SSL Automation
Automate SSL/TLS certificates with ACME
FairSSL's ACME service gives IT professionals, consultants and hosting providers a fast way to automate SSL/TLS certificate management. It is secure, flexible and free from the limitations of free certificate authorities.
Built on ACME v2 (RFC 8555) with ACME Renewal Information (ARI, RFC 9773) support. Our platform automates certificate lifecycle management, including early renewal, CA switching and monitoring of both certificate and client status.
Shorter SSL lifetimes adopted
The CA/Browser Forum has adopted a phased reduction: 200 days (15 March 2026), 100 days (15 March 2027), 47 days (15 March 2029). Without automation, it becomes an administrative nightmare. Learn more →
The price is fixed, reissues are included
The automation fee is €33 per certificate per year and is added on top of the certificate price. One fee covers up to 25 servers, and the price stays the same no matter how often the certificate is reissued. See pricing →
Key benefits of FairSSL ACME
Free choice of CA and product
DigiCert (OV), GlobalSign (OV/EV), Thawte (DV, OV), GeoTrust (DV, OV), RapidSSL (DV). Supports single-domain, wildcard and SAN certificates.
Automated domain validation
Use AutoDNS without exposing DNS API keys, ideal for internal networks and secure environments.
Centralised administration
Create profiles with product-specific settings, monitor certificate expiry and client status, switch products without changing server configuration.
Security controls
Block or allow wildcard issuance and SAN name changes per profile and per ACME client. Lock down ACME clients after setup.
High limits
No limits on the number of paid certificates, up to 1,000 duplicates and 250 SANs. Perfect for disaster recovery and scaling.
ARI: smart renewal
ACME Renewal Information (ARI, RFC 9773) checks daily whether certificates should be renewed early and lets us monitor that each server's ACME client is active and healthy.
Transparent pricing
ACME service fee covers up to 25 servers using the certificate. Usage beyond 25 servers adds another €33.
- SAN changes and reissues are exempt from the fee
- Additional ACME clients using the same certificate: free
- Standard certificate prices apply on top
Certificate Reuse: One Certificate, Many Servers
Do you have the same domain running on multiple servers, e.g., behind a load balancer, in a cluster, or with staging/production environments? You don't need to buy a certificate per server.
With FairSSL ACME, the certificate is managed centrally. When renewed, your ACME client automatically distributes it to all servers using it. You pay for the certificate, not the number of installations.
| Scenario | Competitors | FairSSL |
|---|---|---|
| 1 SAN certificate (www, api, mail), 5 servers | 5 licenses | 1 certificate |
| 1 SAN certificate, 20 servers behind a load balancer | 20 licenses | 1 certificate |
| 1 wildcard, 100 servers | 100 licenses | 1 certificate |
We sell certificates, not licenses per server. One certificate covers all servers it is installed on. With FairSSL ACME, the automation fee covers up to 25 servers per certificate; server 26 triggers another fee.
Worked example: 30 servers, 10 certificates
A company with 30 servers spread across 10 certificates pays for 10 certificates plus 10 ACME fees, roughly €790 per year in total. There are no per-server licenses, and the price does not rise when certificates must be renewed more often.
Security without DNS keys on your servers
Many automation tools require a DNS API key on every server to issue certificates. If that key leaks, an attacker can change your DNS. With FairSSL AutoDNS the validation stays with us: your servers need neither DNS keys nor open ports.
We recommend certificates with named hosts (SAN) over wildcards, and you can enforce it: lock each ACME client to specific names and block wildcard issuance per profile.
Built for engineers
"Set and forget" validation
Forget opening firewalls or handling temporary tokens. We use permanent DNS CNAME validation.
- Your servers need no inbound internet access
- Set the CNAME once, we handle validation automatically forever
Intelligent certificate reuse
Why pay for new certificates when you have 10 servers behind a load balancer?
- The system reuses existing certificates across your infrastructure
- Additional ACME clients using the same certificate are included in the ACME fee
No salespeople: just engineers
You are not talking to sales. You are talking to the developers who built the system.
