Which ACME client should I choose?

How to choose between DigiCert managed automation and third-party ACME clients for Windows, Linux, Kubernetes, and enterprise infrastructure.

ACME (Automated Certificate Management Environment) is an open protocol for automating certificate enrollment and renewal. DigiCert Trust Lifecycle Manager supports ACME automation with compliant third-party ACME v2 clients, but choosing an automation approach is more than choosing a client. You also need to decide who should own installation, binding, validation, renewal, monitoring, and operational support in your environment.

DigiCert managed automation or a third-party ACME client?

DigiCert managed automation uses DigiCert Agents for supported Windows and Linux server applications and DigiCert Sensors for supported network appliances, cloud services, and vaults. Trust Lifecycle Manager provides centralized orchestration, status tracking, inventory context, and deployment validation for these managed workflows.

Third-party ACME automation uses an ACME client such as Certbot, Posh-ACME, win-acme, acme.sh, or cert-manager. The client runs on or in the target platform, connects to the DigiCert ACME service using the ACME Directory URL and External Account Binding (EAB) credentials, and handles the client-side workflow configured by the operator.

Note: A DigiCert Agent is not simply another third-party ACME client. For supported server automation, the DigiCert Agent uses the ACME protocol as part of Trust Lifecycle Manager's managed automation workflow, including certificate installation and endpoint testing.

When a third-party ACME client is a good fit

Common third-party ACME client options

Certbot for common Linux web-server workflows

Certbot is a widely used open-source ACME client produced by the Electronic Frontier Foundation (EFF). Its current official support focuses on major Linux and BSD variants. On supported systems, plugins can integrate certificate issuance and renewal with web servers such as Apache and NGINX.

Choose Certbot when:

DigiCert compatibility note: DigiCert documentation provides Certbot examples for Trust Lifecycle Manager. Client-specific configuration and troubleshooting remain dependent on the Certbot implementation and your environment.

Posh-ACME for Microsoft PowerShell-centric automation environments

Posh-ACME is an open-source PowerShell ACME client with support for ACME v2, External Account Binding, multiple challenge plugins, and automated renewals. It runs on Windows PowerShell and on supported versions of PowerShell Core. For Windows service deployment such as IIS, the companion Posh-ACME.Deploy module provides deployment functions.

Choose Posh-ACME when:

win-acme for Windows and IIS

win-acme is an ACME v2 client for Windows designed to support both simple interactive setup and unattended operation. Its IIS workflow can derive certificate identifiers from site bindings, obtain the certificate, update IIS bindings, and create a scheduled renewal task. The project also supports more advanced validation, storage, and deployment options.

Choose win-acme when:

acme.sh for general Unix environments

acme.sh is an open-source ACME client written in Unix shell. It supports common ACME validation modes, automated renewal, deploy hooks, and Docker-based operation without a Python dependency. It still relies on standard system utilities and cryptographic tooling, so it should not be treated as literally dependency-free.

Choose acme.sh when:

cert-manager for Kubernetes and OpenShift

cert-manager is a Kubernetes certificate controller rather than a traditional host-level ACME client. DigiCert documents cert-manager as a supported third-party ACME integration pattern for Kubernetes and OpenShift workloads. It is typically the better abstraction when certificates are declared and reconciled as Kubernetes resources.

Choose cert-manager when:

Choose by environment and operating model

Selection criteria that matter more than popularity

Frequently asked questions

Is a DigiCert Agent an ACME client?
For supported server automation, a DigiCert Agent uses the ACME protocol as part of Trust Lifecycle Manager managed automation. However, it should not be evaluated as just another third-party ACME client. The DigiCert Agent participates in a centrally managed workflow that can include local discovery, certificate installation, web-server configuration, renewal, status tracking, and endpoint testing.
Can I use any ACME client with DigiCert?
Trust Lifecycle Manager supports third-party clients that comply with ACME v2. In practice, the client must also support the account and workflow capabilities required by your DigiCert configuration, including External Account Binding (EAB), and it must support the challenge and deployment method you intend to automate.
Does ACME replace certificate lifecycle management?
No, ACME is an enrollment and lifecycle protocol. It can automate certificate requests and renewals extremely well, but enterprise certificate lifecycle management also includes inventory, ownership, policy, authorization, deployment verification, exception handling, reporting, and operational governance. Trust Lifecycle Manager can govern ACME-based workflows alongside other automation methods.
How should I protect DigiCert ACME credentials?
Treat the ACME Directory URL and EAB credentials as sensitive automation credentials. Limit who and what can access them, store them in an approved secret-management system, scope the associated DigiCert profile or credential permissions as narrowly as practical, and replace or revoke credentials if compromise is suspected.

Supplemental DigiCert documentation