# Account keys info

**URL:** <https://community.letsencrypt.org/t/account-keys-info/102049>\
**Category:** Client dev\
**Created:** [September 15, 2019, 9:11am UTC](https://community.letsencrypt.org/t/account-keys-info/102049 "2019-09-15T09:11:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![roberta\_sgroi](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@roberta\_sgroi](https://community.letsencrypt.org/u/roberta_sgroi)\
**Post date:** [September 15, 2019, 9:11am UTC](https://community.letsencrypt.org/t/account-keys-info/102049/1 "2019-09-15T09:11:24Z")

</div>

Hi everybody,  
I hope that I choose the correct category.  
I’m working with let’s encrypt and certbot for my master thesis and there’s something in the acme draft that is not completely clear to me.

I have analyzed the acme process and the log written by certbot when interacting with let’s encrypt.  
I read that when you create a new account, a key pair is linked to that account.  
But which kind of key pair are?  
They are not the keys linked to the certificate for sure. Those keys will be generated only when a new-order has to be submitted.

I also read about account key rollover and inside the draft there’s an example of the jws that certbot should create to achive the goal. But I am not able to find the right cmd to be run and It looks like this feature is not available? Is it correct?

I hope that someone can help me 🙂

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [September 15, 2019, 9:36am UTC](https://community.letsencrypt.org/t/account-keys-info/102049/2 "2019-09-15T09:36:07Z")

</div>

> [@roberta\_sgroi](#):
>
> They are not the keys linked to the certificate for sure. Those keys will be generated only when a new-order has to be submitted.

Yep. There is a completely separate keypair for the ACME account. With Certbot, you can find it in inside `/etc/letsencrypt/accounts`. The JWK representation of the key is in `private_key.json`.

> [@roberta\_sgroi](#):
>
> But I am not able to find the right cmd to be run and It looks like this feature is not available? Is it correct?

Yes. Very few ACME clients implement account key rollover because it's not a commonly needed function. If required, most people just deactivate their accounts and move on, since making a new Let's Encrypt account is very easy.

However, users of other CAs (such as commercial ones) that implement ACME, might find the key rollover more useful, depending on how account registration works.

> [@roberta\_sgroi](#):
>
> inside the draft

No longer a draft! RFC8555 has been standardized for some time now.

---

<div class="post-metadata">

**Author:** ![roberta\_sgroi](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@roberta\_sgroi](https://community.letsencrypt.org/u/roberta_sgroi)\
**Post date:** [September 15, 2019, 9:51am UTC](https://community.letsencrypt.org/t/account-keys-info/102049/3 "2019-09-15T09:51:58Z")

</div>

Thank you so much, you have been very clear.  
Moreover I didn’t know that the draft had become official, this is a great news.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 15, 2019, 9:52am UTC](https://community.letsencrypt.org/t/account-keys-info/102049/4 "2019-10-15T09:52:00Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
