SSL Automation
Automate SSL/TLS certificates with ACME
FairSSL's ACME service gives IT professionals, consultants and hosting providers a fast way to automate SSL/TLS certificate management. It is secure, flexible and free from the limitations of free certificate authorities.
Built on ACME v2 (RFC 8555) with ACME Renewal Information (ARI, RFC 9773) support. Our platform automates certificate lifecycle management, including early renewal, CA switching and monitoring of both certificate and client status.
Shorter SSL lifetimes adopted
An SSL certificate can be valid for at most 199 days now, 99 days from 15 March 2027 and 47 days from 15 March 2029. Without automation, it becomes an administrative nightmare. Learn more →
The price is fixed, reissues are included
The automation fee is €33 per certificate per year and is added on top of the certificate price. One fee covers up to 25 servers, and the price stays the same no matter how often the certificate is reissued. See pricing →
Key benefits of FairSSL ACME
Free choice of CA and product
DV certificates from the DigiCert family: RapidSSL and Thawte SSL123, as single-domain, SAN and wildcard.
Automated domain validation
Use AutoDNS without exposing DNS API keys, ideal for internal networks and secure environments.
Centralised administration
Create profiles with product-specific settings, monitor certificate expiry and client status, switch products without changing server configuration.
Security controls
Block or allow wildcard issuance and SAN name changes per profile and per ACME client. Lock down ACME clients after setup.
High limits
No limits on the number of paid certificates, up to 1,000 duplicates and 250 SANs. Perfect for disaster recovery and scaling.
ARI: smart renewal
ACME Renewal Information (ARI, RFC 9773) checks daily whether certificates should be renewed early and lets us monitor that each server's ACME client is active and healthy.
Instant issuance with one DNS record
Publish one permanent DNS record and orders for the DigiCert brands are validated and issued immediately, both in the portal and through the ACME solution. No tokens per order. Available to customers with their own DigiCert account and for OV/EV with their own organization.
Transparent pricing
The ACME service fee is charged per main certificate per year. One fee covers up to 25 servers using that certificate, and each server gets its own reissued certificate at no extra cost.
- SAN changes and reissues are exempt from the fee
- Additional ACME clients using the same certificate: free
- Standard certificate prices apply on top
Certificate Reuse: One Certificate, Many Servers
Do you have the same domain running on multiple servers, e.g., behind a load balancer, in a cluster, or with staging/production environments? You don't need to buy a certificate per server.
With FairSSL ACME, the certificate is managed centrally. When renewed, your ACME client automatically distributes it to all servers using it. You pay for the certificate, not the number of installations.
| Scenario | Competitors | FairSSL |
|---|---|---|
| 1 SAN certificate (www, api, mail), 5 servers | 5 licenses | 1 certificate |
| 1 SAN certificate, 20 servers behind a load balancer | 20 licenses | 1 certificate |
| 1 wildcard, 25 servers | 25 licences | 1 certificate |
We sell certificates, not licenses per server. One certificate covers all servers it is installed on. With FairSSL ACME the fee is charged per main certificate, and one fee covers up to 25 servers.
Worked example: 30 servers, 10 certificates
A company with 30 servers spread across 10 certificates pays for 10 certificates plus 10 ACME fees, roughly €790 per year in total. There are no per-server licenses, and the price does not rise when certificates must be renewed more often.
Security without DNS keys on your servers
Many automation tools require a DNS API key on every server to issue certificates. If that key leaks, an attacker can change your DNS. With FairSSL AutoDNS the validation stays with us: your servers need neither DNS keys nor open ports.
We recommend certificates with named hosts (SAN) over wildcards, and you can enforce it: lock each ACME client to specific names and block wildcard issuance per profile.
Built for engineers
"Set and forget" validation
Forget opening firewalls or handling temporary tokens. We use permanent DNS CNAME validation.
- Your servers need no inbound internet access
- Set the CNAME once, we handle validation automatically forever
Intelligent certificate reuse
Why pay for new certificates when you have 10 servers behind a load balancer?
