Credentials
Credentials store authentication information (username and password, API key, tokens, etc.) to connect with specific third-party apps and services.
On the access management page, you can centrally manage your credential information required for Certimate to access other services.
Read the Providers guide to learn more details.
How to retrieve provider's credentials?
Alibaba Cloud
Please refer to the official user manual.
Least privileges:
- Request certificates (DNS-01 challenge):
- Use system policy:
AliyunDNSFullAccess
- Use custom policy:
alidns:DescribeDomainsalidns:DescribeDomainRecordsalidns:AddDomainRecordalidns:UpdateDomainRecordalidns:DeleteDomainRecord
- Use system policy:
- Deploy certificates:
- Use system policy:
AliyunYundunCertFullAccess- Full access to the related services or resources.
- Use custom policy:
yundun-cert:ListUserCertificateOrderyundun-cert:GetUserCertificateDetailyundun-cert:UploadUserCertificate- Full access to the related services or resources.
- Use system policy:
Tencent Cloud
Please refer to the official user manual.
Least privileges:
- Request certificates (DNS-01 challenge):
- Use system policy:
QcloudDNSPodFullAccess
- Use custom policy:
dnspod:CreateRecorddnspod:ModifyRecorddnspod:DeleteRecord
- Use system policy:
- Deploy certificates:
- Use system policy:
QcloudSSLFullAccess- Full access to the related services or resources.
- Use custom policy:
ssl:DescribeCertificatesssl:DescribeCertificatessl:DescribeCertificateDetailssl:UploadCertificate- Full access to the related services or resources.
- Use system policy:
Baidu Cloud
Please refer to the official user manual.
Least privileges:
- Request certificates (DNS-01 challenge):
- Use system policy:
DNSOperatePolicy
- Use custom policy:
bce:dns:READbce:dns:OPERATE
- Use system policy:
- Deploy certificates:
- Use system policy:
CASFullControlPolicy- Full access to the related services or resources.
- Use custom policy:
bce:cas:FULL_CONTROL- Full access to the related services or resources.
- Use system policy:
Huawei Cloud
Please refer to the official user manual.
Least privileges:
- Request certificates (DNS-01 challenge):
- Use system policy:
DNSFullAccess
- Use custom policy:
dns:zone:listdns:recordset:listdns:recordset:getdns:recordset:createdns:recordset:updatedns:recordset:delete
- Use system policy:
- Deploy certificates:
- Use system policy:
SCMFullAccess- Full access to the related services or resources.
- Use custom policy:
scm:cert:listscm:cert:getscm:cert:downloadscm:cert:upload- Full access to the related services or resources.
- Use system policy:
Volc Engine
Please refer to the official user manual.
Least privileges:
- Request certificates (DNS-01 challenge):
- Use system policy:
DNSFullAccess
- Use custom policy:
dns:ListZonesdns:CreateRecorddns:UpdateRecorddns:DeleteRecord
- Use system policy:
- Deploy certificates:
- Use system policy:
SSLFullAccess- Full access to the related services or resources.
- Use custom policy:
ImportCertificate- Full access to the related services or resources.
- Use system policy:
JD Cloud
Please refer to the official user manual.
Least privileges:
- Request certificates (DNS-01 challenge):
- Use system policy:
JDCloudDomainServiceAdmin
- Use custom polify:
domainservice:describeDomainsdomainservice:describeResourceRecorddomainservice:createResourceRecorddomainservice:modifyResourceRecorddomainservice:deleteResourceRecord
- Use system policy:
- Deploy certificates:
- Use system policy:
JDCloudSSLAdmin- Full access to the related services or resources.
- Use custom polify:
ssl:describeCertsssl:uploadCert- Full access to the related services or resources.
- Use system policy:
AWS
Please refer to the official user manual。
Least privileges:
- Request certificates (DNS-01 challenge):
route53:ListHostedZonesroute53:ListHostedZonesByNameroute53:GetHostedZoneroute53:ListResourceRecordSetsroute53:ChangeResourceRecordSetsroute53:GetChange
- Deploy certificates:
acm:ListCertificatesacm:GetCertificateacm:ImportCertificate- Full access to the related services or resources.
Azure
Please refer to the official user manual。
Least privileges:
- Request certificates (DNS-01 challenge):
Microsoft.Network/dnsZones/readMicrosoft.Network/dnsZones/TXT/*
- Deploy certificates:
Microsoft.KeyVault/vaults/certificates/readMicrosoft.KeyVault/vaults/certificates/write- Full access to the related services or resources.
Cloudflare
Please refer to the following process to obtain:
- Log in to the Cloudflare console.
- Click on the account avatar, then click on "My Profile" -> "API Tokens" -> "Create Token", and select to use the "Edit zone DNS" template.
- Add permission, fill in your domain names, then click the "Continue" button.
Least privileges:
- Request certificates (DNS-01 challenge):
Zone / Zone / ReadZone / DNS / Edit