# FairSSL > FairSSL A/S is an independent Danish SSL/TLS certificate provider (founded 2010, CVR DK33075782) selling from DigiCert, GlobalSign and Sectigo. Its core technical strength is a cloud ACME server with FairSSL AutoDNS: automated certificate issuance and renewal without DNS API keys or open ports on your servers. ## Key facts - The ACME automation fee is charged per certificate per year, on top of the certificate price, and covers up to 25 servers per certificate. A 26th server adds another fee of the same size. Reissues within the paid order period are included; the annual order renewal is a separate purchase. - Protocol: ACME v2 (RFC 8555) with ACME Renewal Information / ARI (RFC 9773). Account binding uses External Account Binding (EAB, preferred, supports multiple accounts) or a custom directory URL (one per account) for appliances without EAB. ACME directory URL: https://fairssl.dk/acme - Certificate types via ACME: DV and OV, plus EV via GlobalSign with prior validation. Certificate authorities: the DigiCert family (RapidSSL, Thawte, GeoTrust, DigiCert) and GlobalSign. Sectigo ACME is not yet available. - FairSSL AutoDNS: create one CNAME record (_dnsauth.your-domain CNAME your-id.autodns.fairssl.dk). A single record on the base domain covers all names on the domain, including wildcards. Your servers need no DNS API keys and no open ports. AutoDNS handles validation for DigiCert-family brands (DigiCert, RapidSSL, GeoTrust, Thawte). ## ACME automation - [SSL automation (ACME)](https://www.fairssl.dk/en/ssl-automation/): overview, pricing, supported platforms - [How FairSSL ACME works](https://www.fairssl.dk/en/ssl-automation/how-it-works/): protocol, EAB, ARI, AutoDNS, HTTP-01 vs DNS-01 - [FairSSL AutoDNS](https://www.fairssl.dk/en/ssl-automation/auto-dns/): DNS validation without keys or open ports - [FairSSL ACME vs Let's Encrypt](https://www.fairssl.dk/en/ssl-automation/fairssl-vs-lets-encrypt/): comparison and priced scenarios - [ACME clients](https://www.fairssl.dk/en/ssl-automation/clients/): simple-acme, Lego, certbot, acme.sh, cert-manager, Posh-ACME - [Appliances and load balancers](https://www.fairssl.dk/en/ssl-automation/appliances/): FortiGate, NetScaler, F5, KEMP, Kubernetes ## Supported platforms and versions The setup wizard in the FairSSL control panel writes the setup for each platform below, and each line states the versions that setup is written for. Windows setups run simple-acme 2.4.0 or newer in the FairSSL edition, a self-contained win-x64 trimmed build with .NET 10 included, so no separate runtime is installed; only IIS 6.0 to 7.5 on Windows Server 2008 R2 or older needs an older simple-acme release. Linux, macOS and Linux-agent setups run lego 5.0.4 or newer, except Caddy, which uses its own ACME client. Line format: platform | supported versions | runs on | ACME client | guide ### Windows - IIS | IIS 8 and newer | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - IIS (legacy) | IIS 6.0 to 7.5, the IIS binding is set by hand | Windows Server 2008 R2 or older | An older simple-acme release that still runs on Windows Server 2008 R2 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - Exchange Server | 2013, 2016, 2019 and Subscription Edition | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportExchange.v3.ps1 | https://www.fairssl.dk/en/guides/exchange-ssl-acme/ - Remote Desktop Services | RD Gateway (also without an RD Connection Broker), RD Web Access, RD Web Client, RD Connection Broker and the RDP listener | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportRDSFullFairSSL.ps1 | https://www.fairssl.dk/en/guides/rdp-rd-gateway-ssl-certificate/ - Dynamics NAV / Business Central | NAV 2013 R2 and newer, every Business Central version (on-premises) | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportDynamicsNAV.ps1 | https://www.fairssl.dk/en/guides/dynamics-nav-business-central-ssl/ - AD FS | The guide sets no version limit | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportADFS-WAP.v1.ps1 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - Web Application Proxy | The guide sets no version limit | Windows Server 2012 R2 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportADFS-WAP.v1.ps1 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - SQL Server | The guide sets no version limit | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportSQL.ps1 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - PRTG Network Monitor | The guide sets no version limit | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportPRTG.ps1 | https://www.fairssl.dk/en/guides/prtg-ssl-acme/ - Apache Tomcat | 8.5, 9.x, 10.x and 11.x | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportTomcat.ps1 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - Other Windows service | Certificate store, PFX or PEM, with your own script | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + ImportCustomWindows.ps1 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ - Several Windows servers | Receiving servers: Windows Server 2012 or newer with PowerShell 5.1 and WinRM | Windows Server 2012 or newer | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + DistributeToWindowsServers.ps1 | https://www.fairssl.dk/en/guides/simple-acme-windows-guide/ ### Linux - nginx | The guide sets no version limit | Linux | lego 5.0.4+ | - - Apache | The guide sets no version limit | Linux | lego 5.0.4+ | - - HAProxy | The guide sets no version limit | Linux | lego 5.0.4+ | - - Traefik | With the file provider | Linux | lego 5.0.4+ | - - Postfix | The guide sets no version limit | Linux | lego 5.0.4+ | - - Caddy | The guide sets no version limit | Linux | Caddy’s built-in ACME with EAB | - - Other Linux service | The guide sets no version limit | Linux | lego 5.0.4+ | - ### macOS - macOS | The guide sets no version limit | macOS | lego 5.0.4+ | https://www.fairssl.dk/en/guides/macos-acme-lego/ ### Appliances - FortiGate | FortiOS 7.6.3 and newer | The device itself | The device’s built-in ACME client with EAB | https://www.fairssl.dk/en/guides/fortigate-ssl-acme/ - FortiGate | FortiOS before 7.6.3 | Windows Server 2016 or newer, or 2012/2012 R2 with WMF 5.1 (PowerShell 5.1) | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + Posh-SSH, CredentialManager | https://www.fairssl.dk/en/guides/fortigate-ssl-acme/ - FortiGate | FortiOS before 7.6.3 | A Linux server that pushes the certificate to the device | lego 5.0.4+ | https://www.fairssl.dk/en/guides/fortigate-ssl-acme/ - FortiMail | The guide sets no version limit | Windows Server 2016 or newer, or 2012/2012 R2 with WMF 5.1 (PowerShell 5.1) | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + Posh-SSH, CredentialManager | https://www.fairssl.dk/en/guides/fortigate-ssl-acme/ - FortiMail | The guide sets no version limit | A Linux server that pushes the certificate to the device | lego 5.0.4+ | https://www.fairssl.dk/en/guides/fortigate-ssl-acme/ - FortiWeb | The guide sets no version limit | Windows Server 2016 or newer, or 2012/2012 R2 with WMF 5.1 (PowerShell 5.1) | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + FortiWeb REST API, CredentialManager | https://www.fairssl.dk/en/guides/fortigate-ssl-acme/ - NetScaler ADC | The guide sets no version limit | Windows Server 2016 or newer, or 2012/2012 R2 with WMF 5.1 (PowerShell 5.1) | simple-acme 2.4.0+ (FairSSL edition, .NET 10 included) + NITRO API, CredentialManager | https://www.fairssl.dk/en/guides/netscaler-ssl-acme/ - F5 BIG-IP | BIG-IP 21.1.0 and newer | The device itself | The device’s built-in ACME client with EAB | https://www.fairssl.dk/en/guides/f5-big-ip-ssl/ - Kemp LoadMaster | LMOS 7.x and newer | A Linux server that pushes the certificate to the device | lego 5.0.4+ | https://www.fairssl.dk/en/guides/kemp-loadmaster-ssl/ - Cisco FDM (Firepower) | FTD 6.4+ | A Linux server that pushes the certificate to the device | lego 5.0.4+ | - - Cisco ASA and devices without EAB | The guide sets no version limit | The device itself | The device’s built-in ACME client with a single-use enrollment URL, no EAB | https://www.fairssl.dk/en/guides/cisco-asa-acme/ - Kubernetes | The guide sets no version limit | The Kubernetes cluster | cert-manager, ARI from v1.21 with the ACMEUseARI feature gate | https://www.fairssl.dk/en/guides/kubernetes-cert-manager/ ## Products and tools Prices are FairSSL's list prices from the product catalogue of 2026-10-04, per certificate for one year, excluding VAT. - [SSL certificates: types and how to choose](https://www.fairssl.dk/en/ssl-certificate/): DV, OV, EV, wildcard and multi-domain compared, from €22 / DKK 170 / SEK 250 per year - [DV SSL](https://www.fairssl.dk/en/dv-ssl/): domain validated, issued in under 2 minutes, from €22 / DKK 170 / SEK 250 per year - [OV and EV SSL](https://www.fairssl.dk/en/business-validated-ssl/): the organisation is validated and named in the certificate; OV from €79 / DKK 590 / SEK 880 per year, EV from €121 / DKK 900 / SEK 1,350 per year - [Wildcard