- No sales meetings, no "contact us for pricing", no upfront payments
- Step-by-step guides for Windows (IIS), Linux and Kubernetes
Popular ACME Clients
Any ACME client that follows RFC 8555 and supports EAB works with FairSSL. Here are the clients we have tested and can help with.
Windows
IIS, Exchange, RDP, SQL Server, ADFS
simple-acme, Certify The Web, Posh-ACMELinux
Apache, Nginx, HAProxy, Docker, Kubernetes
Lego, Certbot, acme.sh, CaddyNetwork Appliances
F5, Palo Alto, NetScaler, Fortinet, pfSense
FortiGate, NetScaler, F5, KEMP, KubernetesCloud
Azure, AWS, Kubernetes cert-manager
Key Vault Acmebot, cert-managerOur recommendation: simple-acme for Windows, Lego for Linux and CI/CD. FairSSL sponsors both projects. They have the best integration with the FairSSL ACME server and support ARI for intelligent renewal and monitoring.
Comparison with free ACME services
See the difference between FairSSL ACME, Let’s Encrypt and ZeroSSL.
Scroll right to see more providers
| Feature | FairSSL | Let's Encrypt |
|---|---|---|
| Certificate types | DV, OV, EV (GlobalSign, pre-validated) | DV |
| Certificate validity | 1–199 days | 90 days (6 days announced) |
| Supports multiple CAs | ✓ | ✗ |
| ACME client monitoring | ✓ | ✗ |
| Expiry alerts & reports | Email lists, daily/weekly/monthly | ✗ |
| Certificates per domain | No limit | 50 per week |
| Duplicate certificates | 1,000 | 5 per week |
| Names per certificate (SANs) | 250 | 100 |
| Wildcards allowed | ✓ | ✓ (requires DNS API key) |
| DNS validation | AutoDNS — set and forget | Requires DNS API key on client |
| Centralised management | ✓ | ✗ |
| Per-profile wildcard control | ✓ | ✗ |
| Per-client SAN locking | ✓ | ✗ |
| Order period | 1–3 years | No order, 90 days at a time |
| Installation guides | ✓ Step-by-step | Community documentation |
| Debug event log | ✓ Full traceability | ✗ |
| Support | Phone & email | Community forum |
ACME server details
- ACME directory URL
- https://fairssl.dk/acme
- Protocol
- ACME v2 (RFC 8555), ARI (RFC 9773)
- Account binding
- EAB (preferred) or a custom URL for appliances without EAB
- Certificate types
- DV, OV, EV (GlobalSign, pre-validated)
- Certificate authorities
- DigiCert family (RapidSSL, Thawte, GeoTrust, DigiCert) and GlobalSign
- Automation fee
- €33 per certificate/year, on top of the certificate price (250 DKK for invoicing in Danish kroner, 370 SEK in Swedish kronor)
- Servers per fee
- Up to 25 (server 26 triggers another fee)
- DNS validation
- AutoDNS: no DNS keys, no open ports
Get started in 10 minutes
# Install certbot (Ubuntu/Debian)
sudo apt install certbot
# Request certificate with FairSSL ACME server
certbot certonly \
--agree-tos \
--email admin@yourcompany.com \
--preferred-challenges http \
--server https://fairssl.dk/acme \
-d www.yourcompany.com Certbot sets up automatic renewal. Nothing more to do.
ACME-compatible certificates
These DV certificates support automatic ACME issuance and renewal:
RapidSSL
Standard DV. Issued in minutes.
Thawte SSL123 SAN DV
DV multi-domain. Supports SAN names and wildcards in combination.
Thawte SSL123 Wildcard
DV wildcard. Can also add individual SAN names.
Frequently asked questions about ACME automation
Find answers to the most common questions about SSL certificates and FairSSL.
Ready to create a free account?
Create a free account and issue your first certificate in under 10 minutes.