Dataflows and firewall rules
Potential ACME traffic scenarios
- F5, A10, Cisco hardware (insert all load balancer names here) load balancers as TLS termination
- CDN / reverse proxy, usually with Cloudflare + Let's Encrypt
- Kubernetes and cert-manager,
- IIS + URL rewrite,
- ACME and IIS (one server, one site, one certificate)
- ACME and IIS (one server, multiple sites)
- ACME, IIS, and LB (two servers, one site, one certificate)
- Behind a firewall, the most common enterprise scenario, where DNS-01 should always be the recommendation
- Behind a proxy server, the TLS inspection covers the gotcha that breaks a lot of agent deployments
- Load-balanced environment, explains the HTTP-01 routing failure in simple terms, and points to Trust Lifecycle Manager (TLM) multi-host as the solution
- Multiple sites, one server, explains that firewall rules are server-level and not per site
- Internal / air gapped environments, cover sensor relays, proxy paths, and on-premises TLM
The two directions of ACME traffic
ACME automation generates network traffic in two different directions, and understanding which prevents most network or firewall misconfigurations.
Direction #1: Outbound
The DigiCert automation agent or Trust Assistant on your server communicates outbound to DigiCert's cloud platform and handles everything from account registration, certificate ordering, challenge completion signaling, certificate retrieval, and renewals.
All the traffic leaves your server on port 443 as outbound HTTPS, and DigiCert will never initiate a connection back to your agent. It is always your server that initiates and conforms to zero-trust networking principles.
Using HTTP-01 validation, DigiCert's infrastructure sends inbound requests on port 80 to your web server, requiring a firewall rule. DNS-01 validation eliminates the need for inbound rules, simplifying setup and firewall rules requirements.
The three universal connectivity rules every DigiCert + ACME deployment requires
⚠️ Important note: DigiCert's IP list is not entirely static and will change over time. It is recommended to use DNS references or user agents over hardcoded static IP addresses where possible. DigiCert Platform IP Addresses and URLs
Rule #1: Outbound HTTPS from your server to DigiCert
The automation agent or Trust Assistant must be able to reach DigiCert's platform on port 443, and this is a single outbound HTTPS rule. If this is blocked, the agent cannot register, order certificates, or retrieve any issued certificates.
Rule #2: DNS resolution for DigiCert endpoints
Your server must be able to resolve DigiCert's hostnames (such as acme.digicert.com) to their current IP addresses. If DNS resolution fails, the ACME client cannot connect to DigiCert even if the outbound port 443 is open. Ensure your DNS infrastructure can resolve external hostnames, or configure forwarders appropriately.
The allow list can include specific DigiCert IP addresses and hostnames in your local DNS. Hardcoding DigiCert IP addresses in local DNS is not recommended because DigiCert may change its IP addresses without notice, which can break your automation. Use this approach only as a last resort in environments where standard external DNS resolution is unavailable, and monitor the list below for changes.
[URL of List of FQDNs of DigiCert]
- System and Network Requirements for Sensor-Based Automation (sensor outbound IPs/ FQDNs for acme.digicert.com and daasdigicert.com)
- Discovery Sensor Firewall Requirements
Rule #3: The Challenge validation path must be clear
For HTTP-01, DigiCert's validation infrastructure must be able to reach your web server on port 80 from the outside. For any DNS-01 or DNS-PERSIST-01, your ACME client must be able to reach your DNS provider's API on port 443 outbound. No inbound rule is needed.
⚠️ Important notes:
-
Certificate renewals use the same outbound connections described in Rules #1 and #3.
- No additional firewall rules are needed for automated renewals.
-
DigiCert's ACME implementation does not support TLS-ALPN-01 challenges.
- Only HTTP-01 and DNS-01/DNS-PERSIST-01 validation methods are available.
Frequently asked questions
- ACME API — Outbound, TCP/443 (HTTPS). Always required.
- DNS-01 — Outbound, TCP/443 (HTTPS). ✅ Recommended.
- HTTP-01 — Inbound, TCP/80 (HTTP). ⚠️ Only if DNS-01 is unavailable.