Certes 4.1.0
See the version list below for details.
dotnet add package Certes --version 4.1.0
NuGet\Install-Package Certes -Version 4.1.0
<PackageReference Include="Certes" Version="4.1.0" />
<PackageVersion Include="Certes" Version="4.1.0" />
<PackageReference Include="Certes" />
paket add Certes --version 4.1.0
#r "nuget: Certes, 4.1.0"
#:package Certes@4.1.0
#addin nuget:?package=Certes&version=4.1.0
#tool nuget:?package=Certes&version=4.1.0
Certes
Certes is an ACME client library for .NET. It creates accounts, places orders, completes HTTP-01, DNS-01 and TLS-ALPN-01 challenges, and exports issued certificates as PEM or PFX.
Supported targets: net10.0, net8.0 and netstandard2.0.
New in 4.1
- ACME Renewal Information (ARI, RFC 9773): retrieve suggested renewal windows and create replacement orders.
- Discover certificate profiles and select a profile when creating an order.
- Order certificates for IPv4 and IPv6 addresses (RFC 8738), with IP subject alternative names in CSRs and TLS-ALPN validation certificates.
These features require support from the ACME server. See the API guide for usage and challenge requirements.
Getting started
var acme = new AcmeContext(WellKnownServers.LetsEncryptStagingV2);
var account = await acme.NewAccount("admin@example.com", true);
var order = await acme.NewOrder(new[] { "example.com" });
Test against a staging CA before using a production CA.
Documentation
The dotnet-certes package provides a command-line tool built on this library.
Licensed under the MIT license.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net461 was computed. net462 was computed. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.0
- BouncyCastle.Cryptography (>= 2.7.0)
- System.Text.Json (>= 9.0.1)
-
net10.0
- BouncyCastle.Cryptography (>= 2.7.0)
-
net8.0
- BouncyCastle.Cryptography (>= 2.7.0)
NuGet packages (37)
Showing the top 5 NuGet packages that depend on Certes:
| Package | Downloads |
|---|---|
|
LettuceEncrypt
Provides API for configuring ASP.NET Core to automatically generate HTTPS certificates. This configures your server to use the ACME protocol to connect with a certificate authority (CA), such as Let's Encrypt (https://letsencrypt.org), to verify ownership of your domain name and generate a HTTPS certificate. This happens automatically when the server starts up, and will renew the certificate automatically when the expiration date is near. This only works with Kestrel, which is the default server configuration for ASP.NET Core projects. Other servers, such as IIS and nginx, are not supported. |
|
|
uwap.WebFramework
Cross-platform .NET library written in C# that allows you to create a web server for dynamic and/or static websites and web apps with ease. |
|
|
FluffySpoon.AspNet.LetsEncrypt
Package Description |
|
|
LagoVista.Net.LetsEncrypt
Provides Middleware and services to request and store certificates from the Let's Encrypt service for ASP.NET Core applications |
|
|
DH.LettuceEncrypt
用于DH框架的Let's Encrypt生成库。参考https://github.com/natemcmaster/LettuceEncrypt |
GitHub repositories (11)
Showing the top 11 popular GitHub repositories that depend on Certes:
| Repository | Stars |
|---|---|
|
natemcmaster/LettuceEncrypt
Free, automatic HTTPS certificate generation for ASP.NET Core web apps
|
|
|
sjkp/letsencrypt-siteextension
Azure Web App Site Extension for easy installation and configuration of Let's Encrypt issued SSL certifcates for custom domain names.
|
|
|
junkai-li/NetCoreKevin
🤖基于.NET搭建的企业级中台AI知识库智能体开源架构:AISkills技能管理、AI语音电话模式、智能体记忆、AI-Qdrant知识库、知识库重排模型、AI联网搜索、多智能体协同、聊天记录压缩策略、智能体权限管控、AgentFramework、RAG检索增强、本地Ollama AI模型调用、智能体技能可控加载、领域事件、一库多租户、Log4、Jwt、CAP、SignalR、Mcp、Hangfire、RabbitMQ、前端(Vue + Ant Design)
|
|
|
Maarten88/rrod
Exploring a new web architecture with React, Redux, Orleans and Dotnet Core
|
|
|
ffMathy/FluffySpoon.AspNet.EncryptWeMust
|
|
|
ark-mod/ArkBot
ARK Survival Evolved application that monitors and extracts data from local ARK servers and exposes this data through a Web App, Web API and Discord Bot. Provides important functions to players: dino listings, food-status, breeding info, statistics; and server admins: rcon-commands, server managing etc.