SSL](https://www.fairssl.dk/en/wildcard-ssl/): one domain and all its subdomains on one level, from €74 / DKK 550 / SEK 820 per year - [Multi-domain (SAN) SSL](https://www.fairssl.dk/en/multi-domain-ssl/): several names on one certificate, from €77 / DKK 580 / SEK 860 per year - [Email certificates (S/MIME)](https://www.fairssl.dk/en/email-certificates/): sign and encrypt email, from €53 / DKK 400 / SEK 600 per year - [Document signing certificates](https://www.fairssl.dk/en/document-signing/): sign PDF documents, from €329 / DKK 2,460 / SEK 3,670 per year - [VMC and CMC certificates](https://www.fairssl.dk/en/vmc-certificates/): a verified brand logo in the inbox with BIMI, from €1,105 / DKK 8,250 / SEK 12,330 per year - [All products with prices](https://www.fairssl.dk/en/products/) - [SSL tools](https://www.fairssl.dk/en/tools/): SSL scanner, CAA generator, certificate decoder ## Code signing - [Code signing certificates](https://www.fairssl.dk/en/code-signing-certificates/): OV and EV code signing, from €374 / DKK 2,790 / SEK 4,180 per year. The private key must be kept on certified hardware: a USB token or a cloud HSM. - Key storage: [USB token](https://www.fairssl.dk/en/code-signing-usb-token/), [HSM key storage compared](https://www.fairssl.dk/en/code-signing-hsm-key-storage/), [Azure Key Vault](https://www.fairssl.dk/en/code-signing-azure-key-vault/), [Google Cloud KMS](https://www.fairssl.dk/en/code-signing-google-cloud-kms/), [AWS KMS](https://www.fairssl.dk/en/code-signing-aws-kms/) - Signing tools: [SignTool and AzureSignTool](https://www.fairssl.dk/en/code-signing-signtool/), [Jsign](https://www.fairssl.dk/en/code-signing-jsign/), [Office VBA macros](https://www.fairssl.dk/en/code-signing-office-macro-signing/) - Setup guides: [Azure Key Vault](https://www.fairssl.dk/en/guides/code-signing-azure-key-vault-setup/), [AWS KMS](https://www.fairssl.dk/en/guides/code-signing-aws-kms-setup/), [GlobalSign USB token](https://www.fairssl.dk/en/guides/code-signing-globalsign-usb-token/), [DigiCert USB token](https://www.fairssl.dk/en/guides/code-signing-digicert-usb-token/) ## Guides - [All technical guides](https://www.fairssl.dk/en/guides/): installation and ACME setup per platform - [simple-acme on Windows Server](https://www.fairssl.dk/en/guides/simple-acme-windows-guide/) - [IIS: several HTTPS websites on one IP address](https://www.fairssl.dk/en/guides/iis-multiple-websites-ssl/) - [RDP and RD Gateway SSL certificate](https://www.fairssl.dk/en/guides/rdp-rd-gateway-ssl-certificate/) - [Microsoft Exchange Server: SSL certificate via ACME](https://www.fairssl.dk/en/guides/exchange-ssl-acme/) - [FortiGate, FortiMail and FortiWeb via ACME](https://www.fairssl.dk/en/guides/fortigate-ssl-acme/) - [Citrix NetScaler / ADC via ACME](https://www.fairssl.dk/en/guides/netscaler-ssl-acme/) - [F5 BIG-IP with ACME](https://www.fairssl.dk/en/guides/f5-big-ip-ssl/) - [KEMP LoadMaster via ACME proxy](https://www.fairssl.dk/en/guides/kemp-loadmaster-ssl/) - [PRTG Network Monitor via ACME](https://www.fairssl.dk/en/guides/prtg-ssl-acme/) - [ACME validation: HTTP-01, DNS-01, TLS-ALPN-01](https://www.fairssl.dk/en/guides/acme-dns-validation-guide/) - [Cross-signed intermediate on Windows Server](https://www.fairssl.dk/en/guides/intermediate-cross-sign-windows/) - [KeyStore Explorer for Java keystores and PFX files](https://www.fairssl.dk/en/guides/keytool-explorer-java-certifikat/) - [Mozilla SSL Configuration Generator](https://www.fairssl.dk/en/guides/mozilla-ssl-configuration-generator/) - [IIS Crypto: TLS hardening of Windows Server](https://www.fairssl.dk/en/guides/iiscrypto-tls-konfiguration-windows/) ## Company - [About FairSSL](https://www.fairssl.dk/en/about/): independent, multi-CA, transparent pricing - [Contact](https://www.fairssl.dk/en/contact/): phone and email support in Danish, Swedish and English ## Localized sites - Danish: https://www.fairssl.dk/da/ - Swedish: https://www.fairssl.se/sv/ ## På svenska (fairssl.se) FairSSL har svensk support och svenska priser i SEK på fairssl.se. - [SSL-certifikat: typer och hur du väljer](https://www.fairssl.se/sv/ssl-certifikat/), från 250 SEK per år exkl. moms - [Alla produkter med priser](https://www.fairssl.se/sv/produkter/) - [SSL-automatisering (ACME)](https://www.fairssl.se/sv/ssl-automatisering/) - [Code Signing-certifikat](https://www.fairssl.se/sv/codesign-certifikat/) - [Tekniska guider](https://www.fairssl.se/sv/guider/) - [Kontakt](https://www.fairssl.se/sv/kontakt/): telefon och e-post på svenska