Auto-install

Issuing is easy. Installing on a server — that’s the pain

Seven ways, from “do nothing” to a self-checking instruction. The priority is ACME delegation via CNAME: our own NS turn this into our advantage.

A seven-rung ladder

  1. 00

    Rung 0. Nothing needed

    A domain used only for mail, a redirect or a parked one doesn’t need HTTPS on its own server. A good tool says there’s no work to do, first of all.

  2. 01

    Rung 1. ACME delegation via CNAMEPriority

    You get a delegation record once, we add it ourselves. Then your certbot, acme.sh, Caddy or Traefik issues and renews the certificate itself, wildcard included. We don’t hold your private key for a second.

    _acme-challenge.kava.com.ua CNAME k7f2.acme.zrazu.com
  3. 02

    Rung 2. Our certificate on our own proxy

    Terminating TLS on our side and proxying to your server is possible, but not a general service: only for redirect domains and our own placeholder pages.

  4. 03

    Rung 3. Control panels via API

    cPanel, Plesk, ISPmanager, HestiaCP: we install the certificate via their API. If your panel already has free AutoSSL, we say so directly.

  5. 04

    Rung 4. A CMS plugin

    WordPress first: the plugin doesn’t just install the certificate, it also fixes the aftermath — mixed content, the site URL, redirects, HSTS.

  6. 05

    Rung 5. A script for a VPS without a panel

    A small CLI and a system timer: fetch the certificate by token, put it in the right paths, reload the server, report back to us.

  7. 06

    Rung 6. Engine-specific instructions

    WordPress, OpenCart, Bitrix and others, with a “check” button that makes a real connection and names the specific defect.

  8. 07

    Rung 7. Cloudflare, separately

    Flexible mode causes an endless redirect loop. Our certificate is installed on the origin server, mode — Full (strict).

Common questions

Do you see my private key?

No, never: with ACME delegation via CNAME the key stays on your server the whole time.

What if none of the methods works?

An email with a single confirm button — a fallback path for any reissue.

Does this work with wildcard?

Yes, ACME delegation via CNAME solves wildcard, which is impossible via HTTP-01.

My site is behind Cloudflare — does that change anything?

Yes: make sure the mode is Full (strict), not Flexible, or you’ll get an endless redirect loop. The certificate still goes on your origin server.