acme.sh review
A free, scriptable ACME client for cross-platform certificate issuance and renewal.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
acme.sh is an open-source ACME protocol client written in Unix shell for issuing, renewing, installing, and deploying SSL/TLS certificates on self-managed systems. It supports Windows, macOS, Linux, and self-hosted environments, making it a fit for teams that prefer scriptable certificate operations across different platforms. The project is officially maintained by ZeroSSL while retaining the acme.sh name, and it remains available as an actively maintained GitHub project.
Its strongest area is workflow coverage. acme.sh supports webroot, standalone, Apache, Nginx, DNS API, and DNS manual validation modes, along with SAN and wildcard certificates. It supports both ECC and RSA certificates, certificate revocation, Docker, and integrations with ZeroSSL, Let's Encrypt, SSL.com, Google Public CA, Actalis, and DNS providers. A recurring cron job can handle unattended renewal, while installation and service reload hooks support copying certificates and reloading services after deployment. These capabilities make it suitable for operators who want certificate automation that can be incorporated into existing scripts and service-management routines.
The trade-off is its operational model. acme.sh is designed for self-managed systems rather than centralized certificate discovery or inventory, so it fits teams that already manage certificate locations, validation methods, deployment hooks, and renewal jobs. Buyers seeking a focused ACME client with broad validation and deployment options should consider it. Teams that need verified discovery across environments or a centralized inventory should choose a certificate management product built around those functions instead.
acme.sh pros and cons
- Where it wins
- Free open-source issuance, renewal, installation, and deployment workflows
- Supports DNS, webroot, standalone, Apache, and Nginx validation
- Works with SAN, wildcard, ECC, and RSA certificates across multiple CAs
- Where it doesn't
- Requires self-managed systems and shell-based configuration
- Does not provide verified certificate discovery
- Does not provide centralized certificate inventory
acme.sh fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.
Last updated · How we research and update