Why need SSL Automation now?

Major web browsers and industry standards are drastically reducing SSL certificate validity periods to enhance security and mitigate potential vulnerabilities. With certificate lifespans getting shorter, manual management has become a significant operational burden, drastically increasing the risks of unexpected expirations, human errors, and costly website downtime.

  • March 15, 2026: Maximum validity reduced to 200 days
  • March 15, 2027: Maximum validity reduced to 100 days
  • March 15, 2029: Maximum validity reduced to 47 days

What is ACME?

ACME (Automated Certificate Management Environment) is an open protocol that empowers servers to request and manage SSL/TLS certificates directly from a Certificate Authority (CA). It fully automates the entire lifecycle - including Domain Validation (DV), Organization Validation (OV), issuance, renewal, installation, and revocation - completely removing the need for human intervention.

With ACME, your server handles the certificate workflow natively. There is no need to manually generate CSRs, upload validation files, or keep track of expiration dates. Instead, the server communicates with the CA over HTTPS using signed JSON requests. To prove domain ownership, the server automatically responds to a challenge (typically via HTTP or DNS). Once verified, the certificate is issued and deployed instantly.

Today, ACME is recognized as an official internet standard under RFC 8555 and is supported by major Certificate Authorities. Its latest iteration, ACME v2, introduced support for wildcard domains, enhanced domain validation, and tighter security checks. This makes ACME SSL certificates the ideal choice for teams running uptime-critical applications, managing multi-server environments, or automating deployments at scale.

Supported ACME Clients

  • Certbot
  • cert-manager
  • acme.sh
  • lego
  • Certify
  • win-acme
  • dehydrated
  • Posh-ACME

Two of the three options below - Sectigo ACME and DigiCert ACME - use this standard ACME protocol with your own ACME client (e.g. Certbot, acme.sh). Nethub Automation Agent uses a different mechanism - a lightweight agent Nethub built and operates on your behalf - see the comparison below for differences of three options.

SSL Automation Solution Comparison

  • Additional Cost
  • Automation Connection
  • Credential Update upon Renewal
  • Protocol / Standard
  • Environment Fit
  • Platform
  • OV Pre-validation
  • Technical Support
  • Subscription Service Period
  • SSL Product Type
  • DV SSL Certificate
  • OV SSL Certificate
  • EV SSL Certificate
  • Multiple Years
  • Nethub Automation Agent

  • Additional Cost
    No additional cost
  • Automation Connection
    Connect to Nethub server
  • Credential Update upon Renewal
    Required
  • Protocol / Standard
    Python agent (not ACME)
  • Environment Fit
    Need root/admin rights
  • Platform
    Linux & Windows
  • OV Pre-validation
    OV will be performed after order
  • Technical Support
    Supported by Nethub
  • Subscription Service Period
    Start with certificate issue date of new order
  • SSL Product Type
  • DV SSL Certificate
  • OV SSL Certificate
  • EV SSL Certificate
  • Multiple Years
  • Sectigo ACME

  • Additional Cost
    Higher cost
  • Automation Connection
    Connect to CA server
  • Credential Update upon Renewal
    Not required (Renew at least 24 hours before service expiry)
  • Protocol / Standard
    Standard ACME
  • Environment Fit
    Work with standard ACME clients / environments
  • Platform
    Linux & Windows
  • OV Pre-validation
    OV must be pre-validated before order
  • Technical Support
    ACME client managed by end-user
  • Subscription Service Period
    Start with ACME EAB provided
  • SSL Product Type
  • DV SSL Certificate
  • OV SSL Certificate
  • EV SSL Certificate
  • Multiple Years
  • DigiCert ACME

  • Additional Cost
    Higher cost
  • Automation Connection
    Connect to CA server
  • Credential Update upon Renewal
    Not required (Renew before service expiry)
  • Protocol / Standard
    Standard ACME
  • Environment Fit
    Work with standard ACME clients / environments
  • Platform
    Linux & Windows
  • OV Pre-validation
    OV must be pre-validated before order
  • Technical Support
    ACME client managed by end-user
  • Subscription Service Period
    Start with ACME EAB provided
  • SSL Product Type
  • DV SSL Certificate
  • OV SSL Certificate
  • EV SSL Certificate
  • Multiple Years

Which one should I choose?

Nethub Automation Agent

A lightweight agent Nethub built, installed on your own Linux or Windows server (needs SSH/admin access once, at setup). It fully automates the entire lifecycle through Nethub, and DV/OV/EV are all supported. Best if you want Nethub to manage the certificate lifecycle end-to-end and would rather not run a separate ACME client yourself.

# When you submit online order, please select "Nethub Automation Agent" in Automation options.

Sectigo ACME

Standard ACME v2 via Sectigo - run your own ACME client (Certbot, acme.sh, etc.) and it renews automatically with no ACME EAB credential updates needed, as long as payment is settled at least 24 hours before each renewal. Supports DV and OV SSL Certificates. Best for teams already comfortable running a standard ACME client across one or more servers.

Sectigo ACME pricing & details → · ACME client installation guides →

DigiCert ACME

Standard ACME v2 direct via DigiCert - same idea as Sectigo ACME, run your own ACME client and it renews automatically using the same EAB credential, as long as you renew before service expiry. Supports DV, OV, EV, and multi-year terms. Best for teams that need EV or a multi-year term alongside ACME automation.

# When you submit online order, please select "DigiCert ACME Automation" in Automation options.

ACME client installation guides →

For details, please contact our customer representative at (852) 26222130