EAB Credentials for Certificate as a Service (CaaS)

External Account Binding (EAB) credentials are the secure keys that connect your ACME client to your pre-paid Trustico® Certificate as a Service (CaaS). They authenticate your ACME client with the Certificate Authority (CA) and tie every SSL Certificate request to your active service.

Without valid External Account Binding (EAB) credentials, an ACME client cannot request SSL Certificates against your Trustico® Certificate as a Service (CaaS). They are what link the automated protocol to the specific service you have paid for.

Your EAB credentials act as a bridge between your ACME client software and your pre-paid Trustico® service, enabling automatic SSL Certificate issuance and reissue without manual intervention. Explore Certificate as a Service (CaaS) 🔗

Your EAB Credentials Package

When you purchase Trustico® Certificate as a Service (CaaS), you receive three pieces of information by e-mail. Together they let your ACME client connect to the correct service and authenticate every request.

EAB Key Identifier : A unique reference that identifies your specific Trustico® Certificate as a Service (CaaS) account to the Certificate Authority (CA).

EAB Message Authentication Code (MAC) Key : A secret key used to sign your account registration, proving that the request genuinely comes from you.

ACME Server URL : The dedicated server endpoint where your ACME client will connect to request and manage SSL Certificates. Learn About ACME Endpoints Explained 🔗

We generally only send this information via e-mail when Trustico® Certificate as a Service (CaaS) is activated or extended. If you lose the e-mail please speak with our support team for further assistance. Discover How to Obtain Your Credentials 🔗

How EAB Credentials Work

External Account Binding (EAB) credentials solve a specific problem. They link the open ACME protocol to a specific, pre-paid commercial service, so the Certificate Authority (CA) knows which SSL Certificate requests are authorized.

When your ACME client first registers, it uses the EAB Key Identifier and EAB Message Authentication Code (MAC) Key to prove the account belongs to you. The Certificate Authority (CA) checks this against your active Trustico® Certificate as a Service (CaaS) before allowing any SSL Certificate to be issued.

Once registered, your ACME client can request and reissue SSL Certificates automatically for the domains your service covers, without needing the credentials again for every request.

Sharing One Account Across Systems

The same External Account Binding (EAB) credentials can be used on more than one server or ACME client, which is useful when you run several systems under a single Trustico® Certificate as a Service (CaaS).

Each server registers its own ACME account using the same credentials, and each can then request SSL Certificates for the domains your service covers. This keeps automated management consistent across your infrastructure.

Because the credentials are shared, protecting them on every system matters. Anyone who holds them can register an ACME client against your service.

Domain Authorization

Your External Account Binding (EAB) credentials are tied to the specific domains covered by your Trustico® Certificate as a Service (CaaS). Your ACME client can only issue SSL Certificates for those domains and their included variations.

This keeps SSL Certificate issuance aligned with what you have purchased, while still allowing unlimited SSL Certificates for the domains your service covers.

Configuring Your ACME Client

Most popular ACME clients support EAB credentials through command-line parameters or configuration files. The exact setup process varies by client, but the core information remains the same. Discover Supported ACME Clients 🔗

You provide the EAB Key Identifier, the EAB Message Authentication Code (MAC) Key, and the ACME Server URL when you register the account. From that point on, the client uses its registered account for all SSL Certificate operations.

Keeping Your EAB Credentials Secure

Your External Account Binding (EAB) credentials deserve the same care as any other sensitive password or API key. Anyone who has them can request SSL Certificates against your Trustico® Certificate as a Service (CaaS).

Store them in environment variables or a secure credential management system rather than in plain files. Never commit them to code repositories, and never share them in e-mail or support tickets.

If you believe your credentials have been exposed, contact our support team so the situation can be reviewed and addressed.

Troubleshooting EAB Issues

Most External Account Binding (EAB) problems appear during the first account registration, and they usually come down to a few common causes.

Check that the EAB Key Identifier and EAB Message Authentication Code (MAC) Key are copied exactly as supplied, with no extra spaces. Confirm that you are using the correct ACME Server URL, and that your Trustico® Certificate as a Service (CaaS) is active.

If registration still fails, our support team can confirm whether your credentials are valid and your service is active.

Managing Your Service

Your External Account Binding (EAB) credentials remain valid for as long as your Trustico® Certificate as a Service (CaaS) is active. The same credentials continue to work across reissues, with no need to update your ACME client.

