Auto-install
Issuing is easy. Installing on a server — that’s the pain
Seven ways, from “do nothing” to a self-checking instruction. The priority is ACME delegation via CNAME: our own NS turn this into our advantage.
A seven-rung ladder
- 00
Rung 0. Nothing needed
A domain used only for mail, a redirect or a parked one doesn’t need HTTPS on its own server. A good tool says there’s no work to do, first of all.
- 01
Rung 1. ACME delegation via CNAMEPriority
You get a delegation record once, we add it ourselves. Then your certbot, acme.sh, Caddy or Traefik issues and renews the certificate itself, wildcard included. We don’t hold your private key for a second.
_acme-challenge.kava.com.ua CNAME k7f2.acme.zrazu.com - 02
Rung 2. Our certificate on our own proxy
Terminating TLS on our side and proxying to your server is possible, but not a general service: only for redirect domains and our own placeholder pages.
- 03
Rung 3. Control panels via API
cPanel, Plesk, ISPmanager, HestiaCP: we install the certificate via their API. If your panel already has free AutoSSL, we say so directly.
- 04
Rung 4. A CMS plugin
WordPress first: the plugin doesn’t just install the certificate, it also fixes the aftermath — mixed content, the site URL, redirects, HSTS.
- 05
Rung 5. A script for a VPS without a panel
A small CLI and a system timer: fetch the certificate by token, put it in the right paths, reload the server, report back to us.
- 06
Rung 6. Engine-specific instructions
WordPress, OpenCart, Bitrix and others, with a “check” button that makes a real connection and names the specific defect.
- 07
Rung 7. Cloudflare, separately
Flexible mode causes an endless redirect loop. Our certificate is installed on the origin server, mode — Full (strict).
Common questions
Do you see my private key?
No, never: with ACME delegation via CNAME the key stays on your server the whole time.
What if none of the methods works?
An email with a single confirm button — a fallback path for any reissue.
Does this work with wildcard?
Yes, ACME delegation via CNAME solves wildcard, which is impossible via HTTP-01.
My site is behind Cloudflare — does that change anything?
Yes: make sure the mode is Full (strict), not Flexible, or you’ll get an endless redirect loop. The certificate still goes on your origin server.