optionally configure any Domain Rules or Issuance Rules:

    • Notification Email: Enter the email address where you want to receive notifications related to your Let’s Encrypt CA. A group email address is recommended instead of a specific person.
    • Domains Available: Control if you want all domains to be available for issuance or if you want to restrict issuance to specific domains. Note that this cannot be changed later without recreating your CA.
    • Wild-Card Certificates: Enable this option if you want to allow the issuance of wild-card certificates for your domains. Note that this cannot be changed later without recreating your CA.
    • Domain Registration Approval: Enable this if you want new Domains to have to be approved first before they can be used for certificate issuance. If checked you can add any Entra ID users/groups that can act as approvers. Can be updated later.
    • Allowed Domain Requesters > Allow all users: Uncheck this box if you only want specific Entra ID users/groups to be able to request/create new Domains for this CA. Can be updated later.
  7. Click Create CA to complete the creation of your Let’s Encrypt CA.

    EZCA Cloud PKI Let's Encrypt Configuration

Collapses this section and completes the checkmark.

Now that your CA has been created, you can create a Domain, which controls who can issue certificates for specific subject and SAN values in a certificate.

  1. Navigate to https://portal.ezca.io (or your private/regional EZCA instance).

  2. From the left-hand menu, navigate to My Domains.

    EZCA Cloud PKI portal My Domains page listing registered domains with Request Certificate buttons.
  3. Click + Register Domain.

    EZCA Cloud PKI My Domains page with Register Domain button highlighted in the top right.
  4. From the Issuing CA dropdown, select your Let’s Encrypt CA.

    EZCA Cloud PKI Register New Domain form with Issuing CA dropdown highlighted for selection.
  5. In the Domain field, enter the domain name or IP address you want to register.

    EZCA Cloud PKI Register New Domain form with Domain name field highlighted for entering the domain.
  6. In the Domain Ownership Details, enter the user(s) and/or group(s) that will act as the Domain Owner. Domain owners can make changes to this Domain including access control and other settings.

    EZCA Cloud PKI Register New Domain form with Domain Owners list showing added users and groups.
  7. In the Certificate Management field, enter the user(s), group(s), and Entra ID application(s) that will be allowed to request certificates for this domain.

    EZCA Cloud PKI Register New Domain form with Certificate Management list showing added users and service principals.
  8. In the ACME DNS Validation section, copy the DNS Record Name and Record Value. You will need to create a CNAME record in your DNS provider for the domain. This CNAME allows EZCA to complete the ACME DNS challenge on your behalf for just this domain and just for the ACME record. EZCA does not have access to any other part of your DNS record (unless you elect to add optional automation for future subdomains in the next section).

    EZCA Cloud PKI Register New Domain form with ACME DNS Validation showing.
  9. If you want to automate DNS onboarding for future subdomains, move onto the next step. Otherwise click Register Domain to complete the domain registration.

Collapses this section and completes the checkmark.

If you plan to add additional subdomain records (e.g., sub.example.com), you can optionally automate the creation of the necessary CNAME records by giving EZCA access to your DNS zone for your root domains (e.g., example.com).

Follow these steps to give EZCA access to your Azure DNS zone so it can automatically create the necessary CNAME records for new subdomains.

  1. Begin by toggling Enable CNAME automation for this domain:

    EZCA Toggle 'Enable CNAME automation for this domain'.
  2. Under DNS Provider, select Azure DNS.

  3. In another tab, go to https://portal.azure.com.

  4. In your DNS Zones, select your public DNS zone corresponding to your domain.

  5. On the sidebar, select Access control (IAM).

    Azure Select DNS Zone IAM
  6. On the top bar, select Add role assignment.

    Azure IAM Add Role Assignment
  7. In the search bar, search for the DNS Zone Contributor role and select it. Then, click Next.

    Azure IAM Select DNS Zone Contributor
  8. In the search bar, search for the Keytos application and select it.

    Azure IAM Select Keytos Application
  9. At the bottom of the page, click Review + assign.

    Azure IAM Review and Assign
  10. Back in your DNS zone, on the sidebar, click Settings and Properties.

    Azure Select DNS Zone properties
  11. Under Essentials, copy the Resource ID.

    Azure Copy DNS Zone Resource ID
  12. Go back to your EZCA tab.

  13. Paste the Resource ID into the DNS Zone Resource ID field and click Create Connection.

    EZCA Fill in DNS Zone Resource ID and click Create Connection
  14. Click the Register Domain button.

  1. Begin by toggling Enable CNAME automation for this domain:

    EZCA Toggle 'Enable CNAME automation for this domain'.
  2. Under DNS Provider, select your DNS provider from the list and follow the steps in the tabs below.

  3. In another tab, go to https://dash.cloudflare.com.

  4. Among the options, select your domain.

  5. On the right-hand sidebar, scroll down to the API section and copy the Zone ID.

    Cloudflare API Section Copy Zone ID
  6. Go back to your EZCA tab.

  7. Paste the Zone ID in the Zone ID field.

    EZCA Cloudflare Paste Zone ID
  8. Go back to your Cloudflare tab.

  9. On the right-hand sidebar, in the API section, select Get your API token.

    Cloudflare API Section Get Your API Token
  10. Select Account API Tokens.

    Cloudflare Account Token
  11. Click Create Token.

    Cloudflare Account Token Create Token
  12. Give your token a name in the Token name section.

  13. In the Permission policies, select Edit zone DNS. By default, this will give EZCA access to all domains in the account. To change this, edit the policy to only give EZCA access to the domains you need.

    Cloudflare Account Token Edit Zone DNS Permission
  14. In the Token expiration section, set an expiration data for EZCA’s access to your DNS.

  15. Select Review Token.

    Cloudflare Account Token Review Token
  16. Select Create Token.

    Cloudflare Account Token Create Token
  17. Copy the API Token.

    Cloudflare Account Token Copy Token
  18. Go back to your EZCA tab.

  19. Paste the API token in the API Token field and click Create Connection.

    EZCA Cloudflare Paste Token and Create Connection
  20. Click the Register Domain button.

Collapses this section and completes the checkmark.

Next Steps - How to Issue a Let’s Encrypt Certificate in EZCA

Now that you’ve onboarded Let’s Encrypt to EZCA, the next step is to create a certificate. Behind the scenes, EZCA will handle the ACME challenge on you behalf.

How to Issue a Certificate