A simple ACME command line tool without 3rd party deps!


A simple command line tool to manage TLS certificates with ACME-compliant CAs, which has no third party depedencies.

If you’re looking for a package to import in your program, or is what you’ll want instead.

This package is a work in progress and makes no API stability promises.


Quick install with go get -u or download a pre-built binary from the releases page.

The release binaries have an additional command, acme version, which reports the release version.

  1. You need to have a user account, registered with the CA. This is represented by an RSA private key.

The easiest is to let the acme tool generate it for you:

    acme reg -gen mailto:[email protected]

If you want to generate a key manually:

    mkdir -p ~/.config/acme
    openssl genrsa -out ~/.config/acme/account.key 4096
    acme reg mailto:[email protected]

The latter version assumes that default acme config dir is ~/.config/acme. Yours may vary. Check with acme help reg.

The “mailto:[email protected]” in the example above is a contact argument. While some ACME CA may let you register without providing any contact info, it is recommended to use one. For instance a CA might need to notify cert owners with an update.

  1. Agree with the ACME CA Terms of Service.

Before requesting your first certificate, you may need to agree with the terms of the CA. You can check the status of our account with:

    acme whoami

and look for “Accepted: …” line. If it says “no”, check CA’s terms document provided as a link in “Terms: …” field and agree by executing:

    acme update -accept
  1. Request a new certificate for your domain.

The easiest way to do this is:

    acme cert

The above command will generate a new certificate key (unless one already exists), and send a certifcate request. The location of the output files is ~/.config.acme, but depends on your environment. Check with acme help cert.

If you don’t want auto-generated cert key, one can always be generated upfront:

    openssl genrsa -out cert.key 2048

in which case the cert command will look something like this:

    acme cert -k cert.key

Note that for certificate request command to succeed, it needs to be executed in a way allowing for resolving authorization challenges (domain ownership proof). This typically means the command should be executed on the same host the domain is served from.

If the latter is not possible, use -manual flag and follow the instructions:

    acme cert -manual


© Google, 2015. Licensed under Apache-2 license.

This is not an official Google product.

Related Repositories

A pure Unix shell script implementing ACME client protocol ...



:lock: acmetool, an automatic certificate acquisition tool for ACME (Let's Encrypt) ...



ACME Specification ...



A Ruby client for the letsencrypt's ACME protocol. ...



Let's Encrypt / ACME client written in PHP for the CLI. ...

Top Contributors

x1ddos sgomes titanous mbwalas hkjn kkirsche siepkes ikellenberger


-   1.1.1 zip tar
-   1.1.0 zip tar
-   1.0.0 zip tar