|
|
|
kl3mta3/SphereSSL
Web-powered SSL certificate manager with DNS integration, auto-renewals, and cert tracking. It's like if Certbot and ZeroSSL had a baby. Certbot but more friendly, smarter, and with a dashboard.
|
|
|
NethermindEth/dotnet-libp2p
A libp2p implementation for .NET in C#.
|
|
|
aloopkin/WinCertes
An ACMEv2 client for Windows
|
|
|
sjkp/letsencrypt-azure
The easiest way to use lets encrypt certificates on Azure
|
|
|
stratdev3/SimpleW
Lightweight Web Server for .NET. Simple by design. Standalone or embedded.
|
| Version | Downloads | Last Updated |
|---|---|---|
| 5.0.0-beta.1 | 49 | 9/29/2026 |
| 4.1.0 | 1,041 | 9/27/2026 |
| 4.0.0 | 818 | 9/23/2026 |
| 4.0.0-beta.1 | 59 | 9/23/2026 |
| 3.0.4 | 1,361,878 | 1/4/2023 |
| 3.0.3 | 338,284 | 10/4/2021 |
| 3.0.0 | 191,207 | 7/18/2021 |
| 2.3.4 | 703,466 | 3/27/2020 |
| 2.3.3 | 406,689 | 12/17/2018 |
| 2.3.2 | 86,604 | 10/20/2018 |
| 2.3.1 | 12,698 | 10/16/2018 |
| 2.3.0 | 31,933 | 6/15/2018 |
| 2.2.2 | 13,540 | 5/31/2018 |
| 2.2.1 | 13,611 | 5/15/2018 |
| 2.2.0 | 14,338 | 5/5/2018 |
### Added
- IP address identifiers (RFC 8738): `IdentifierType.Ip`, and `NewOrder`,
`NewOrderWithProfile` and `NewReplacementOrder` overloads accepting typed
`Identifier` lists. IP values are validated and sent in canonical form.
- Certificate profile discovery through `DirectoryMeta.Profiles`, selection via
`NewOrderWithProfile`, and the selected `Order.Profile`
([#330](https://github.com/fszlin/certes/issues/330)). Profile orders can also
include an ARI replacement certificate ID.
- ACME Renewal Information (ARI, RFC 9773): `Directory.RenewalInfo`,
`GetRenewalInfoCertificateId()` for `CertificateChain` and `IEncodable`,
`GetRenewalInfo()` (suggested window, explanation URL and `Retry-After`) and
`NewReplacementOrder()` extension methods on `IAcmeContext`, and `Order.Replaces`.
Based on the proposal in [#329](https://github.com/fszlin/certes/issues/329)
by @WhitWaldo.
- CLI: `order new --profile` and `--replaces`, `cert renewal-info <cert-path>`,
and the `tls-alpn` challenge type for `order authz`/`order validate` (with
`dns-01`, `http-01` and `tls-alpn-01` aliases). IP addresses passed to
`order new` are ordered as IP identifiers.
### Changed
- `NewOrder`, `NewOrderWithProfile` and `NewReplacementOrder` string overloads
now send values that strictly parse as IP addresses as `ip` identifiers in
canonical form, instead of `dns`. CAs reject IP addresses as DNS identifiers, so
previously such orders always failed.
- `IOrderContext.Authorization(value, IdentifierType.Ip)` compares IP identifiers
by address rather than by text.
- `CertificationRequestBuilder` encodes subject alternative names that are IP
addresses as IP SANs instead of DNS names, and `TlsAlpnCertificate` does the same
for its subject name.
- When `CsrInfo.CommonName` is not set, `Finalize`/`Generate` use the first DNS
name of at most 64 characters as the common name, instead of always the first
identifier. IP-only orders produce a CSR without a common name.
### Fixed
- CLI: `cert pfx --help` described the command as exporting PEM.
Full changelog: https://github.com/fszlin/certes/blob/v4.1.0/docs/CHANGELOG.md