Emergency server help: get in touch

DirectAdmin External Account Binding: Paid CA Setup in 1.711+

How to connect DirectAdmin's built-in ACME client to a commercial certificate authority using External Account Binding credentials, which providers to expect, how to hide the ones you do not sell, and how to confirm certificates are coming from the paid account.

Published Updated 6 min read

DirectAdmin 1.711, released on 2026-09-22, added External Account Binding to the ACME TLS system. EAB is the mechanism most commercial CAs use to tie an ACME account to a paying customer: you get a key identifier and an HMAC key from the CA’s portal, hand them to the ACME client once, and every certificate that client requests is billed to and issued from your commercial account. This is how a hosting provider offers paid OV or branded certificates through the same automation that already handles free ones, without a separate certificate-installation workflow.

Short answer: Generate ACME credentials in the CA’s portal, then add the provider under Admin Level → Server TLS Certificate in DirectAdmin 1.711 or later with the directory URL, EAB key ID and HMAC key; the panel registers the account once and stores the key under data/admin/. Hide the provider from ordinary users with da config-set acme_hidden_cert_providers, select it per domain, and confirm the issuer with openssl s_client.

Why use a paid CA with ACME

Free issuers remain the right default for most domains. The reasons to add a paid CA are practical: an OV certificate for a customer who needs the organisation name in the certificate, a CA whose roots are trusted in a legacy environment, dedicated support and SLAs, or simply avoiding the per-domain rate limits on a server that hosts thousands of names. Certificate lifetimes are shrinking for everyone (200 days from March 2026, 100 days in 2027, 47 days in 2029 under the CA/Browser Forum schedule), so manual paid certificates become impractical, and EAB is the way to keep them automated.

Getting the credentials

Log into the CA’s account portal and generate ACME credentials. Different CAs label them differently but you receive three things: the ACME directory URL, an EAB key ID, and an EAB HMAC key (a base64 string). Some CAs issue one set of credentials per organisation and others let you create one per server; the per-server option is better because a leaked key can be revoked without affecting other machines.

Note whether the credentials are single-use. Several CAs invalidate the HMAC after the first account registration, which is fine for DirectAdmin because the panel registers once and stores the resulting account key, but it means you cannot reuse the same pair on a second server.

Adding the provider in DirectAdmin

In the Evolution skin, open Admin Level → Server TLS Certificate and then the certificate providers section. Add a provider with the directory URL and paste the EAB key ID and HMAC key. The panel registers the ACME account immediately and reports success or the CA’s error message. The account key is stored under /usr/local/directadmin/data/admin/ alongside the existing Let’s Encrypt and ZeroSSL accounts; it is root-readable only and is not exposed to users.

Once registered, the provider appears in every user’s certificate provider list. If you sell paid certificates as an add-on rather than to everyone, restrict who sees it. 1.711 added acme_hidden_cert_providers, a comma-separated list of provider names to hide from the user-level interface while still allowing administrators to select them:

da config-set acme_hidden_cert_providers "commercial-ca"
da config-get acme_hidden_cert_providers

Setting it takes effect without a restart on 1.710 and later. To offer the paid provider to specific users, set it on their domains as admin and leave it hidden for everyone else.

The default provider for new domains is governed by default_acme_profile and the provider ordering. Do not make the paid CA the server default unless you intend to pay for every certificate on the box, including hostnames and test domains.

Issuing a certificate from the paid account

For a domain, open User Level → SSL Certificates, choose the automatic ACME option, pick the commercial provider from the drop-down and save. The request goes through the same HTTP-01 or DNS-01 validation as any other, and the result is recorded in Provisioning history. Renewal is automatic at 65 percent of the certificate lifetime, and each renewal is a new order billed according to your CA agreement, so check with the CA whether renewals count as new issuances.

For OV certificates the CA has to have validated your organisation beforehand; the ACME order will hang in a pending state until that is complete. The panel shows it as a failure after the timeout and retries on the next daily run.

Common pitfall: HMAC pasted with whitespace

The most common registration failure is a trailing newline or space in the HMAC key copied from a portal. The CA returns a generic “malformed” or “unauthorized” error rather than saying the key is wrong. Re-copy the key carefully, and if the CA’s credentials are single-use you may need to generate a new pair. The second most common failure is an outbound firewall that permits the Let’s Encrypt endpoints but not the commercial CA’s directory URL; test with curl -sI <directory-url> from the server before blaming the credentials.

Verify

Confirm the issuer on a certificate requested through the new provider:

openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
  | openssl x509 -noout -issuer -dates

The issuer should name the commercial CA rather than Let’s Encrypt or ZeroSSL. Check the CA portal shows the order against your account, and review the first automatic renewal in Provisioning history to make sure it also went to the paid account rather than falling back to a free provider. Our SSL expiry check script can be pointed at the domains on the paid tier to give you an independent view of what is actually being served.

DirectAdmin External Account Binding at a glance

DirectAdmin External Account Binding summary card: Generate ACME credentials in the CA's portal, then add the provider under Admin Level → Server TLS Certificate in…
In short: Generate ACME credentials in the CA’s portal, then add the provider under Admin Level → Server TLS Certificate in DirectAdmin 1.711 or later with the directory URL, EAB key ID and HMAC key; the panel registers the account once and stores…

Official documentation: DirectAdmin documentation, Linux man pages.

Related guides: Migrating domains to DirectAdmin’s new ACME TLS system (1.706+) and running the migration task · Exim, Dovecot or DirectAdmin still serving the old certificate after renewal · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback.

Frequently asked questions

Does External Account Binding work with ZeroSSL and Google Trust Services as well as paid CAs?

Yes. Any ACME CA that issues EAB credentials can be added the same way; DirectAdmin already creates a ZeroSSL account automatically from 1.707, and other free or paid issuers that require EAB are added through the same provider form.

How long does it take to get certificates from the paid CA after adding it?

Registration is immediate, and a DV certificate from the commercial provider is normally issued within a minute of the validation completing; OV orders wait until the CA has validated the organisation, which can take several days the first time.

Can I undo this?

Yes. Remove the provider from the Server TLS Certificate page and switch affected domains back to a free provider; their next renewal is issued from the new provider, and the paid CA account can be revoked in the CA’s portal.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.