SSL certificates can be valid for at most 199 days. From 15 March 2027 the limit becomes 99 days. Read more →

SSL Automation

Automate SSL/TLS certificates with ACME

FairSSL's ACME service gives IT professionals, consultants and hosting providers a fast way to automate SSL/TLS certificate management. It is secure, flexible and free from the limitations of free certificate authorities.

Built on ACME v2 (RFC 8555) with ACME Renewal Information (ARI, RFC 9773) support. Our platform automates certificate lifecycle management, including early renewal, CA switching and monitoring of both certificate and client status.

Shorter SSL lifetimes adopted

An SSL certificate can be valid for at most 199 days now, 99 days from 15 March 2027 and 47 days from 15 March 2029. Without automation, it becomes an administrative nightmare. Learn more →

The price is fixed, reissues are included

The automation fee is €33 per certificate per year and is added on top of the certificate price. One fee covers up to 25 servers, and the price stays the same no matter how often the certificate is reissued. See pricing →

Key benefits of FairSSL ACME

Free choice of CA and product

DV certificates from the DigiCert family: RapidSSL and Thawte SSL123, as single-domain, SAN and wildcard.

Automated domain validation

Use AutoDNS without exposing DNS API keys, ideal for internal networks and secure environments.

Centralised administration

Create profiles with product-specific settings, monitor certificate expiry and client status, switch products without changing server configuration.

Security controls

Block or allow wildcard issuance and SAN name changes per profile and per ACME client. Lock down ACME clients after setup.

High limits

No limits on the number of paid certificates, up to 1,000 duplicates and 250 SANs. Perfect for disaster recovery and scaling.

ARI: smart renewal

ACME Renewal Information (ARI, RFC 9773) checks daily whether certificates should be renewed early and lets us monitor that each server's ACME client is active and healthy.

Instant issuance with one DNS record

Publish one permanent DNS record and orders for the DigiCert brands are validated and issued immediately, both in the portal and through the ACME solution. No tokens per order. Available to customers with their own DigiCert account and for OV/EV with their own organization.

Transparent pricing

€33 per certificate

The ACME service fee is charged per main certificate per year. One fee covers up to 25 servers using that certificate, and each server gets its own reissued certificate at no extra cost.

  • SAN changes and reissues are exempt from the fee
  • Additional ACME clients using the same certificate: free
  • Standard certificate prices apply on top

Certificate Reuse: One Certificate, Many Servers

Do you have the same domain running on multiple servers, e.g., behind a load balancer, in a cluster, or with staging/production environments? You don't need to buy a certificate per server.

With FairSSL ACME, the certificate is managed centrally. When renewed, your ACME client automatically distributes it to all servers using it. You pay for the certificate, not the number of installations.

Scenario Competitors FairSSL
1 SAN certificate (www, api, mail), 5 servers 5 licenses 1 certificate
1 SAN certificate, 20 servers behind a load balancer 20 licenses 1 certificate
1 wildcard, 25 servers 25 licences 1 certificate

We sell certificates, not licenses per server. One certificate covers all servers it is installed on. With FairSSL ACME the fee is charged per main certificate, and one fee covers up to 25 servers.

Worked example: 30 servers, 10 certificates

A company with 30 servers spread across 10 certificates pays for 10 certificates plus 10 ACME fees, roughly €790 per year in total. There are no per-server licenses, and the price does not rise when certificates must be renewed more often.

Security without DNS keys on your servers

Many automation tools require a DNS API key on every server to issue certificates. If that key leaks, an attacker can change your DNS. With FairSSL AutoDNS the validation stays with us: your servers need neither DNS keys nor open ports.

We recommend certificates with named hosts (SAN) over wildcards, and you can enforce it: lock each ACME client to specific names and block wildcard issuance per profile.

Built for engineers

1

"Set and forget" validation

Forget opening firewalls or handling temporary tokens. We use permanent DNS CNAME validation.

  • Your servers need no inbound internet access
  • Set the CNAME once, we handle validation automatically forever
2

Intelligent certificate reuse

Why pay for new certificates when you have 10 servers behind a load balancer?

  • The system reuses existing certificates across your infrastructure
  • Additional ACME clients using the same certificate are included in the ACME fee
3

No salespeople: just engineers

You are not talking to sales. You are talking to the developers who built the system.

  • No sales meetings, no "contact us for pricing", no upfront payments
  • Step-by-step guides for Windows (IIS), Linux and Kubernetes

Popular ACME Clients

Any ACME client that follows RFC 8555 and supports EAB works with FairSSL. Here are the clients we have tested and can help with.

