This is a ACMEv2 client for Windows that aims to be very simple to start with, but powerful enough to grow into almost every scenario.
- A very simple interface to create and install certificates on a local IIS server
- A more advanced interface for many other use cases, including Apache and Exchange
- Automatically creates a scheduled task to renew certificates when needed
- Get certificates with wildcards (*.example.com), international names (证书.example.com), OCSP Must Staple extension (optional).
- Re-use private keys for DANE, use EC crypto or bring your own CSR
- Advanced toolkit for DNS, HTTP and TLS validation: SFTP/FTPS, acme-dns, Azure, Route53, Cloudflare and many more…
- Store your certificates where and how you want them: Windows, IIS Central Store, .pem files, .pfx file or KeyVault
- Compatible with all popular ACME services, including Let’s Encrypt, ZeroSSL, DigiCert, Sectigo, Buypass, Keyon and others…
- Completely unattended operation from the command line
- Other forms of automation through manipulation of .json files
- Write your own Powershell .ps1 scripts to handle installation and validation
- Build your own plugins with C#
Let’s Encrypt client and ACME library written in Go.
Features
- ACME v2 [RFC 8555}(https://www.rfc-editor.org/rfc/rfc8555.html)
- Register with CA
- Obtain certificates, both from scratch or with an existing CSR
- Renew certificates
- Revoke certificates
- Robust implementation of all ACME challenges
- HTTP (http-01)
- DNS (dns-01)
- TLS (tls-alpn-01)
- SAN certificate support
- Comes with multiple optional DNS providers
- Custom challenge solvers
- Certificate bundling
- OCSP helper function
github: LEGO
acme.sh --issue -d example.com --dns \
--yes-I-know-dns-manual-mode-enough-go-ahead-please
acme.sh --renew -d example.com \
--yes-I-know-dns-manual-mode-enough-go-ahead-please- An ACME protocol client written purely in Shell (Unix shell) language.
- Full ACME protocol implementation.
- Support ACME v1 and ACME v2
- Support ACME v2 wildcard certs
- Simple, powerful and very easy to use. You only need 3 minutes to learn it.
- Bash, dash and sh compatible.
- Purely written in Shell with no dependencies on python or the official Let's Encrypt client.
- Just one script to issue, renew and install your certificates automatically.
- DOES NOT require root/sudoer access.
- Docker friendly
- IPv6 support
- Cron job notifications for renewal or error etc.
It's probably the easiest & smartest shell script to automatically issue & renew the free certificates from Let's Encrypt.
The web is moving to HTTPS, preventing network attackers from observing or injecting page contents. But HTTPS needs TLS certificates, and while deployment is increasingly a solved issue thanks to the ACME protocol and Let's Encrypt, development still mostly ends up happening over HTTP because no one can get an universally valid certificate for localhost.