Let’s Encrypt
Free
Included by default. Issued and reissued automatically, wildcard included, when the domain uses our NS.
We reissue the certificate automatically — nothing for you to do.
If that is enough for you, take the free one — that is fine.
Empty for now. Find a name and it will show up here.
Ukrainian and global zones. “Available” only when the registry says so.
first subscription year
Same encryption as the free one.
First-year price; after that, standard rates apply. Prices exclude VAT.
SSL certificates
The rule is the same for every certificate authority. Nobody wants to swap a certificate by hand every few weeks. So that’s our job.
maximum lifetime of one certificate
Almost eight swaps a year, if you do it by hand.
Usually a certificate inside a subscription has to be reissued and installed by hand about every six months. With us it happens automatically, without you.
ACME delegation: we add one record to your zone once, and your server issues and reissues the certificate on its own. We never hold your private key and never ask for server access.
_acme-challenge.kava.com.uaCNAMEk7f2.acme.zrazu.comdoneWe add an _acme-challenge record to your zonecertbot·kava.com.ua,*.kava.com.uadoneYour certbot, Caddy or Traefik issues the certificate itself, wildcard includedrenew·autodoneReissued automatically before it expiresHonestly: most sites are fine with the free one.
Free
Included by default. Issued and reissued automatically, wildcard included, when the domain uses our NS.
We reissue the certificate automatically — nothing for you to do.
If that is enough for you, take the free one — that is fine.
first subscription year
We reissue the certificate automatically — nothing for you to do.
Same encryption as the free one.
Confirms the domain is yours.
When you don’t need it: if your free one works.
first subscription year
We reissue the certificate automatically — nothing for you to do.
The certificate contains your verified organisation name. Verification takes 3–5 business days.
O = Kava LLC, Kyiv, UAYour organisation details are already filled in from your profile and the state register. Each year you just confirm, nothing to re-enter.
When you don’t need it: if visitors don’t care to see the company name in the certificate.
first subscription year
We reissue the certificate automatically — nothing for you to do.
Extended organisation validation. Nothing changes visually in the browser.
Needed if a regulator or a counterparty requires it.
First subscription year price; after that, standard rates apply. We suggest wildcard or SAN when we see several subdomains. A Let’s Encrypt wildcard is free.
After you pay
ns1.zrazu.com · ns2.zrazu.comworkingZRAZUnow
kava.kyiv.ua: certificate reissued, valid until 26.12.2026. Nothing to do.
After payment the request goes to the registry. We describe the status in words: “the registry confirmed”, not just a green tick.
The zone is already set up, every record labelled in plain language. Nothing to type by hand.
We issue Let’s Encrypt automatically and reissue it before it expires.
Every 15 minutes we check the domain, DNS and certificate. If something is wrong, we write on Telegram or by email. No ads in that message.
Prices
The condition sits right next to it, same type size: first-year price; after that, standard rates apply. Two years cost less.
If the registry is silent, we say so: “couldn’t check”.
We never add anything to your cart for you or rush you.
The switch sits next to the prices — invoice from the LLC or the sole proprietor.