If your service lapses, the credentials can no longer be used to issue SSL Certificates until the service is restored. Keeping your service active is what keeps automated management working.

EAB Credentials and Your Service Lifecycle

Your External Account Binding (EAB) credentials are issued when you first purchase Trustico® Certificate as a Service (CaaS), and they stay with your service throughout its life.

As long as you keep your service active, the same credentials keep your ACME client issuing and reissuing SSL Certificates automatically. This makes the credentials a long-term part of your infrastructure, not something to be replaced at each reissue.

Getting Help with EAB Setup

If you need help with your External Account Binding (EAB) credentials, our support team can assist with registration, configuration, and troubleshooting.

When you contact us, describe your ACME client and the issue you are seeing, and include any error messages. To keep your service secure, never include your EAB Message Authentication Code (MAC) Key in a support request.

Service Continuity

Keeping your Trustico® Certificate as a Service (CaaS) active is what keeps your External Account Binding (EAB) credentials working and your SSL Certificates reissuing automatically.

Extend your service before it expires, or set up automatic billing, so your ACME client can keep protection in place without interruption.

Certificate as a Service (CaaS) - Pricing

Trustico® Certificate as a Service (CaaS) provides automated SSL Certificate issuance through the Automated Certificate Management Environment (ACME) protocol. The table below shows the price for each Certificate as a Service (CaaS) product.

Product Name Supplier List Price Your Price
Trustico® CaaS DV Single Site 🔗
€97,95 EUR
€52,95 EUR Save 46%
Trustico® CaaS DV + Wildcard 🔗
€486,95 EUR
€208,95 EUR Save 57%
Trustico® CaaS DV + Multi Domain 🔗
€97,48 EUR
€52,48 EUR Save 46%
Trustico® CaaS DV + Wildcard + Multi Domain 🔗
€486,48 EUR
€208,98 EUR Save 57%
Sectigo® CaaS DV Single Site 🔗
€88,95 EUR
€61,95 EUR Save 30%
Sectigo® CaaS DV + Wildcard 🔗
€442,95 EUR
€244,95 EUR Save 45%
Sectigo® CaaS DV + Multi Domain 🔗
€88,65 EUR
€61,32 EUR Save 31%
Sectigo® CaaS DV + Wildcard + Multi Domain 🔗
€442,32 EUR
€244,32 EUR Save 45%

*Multi-Domain SSL Certificate pricing is displayed per Subject Alternative Name (SAN). Each Multi-Domain product has its own minimum number of Subject Alternative Names (SANs) that are included or required to be purchased, and this minimum differs between products.

Sectigo® CaaS DV Single Site vs Wildcard Comparison

Certificate as a Service (CaaS) provides automated SSL Certificate management through APIs. Choose Single Site for individual domain automation, or Wildcard for comprehensive subdomain coverage with full API-driven SSL Certificate lifecycle management.

Feature Sectigo® CaaS DV Single Site Sectigo® CaaS DV + Wildcard
Service Type Certificate as a Service (CaaS) Certificate as a Service (CaaS)
Coverage Single Domain Only Unlimited Subdomains
Domains Covered www.example.com + example.com *.example.com + example.com
Automation Level Fully Automated Fully Automated
API Access Full RESTful API Full RESTful API
Validation Level Domain Validation (DV) Domain Validation (DV)
Validation Methods E-Mail / DNS / HTTP / HTTPS E-Mail / DNS / HTTP / HTTPS
Issuance Time Very Fast! Issued Within Minutes Very Fast! Issued Within Minutes
Auto-Renewal Automated Renewal Available Automated Renewal Available
Certificate Management Centralized Dashboard Centralized Dashboard
Integration Options API, Webhooks, SDK API, Webhooks, SDK
Ideal For SaaS Platforms, Single Domain Apps Multi-Tenant SaaS, Complex Infrastructures
Scalability Per-Domain Scaling Automatic Subdomain Coverage
Warranty $500,000 USD $500,000 USD
Encryption Strength 256-bit SSL Encryption 256-bit SSL Encryption
Browser Compatibility 99.9% Browser Trust 99.9% Browser Trust
Dual Domain Coverage Includes Root Domain SAN Free! Includes Root Domain SAN Free!
Reissues Unlimited Unlimited
Deployment Options Cloud, On-Premise, Hybrid Cloud, On-Premise, Hybrid
Information Page Product Information Page 🔗 Product Information Page 🔗
Your Trustico® Price €61,95 EUR €244,95 EUR
Purchase Options Instant - Buy Now 🔗 Instant - Buy Now 🔗

Most Popular Questions

Learn how External Account Binding (EAB) credentials work with Trustico® Certificate as a Service (CaaS) to enable automated SSL Certificate issuance and reissue through Automatic Certificate Management Environment (ACME) clients.