Our recommendation: simple-acme for Windows, Lego for Linux and CI/CD. FairSSL sponsors both projects. They have the best integration with the FairSSL ACME server and support ARI for intelligent renewal and monitoring.

Comparison with free ACME services

See the difference between FairSSL ACME, Let’s Encrypt and ZeroSSL.

Scroll right to see more providers

Feature FairSSL Let's Encrypt
Certificate types DV (RapidSSL, Thawte SSL123) DV
Certificate validity 1–199 days 90 days (6 days announced)
Permanent DNS validation (DNS-PERSIST-01) ✓ One record, instant issuance (DigiCert brands) Announced, staging only
Supports multiple CAs
ACME client monitoring
Expiry alerts & reports Email lists, daily/weekly/monthly
Certificates per domain No limit 50 per week
Duplicate certificates 1,000 5 per week
Names per certificate (SANs) 250 100
Wildcards allowed ✓ (requires DNS API key)
DNS validation AutoDNS — set and forget Requires DNS API key on client
Centralised management
Per-profile wildcard control
Per-client SAN locking
Order period 1–3 years No order, 90 days at a time
Installation guides ✓ Step-by-step Community documentation
Debug event log ✓ Full traceability
Support Phone & email Community forum

ACME server details

ACME directory URL
https://fairssl.dk/acme
Protocol
ACME v2 (RFC 8555), ARI (RFC 9773)
Account binding
EAB (preferred) or a custom URL for appliances without EAB
Certificate types
DV from RapidSSL and Thawte SSL123, including SAN and wildcard
Certificate authorities
DigiCert family (RapidSSL and Thawte). GlobalSign and Sectigo are not issued through automation
Automation fee
€33 per certificate/year, on top of the certificate price (250 DKK for invoicing in Danish kroner, 370 SEK in Swedish kronor)
Fee unit
Per main certificate per year. Up to 25 servers using that certificate are included
DNS validation
AutoDNS: no DNS keys, no open ports
Persistent domain validation
DNS-PERSIST-01 (CA/Browser Forum), DigiCert brands

Get started from the control panel

  1. Create a free account, or log in to the control panel.
  2. Choose SSL Automation and the platform the certificate is for, such as IIS, nginx or a FortiGate.
  3. Enter the domains. The control panel generates the command or configuration with your key and the server address.
  4. Copy it and run it on the server. Add one CNAME for AutoDNS and no inbound ports need to be opened.
Go to the control panel →

The command carries your EAB key, so the client is bound to your account. Renewal and monitoring then run on their own.

ACME-compatible certificates

These DV certificates support automatic ACME issuance and renewal:

RapidSSL

RapidSSL

DV

Standard DV. Issued in minutes.

from €46 /year See details →
Thawte

Thawte SSL123 SAN DV

DV

DV multi-domain. Supports SAN names and wildcards in combination.

from €86 /year See details →

Frequently asked questions about ACME automation

Find answers to the most common questions about SSL certificates and FairSSL.

The ACME service fee is €33 per main certificate per year, on top of the certificate price. One fee covers up to 25 servers using that certificate, and each server gets its own reissued certificate free. SAN changes and reissues are exempt, and additional ACME clients on the same certificate are free. A separate certificate is priced from scratch: its own price plus the fee.
The CA/Browser Forum adopted a phased reduction in 2025 (SC-081). The maximum lifetime is 199 days now, 99 days from 15 March 2027 and 47 days from 15 March 2029. Without automation, it becomes an administrative nightmare.
No. You pay for an order period, typically one year, and the price stays the same no matter how many times the certificate is reissued within that period. Since March 2026 certificates must be replaced more often, and from 15 March 2027 more often still, but every reissue is included in the price. With SSL Automation from FairSSL, renewal happens automatically.
If you already use ACME (Certbot, simple-acme, acme.sh) and renew automatically, you are well positioned. If you renew manually, you should migrate to ACME now.
No. Automation issues DV certificates from RapidSSL and Thawte SSL123, as single-domain, SAN and wildcard. OV and EV are ordered in the control panel, where pre-validation makes issuance fast: call or write and we will set it up.
Yes. cert-manager supports ACME with External Account Binding (EAB) and can be configured to point at the FairSSL ACME server.
No limits on the number of paid certificates per domain, up to 1,000 duplicates and 250 names (SANs) per certificate. We have high request rate limits to prevent errors and misuse, but they do not affect normal operations. Perfect for disaster recovery, scaling and large installations.

Ready to create a free account?

Create a free account and order your first certificate. A DV certificate is issued in under 2 minutes.