ACME Command Generator - Certbot, acme.sh & More

ACME Command Generator

Copy-paste Let's Encrypt issuance commands for the four most common ACME clients.

Enter your email and domains to generate a command.
HTTP-01 requires port 80 reachable and the webroot path to exist. Run our ACME preflight first to avoid failed attempts.

About ACME Command Generator

The CSR.plus ACME Command Generator removes the guesswork from Let's Encrypt setup. Pick your ACME client (Certbot, acme.sh, lego or win-acme), your validation method (HTTP-01 or DNS-01), your DNS provider, add your domains, and get a complete, copy-paste-ready command line.

It covers the four most common clients, including DNS-01 credentials hints and the pitfalls that typically waste people's first attempts (webroot paths, credentials file permissions, account email).

Why use

  • Four clients: Certbot, acme.sh, lego and win-acme
  • HTTP-01 and DNS-01 modes with five DNS providers
  • Multiple domains supported (-d / --domains chains)
  • Best-practice flags pre-applied (--agree-tos, --no-eff-email, ...)

How to use

  1. Enter your account email (used by ACME for expiry notices).
  2. List your domains, one or several (space-separated).
  3. Choose client, validation method and (for DNS-01) DNS provider.
  4. Copy the generated command and run it on your server.

Frequently asked questions

▸Which client should I choose?

Certbot is the most documented and integrates with Nginx/Apache; acme.sh is a lightweight shell script great for cron renewal; lego is a single Go binary; win-acme covers Windows. All four renew automatically once configured.

▸Why use DNS-01 instead of HTTP-01?

DNS-01 works for wildcard certificates and when port 80 is blocked or the domain is fronted by a CDN. It requires DNS provider API credentials.

▸Do I need port 80 open for HTTP-01?

Yes — Let's Encrypt validates HTTP-01 by fetching a URL over plain HTTP on port 80. Use our preflight checker to confirm readiness before issuing.

▸How do I keep the certificate renewed automatically?

Certbot installs a systemd timer; acme.sh installs a cron job; lego and win-acme have their own schedulers. All re-run the same command and renew when the certificate is within the renewal window.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.