- The system reuses existing certificates across your infrastructure
- Additional ACME clients using the same certificate are included in the ACME fee
No salespeople: just engineers
You are not talking to sales. You are talking to the developers who built the system.
- No sales meetings, no "contact us for pricing", no upfront payments
- Step-by-step guides for Windows (IIS), Linux and Kubernetes
Popular ACME Clients
Any ACME client that follows RFC 8555 and supports EAB works with FairSSL. Here are the clients we have tested and can help with.
Windows
IIS, Exchange, RDP, SQL Server, ADFS
simple-acme, Certify The Web, Posh-ACMELinux
Apache, Nginx, HAProxy, Docker, Kubernetes
Lego, Certbot, acme.sh, CaddyNetwork Appliances
F5, Palo Alto, NetScaler, Fortinet, pfSense
FortiGate, NetScaler, F5, KEMP, KubernetesCloud
Azure, AWS, Kubernetes cert-manager
Key Vault Acmebot, cert-managerOur recommendation: simple-acme for Windows, Lego for Linux and CI/CD. FairSSL sponsors both projects. They have the best integration with the FairSSL ACME server and support ARI for intelligent renewal and monitoring.
Comparison with free ACME services
See the difference between FairSSL ACME, Let’s Encrypt and ZeroSSL.
Scroll right to see more providers
| Feature | FairSSL | Let's Encrypt |
|---|---|---|
| Certificate types | DV (RapidSSL, Thawte SSL123) | DV |
| Certificate validity | 1–199 days | 90 days (6 days announced) |
| Permanent DNS validation (DNS-PERSIST-01) | ✓ One record, instant issuance (DigiCert brands) | Announced, staging only |
| Supports multiple CAs | ✓ | ✗ |
| ACME client monitoring | ✓ | ✗ |
| Expiry alerts & reports | Email lists, daily/weekly/monthly | ✗ |
| Certificates per domain | No limit | 50 per week |
| Duplicate certificates | 1,000 | 5 per week |
| Names per certificate (SANs) | 250 | 100 |
| Wildcards allowed | ✓ | ✓ (requires DNS API key) |
| DNS validation | AutoDNS — set and forget | Requires DNS API key on client |
| Centralised management | ✓ | ✗ |
| Per-profile wildcard control | ✓ | ✗ |
| Per-client SAN locking | ✓ | ✗ |
| Order period | 1–3 years | No order, 90 days at a time |
| Installation guides | ✓ Step-by-step | Community documentation |
| Debug event log | ✓ Full traceability | ✗ |
| Support | Phone & email | Community forum |
ACME server details
- ACME directory URL
- https://fairssl.dk/acme
- Protocol
- ACME v2 (RFC 8555), ARI (RFC 9773)
- Account binding
- EAB (preferred) or a custom URL for appliances without EAB
- Certificate types
- DV from RapidSSL and Thawte SSL123, including SAN and wildcard
- Certificate authorities
- DigiCert family (RapidSSL and Thawte). GlobalSign and Sectigo are not issued through automation
- Automation fee
- €33 per certificate/year, on top of the certificate price (250 DKK for invoicing in Danish kroner, 370 SEK in Swedish kronor)
- Fee unit
- Per main certificate per year. Up to 25 servers using that certificate are included
- DNS validation
- AutoDNS: no DNS keys, no open ports
- Persistent domain validation
- DNS-PERSIST-01 (CA/Browser Forum), DigiCert brands
Get started from the control panel
- Create a free account, or log in to the control panel.
- Choose SSL Automation and the platform the certificate is for, such as IIS, nginx or a FortiGate.
- Enter the domains. The control panel generates the command or configuration with your key and the server address.
- Copy it and run it on the server. Add one CNAME for AutoDNS and no inbound ports need to be opened.
The command carries your EAB key, so the client is bound to your account. Renewal and monitoring then run on their own.
ACME-compatible certificates
These DV certificates support automatic ACME issuance and renewal:
Frequently asked questions about ACME automation
Find answers to the most common questions about SSL certificates and FairSSL.
Ready to create a free account?
Create a free account and order your first certificate. A DV certificate is issued in under 2 minutes.