What Are EAB Credentials and Why Do You Need Them?

External Account Binding (EAB) credentials are secure authentication keys that connect your Automatic Certificate Management Environment (ACME) client to your paid Trustico® Certificate as a Service (CaaS). They ensure only authorized users can issue SSL Certificates under your service, enabling automatic SSL Certificate issuance and reissue without manual intervention.

What Credentials Do You Receive When Purchasing Trustico® Certificate as a Service?

Your credentials package includes four components : a Trustico® Automatic Certificate Management Environment (ACME) Account ID for service management and support, an External Account Binding (EAB) Key ID as your unique account identifier, an EAB Message Authentication Code (MAC) Key as your secure authentication key, and an ACME Server URL where your client connects. These are sent via e-mail when your service is activated or renewed.

Can EAB Credentials Be Used Across Multiple Servers?

Yes, one of the key benefits of Trustico® Certificate as a Service (CaaS) is that your External Account Binding (EAB) credentials can be shared across multiple Automatic Certificate Management Environment (ACME) clients and servers. You can configure production servers, staging environments, load balancers, and development systems all with the same credentials, eliminating the need for separate services for each server.

How Do You Configure Certbot with EAB Credentials?

For Certbot, use the --eab-kid and --eab-hmac-key parameters along with --server to specify your Automatic Certificate Management Environment (ACME) Server URL during account registration. Your External Account Binding (EAB) Key ID and EAB Message Authentication Code (MAC) Key must be copied exactly as provided in your credentials e-mail, without additional spaces or line breaks.

How Do You Configure acme.sh with EAB Credentials?

For acme.sh, set the ACME_EAB_KID and ACME_EAB_HMAC_KEY environment variables with your credentials, then specify your server URL with the --server parameter. The credentials are case-sensitive and must match precisely what was provided in your credentials e-mail.

How Should EAB Credentials Be Securely Stored?

Store your External Account Binding (EAB) Message Authentication Code (MAC) Key in environment variables or secure credential management systems. Never commit these credentials to code repositories, configuration files, or any unencrypted storage. Regularly audit which systems have access and remove credentials from decommissioned servers or environments that no longer need SSL Certificate access.

Why Does the ACME Client Fail Authentication with EAB Credentials?

First verify you are using the correct Automatic Certificate Management Environment (ACME) Server URL provided in your credentials e-mail. Ensure your External Account Binding (EAB) Key ID and EAB Message Authentication Code (MAC) Key are copied exactly without extra spaces or line breaks, as they are case-sensitive. Also check that your Trustico® Certificate as a Service (CaaS) is active and has not expired.

What Happens with EAB Credentials When Renewing the Service?

When you extend your Trustico® Certificate as a Service (CaaS), your existing External Account Binding (EAB) credentials continue working without any changes required to your Automatic Certificate Management Environment (ACME) client configuration. This ensures seamless SSL Certificate operations across service renewals with no reconfiguration needed.

What Happens When Certificate as a Service Expires?

When your service expires, your External Account Binding (EAB) credentials automatically become inactive, preventing SSL Certificate issuance. Your Automatic Certificate Management Environment (ACME) client will be unable to reissue SSL Certificates, potentially leading to SSL Certificate expiration and website downtime until service is restored. Renew before expiration or set up automatic billing to ensure continuity.

Lost the EAB Credentials E-Mail. How Can They Be Retrieved?

The credentials are shown in your order and billing history against the relevant Certificate as a Service (CaaS) order, generally for 7 days after the order is submitted, and an alternate retrieval method is provided for the same credentials. If they are no longer available there, contact the Trustico® support team with your order number and Trustico® Automatic Certificate Management Environment (ACME) Account ID. Never share your External Account Binding (EAB) Message Authentication Code (MAC) Key in support communications, as the team can verify your credentials without seeing the actual key values.