Certificate Manager
Free TLS Certificates for Your Endpoints, Renewed for You
Free TLS certificates from Let's Encrypt for your endpoints: DNS or HTTP validation, wildcard names, automatic renewal, imported certificates, expiry warnings and notifications.
Certificate Manager
Scope & Capabilities
Free public TLS certificates from Let's Encrypt, validated by DNS or HTTP and renewed automatically, or imported; expiry warnings; used by Object Storage endpoints on your own domain.
- Free public TLS certificates from Let's Encrypt for your project's endpoints, today Object Storage endpoints on your own domain
- Each organization orders with an ACME account of its own
- DNS validation: add one CNAME record per name, once, and keep it; wildcard names supported
- HTTP validation: answered automatically by your Object Storage gateways on port 80
- Renewed automatically 30 days before expiry with nothing to do, while the current certificate keeps serving
- Import certificates issued elsewhere (RSA 2048 bits or more, ECDSA P-256 or P-384, Ed25519) and replace them with their renewals
- Expiry warnings 30, 14, 7 and 1 days before a certificate ends
- Events for issued, renewed, failed, expiring and expired certificates, with notifications to email, Slack, Microsoft Teams or webhooks
- Private keys stored encrypted, never returned by the API, and sent only to your own endpoints that serve them; export gives the certificate and chain
- In-use protection: a certificate an endpoint uses cannot be deleted
- Certificate Manager is free
See Certificate Manager on your own cloud
Book a walkthrough with our team to see it working against your own environment.