SSL certificate

Let’s Encrypt — free and on by default

Turns on by itself for every domain on our NS. The encryption is the same as any paid certificate.

What’s included

  • Automatic issue and reissue — no emails, no reminders
  • Free wildcard via DNS-01, when the domain is on our NS
  • The same encryption as paid certificates
  • Works on any server that supports ACME

Why Let’s Encrypt specifically

Our ACME driver doesn’t depend on a single provider: Let’s Encrypt is the main one, ZeroSSL or Google Trust Services is the backup, both free. If something happens to one CA, we switch with a config change, not a product rewrite.

When it’s worth looking at a paid one

If a counterparty, bank or tender requires a “purchased certificate” or a verified organisation, if you have an old system without ACME support, or if you have several different domains under one certificate.

Common questions

What do I need to do to turn it on?

Nothing, if the domain is on our NS: the certificate is issued automatically right after the domain is connected.

What if I have several subdomains?

A wildcard certificate for all subdomains at once is also free and automatic when the domain is on our NS.

Domain on other NS — does this work?

Yes, via ACME CNAME delegation: you add a record once, then your certbot or another client issues and renews the certificate itself.

What happens if Let’s Encrypt shuts down?

We have a backup free certificate authority configured: the switch happens via config, without you doing anything.

Want to make sure the certificate is already working? Check the certificate