Skip to main content
Certificate Manager

Free TLS Certificates for Your Endpoints, Renewed for You

Free TLS certificates from Let's Encrypt for your endpoints: DNS or HTTP validation, wildcard names, automatic renewal, imported certificates, expiry warnings and notifications.

All Platform Services
Certificate Manager

Scope & Capabilities

Free public TLS certificates from Let's Encrypt, validated by DNS or HTTP and renewed automatically, or imported; expiry warnings; used by Object Storage endpoints on your own domain.

  • Free public TLS certificates from Let's Encrypt for your project's endpoints, today Object Storage endpoints on your own domain
  • Each organization orders with an ACME account of its own
  • DNS validation: add one CNAME record per name, once, and keep it; wildcard names supported
  • HTTP validation: answered automatically by your Object Storage gateways on port 80
  • Renewed automatically 30 days before expiry with nothing to do, while the current certificate keeps serving
  • Import certificates issued elsewhere (RSA 2048 bits or more, ECDSA P-256 or P-384, Ed25519) and replace them with their renewals
  • Expiry warnings 30, 14, 7 and 1 days before a certificate ends
  • Events for issued, renewed, failed, expiring and expired certificates, with notifications to email, Slack, Microsoft Teams or webhooks
  • Private keys stored encrypted, never returned by the API, and sent only to your own endpoints that serve them; export gives the certificate and chain
  • In-use protection: a certificate an endpoint uses cannot be deleted
  • Certificate Manager is free

See Certificate Manager on your own cloud

Book a walkthrough with our team to see it working against your own environment.

Pricing Details

Syntoric Platform Services Tour

Explore how Syntoric secures, optimizes, and automates enterprise cloud operations

Continuous Multi-Cloud Security (CSPM)

Automated risk detection without stored credentials
Syntoric continuously audits your AWS and Azure environments for security misconfigurations, open perimeters, and regulatory non-compliance. Our agentless scanning model assumes customer IAM roles using short-lived tokens - ensuring zero static credentials ever touch our platform.
Step 1 of 3
Turnkey Enterprise Integration