SSL certificate
Let’s Encrypt — free and on by default
Turns on by itself for every domain on our NS. The encryption is the same as any paid certificate.
What’s included
- Automatic issue and reissue — no emails, no reminders
- Free wildcard via DNS-01, when the domain is on our NS
- The same encryption as paid certificates
- Works on any server that supports ACME
Why Let’s Encrypt specifically
Our ACME driver doesn’t depend on a single provider: Let’s Encrypt is the main one, ZeroSSL or Google Trust Services is the backup, both free. If something happens to one CA, we switch with a config change, not a product rewrite.
When it’s worth looking at a paid one
If a counterparty, bank or tender requires a “purchased certificate” or a verified organisation, if you have an old system without ACME support, or if you have several different domains under one certificate.
Common questions
What do I need to do to turn it on?
Nothing, if the domain is on our NS: the certificate is issued automatically right after the domain is connected.
What if I have several subdomains?
A wildcard certificate for all subdomains at once is also free and automatic when the domain is on our NS.
Domain on other NS — does this work?
Yes, via ACME CNAME delegation: you add a record once, then your certbot or another client issues and renews the certificate itself.
What happens if Let’s Encrypt shuts down?
We have a backup free certificate authority configured: the switch happens via config, without you doing anything.
Want to make sure the certificate is already working? Check the certificate