Certes 4.1.0

There is a newer prerelease version of this package available.
See the version list below for details.
dotnet add package Certes --version 4.1.0
                    
NuGet\Install-Package Certes -Version 4.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Certes" Version="4.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Certes" Version="4.1.0" />
                    
Directory.Packages.props
<PackageReference Include="Certes" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Certes --version 4.1.0
                    
#r "nuget: Certes, 4.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Certes@4.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Certes&version=4.1.0
                    
Install as a Cake Addin
#tool nuget:?package=Certes&version=4.1.0
                    
Install as a Cake Tool

Certes

Certes is an ACME client library for .NET. It creates accounts, places orders, completes HTTP-01, DNS-01 and TLS-ALPN-01 challenges, and exports issued certificates as PEM or PFX.

Supported targets: net10.0, net8.0 and netstandard2.0.

New in 4.1

  • ACME Renewal Information (ARI, RFC 9773): retrieve suggested renewal windows and create replacement orders.
  • Discover certificate profiles and select a profile when creating an order.
  • Order certificates for IPv4 and IPv6 addresses (RFC 8738), with IP subject alternative names in CSRs and TLS-ALPN validation certificates.

These features require support from the ACME server. See the API guide for usage and challenge requirements.

Getting started

var acme = new AcmeContext(WellKnownServers.LetsEncryptStagingV2);
var account = await acme.NewAccount("admin@example.com", true);
var order = await acme.NewOrder(new[] { "example.com" });

Test against a staging CA before using a production CA.

Documentation

The dotnet-certes package provides a command-line tool built on this library.

Licensed under the MIT license.

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (37)

Showing the top 5 NuGet packages that depend on Certes:

Package Downloads
LettuceEncrypt

Provides API for configuring ASP.NET Core to automatically generate HTTPS certificates. This configures your server to use the ACME protocol to connect with a certificate authority (CA), such as Let's Encrypt (https://letsencrypt.org), to verify ownership of your domain name and generate a HTTPS certificate. This happens automatically when the server starts up, and will renew the certificate automatically when the expiration date is near. This only works with Kestrel, which is the default server configuration for ASP.NET Core projects. Other servers, such as IIS and nginx, are not supported.

uwap.WebFramework

Cross-platform .NET library written in C# that allows you to create a web server for dynamic and/or static websites and web apps with ease.

FluffySpoon.AspNet.LetsEncrypt

Package Description

LagoVista.Net.LetsEncrypt

Provides Middleware and services to request and store certificates from the Let's Encrypt service for ASP.NET Core applications

DH.LettuceEncrypt

用于DH框架的Let's Encrypt生成库。参考https://github.com/natemcmaster/LettuceEncrypt

GitHub repositories (11)

Showing the top 11 popular GitHub repositories that depend on Certes:

Repository Stars
natemcmaster/LettuceEncrypt
Free, automatic HTTPS certificate generation for ASP.NET Core web apps
sjkp/letsencrypt-siteextension
Azure Web App Site Extension for easy installation and configuration of Let's Encrypt issued SSL certifcates for custom domain names.
junkai-li/NetCoreKevin
🤖基于.NET搭建的企业级中台AI知识库智能体开源架构:AISkills技能管理、AI语音电话模式、智能体记忆、AI-Qdrant知识库、知识库重排模型、AI联网搜索、多智能体协同、聊天记录压缩策略、智能体权限管控、AgentFramework、RAG检索增强、本地Ollama AI模型调用、智能体技能可控加载、领域事件、一库多租户、Log4、Jwt、CAP、SignalR、Mcp、Hangfire、RabbitMQ、前端(Vue + Ant Design)
Maarten88/rrod
Exploring a new web architecture with React, Redux, Orleans and Dotnet Core
ffMathy/FluffySpoon.AspNet.EncryptWeMust
ark-mod/ArkBot
ARK Survival Evolved application that monitors and extracts data from local ARK servers and exposes this data through a Web App, Web API and Discord Bot. Provides important functions to players: dino listings, food-status, breeding info, statistics; and server admins: rcon-commands, server managing etc.
kl3mta3/SphereSSL
Web-powered SSL certificate manager with DNS integration, auto-renewals, and cert tracking. It's like if Certbot and ZeroSSL had a baby. Certbot but more friendly, smarter, and with a dashboard.
NethermindEth/dotnet-libp2p
A libp2p implementation for .NET in C#.
aloopkin/WinCertes
An ACMEv2 client for Windows
sjkp/letsencrypt-azure
The easiest way to use lets encrypt certificates on Azure
stratdev3/SimpleW
Lightweight Web Server for .NET. Simple by design. Standalone or embedded.
Version Downloads Last Updated
5.0.0-beta.1 49 9/29/2026
4.1.0 1,041 9/27/2026
4.0.0 818 9/23/2026
4.0.0-beta.1 59 9/23/2026
3.0.4 1,361,878 1/4/2023
3.0.3 338,284 10/4/2021
3.0.0 191,207 7/18/2021
2.3.4 703,466 3/27/2020
2.3.3 406,689 12/17/2018
2.3.2 86,604 10/20/2018
2.3.1 12,698 10/16/2018
2.3.0 31,933 6/15/2018
2.2.2 13,540 5/31/2018
2.2.1 13,611 5/15/2018
2.2.0 14,338 5/5/2018
Loading failed

### Added
- IP address identifiers (RFC 8738): `IdentifierType.Ip`, and `NewOrder`,
 `NewOrderWithProfile` and `NewReplacementOrder` overloads accepting typed
 `Identifier` lists. IP values are validated and sent in canonical form.
- Certificate profile discovery through `DirectoryMeta.Profiles`, selection via
 `NewOrderWithProfile`, and the selected `Order.Profile`
 ([#330](https://github.com/fszlin/certes/issues/330)). Profile orders can also
 include an ARI replacement certificate ID.
- ACME Renewal Information (ARI, RFC 9773): `Directory.RenewalInfo`,
 `GetRenewalInfoCertificateId()` for `CertificateChain` and `IEncodable`,
 `GetRenewalInfo()` (suggested window, explanation URL and `Retry-After`) and
 `NewReplacementOrder()` extension methods on `IAcmeContext`, and `Order.Replaces`.
 Based on the proposal in [#329](https://github.com/fszlin/certes/issues/329)
 by @WhitWaldo.
- CLI: `order new --profile` and `--replaces`, `cert renewal-info <cert-path>`,
 and the `tls-alpn` challenge type for `order authz`/`order validate` (with
 `dns-01`, `http-01` and `tls-alpn-01` aliases). IP addresses passed to
 `order new` are ordered as IP identifiers.

### Changed
- `NewOrder`, `NewOrderWithProfile` and `NewReplacementOrder` string overloads
 now send values that strictly parse as IP addresses as `ip` identifiers in
 canonical form, instead of `dns`. CAs reject IP addresses as DNS identifiers, so
 previously such orders always failed.
- `IOrderContext.Authorization(value, IdentifierType.Ip)` compares IP identifiers
 by address rather than by text.
- `CertificationRequestBuilder` encodes subject alternative names that are IP
 addresses as IP SANs instead of DNS names, and `TlsAlpnCertificate` does the same
 for its subject name.
- When `CsrInfo.CommonName` is not set, `Finalize`/`Generate` use the first DNS
 name of at most 64 characters as the common name, instead of always the first
 identifier. IP-only orders produce a CSR without a common name.

### Fixed
- CLI: `cert pfx --help` described the command as exporting PEM.

Full changelog: https://github.com/fszlin/certes/blob/v4.1.0/docs/CHANGELOG.md