7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source DigiCert alternatives

A curated, ranked list of the 4 best open-source alternatives to DigiCert.

The best open-source alternative to DigiCert is acme.sh. If that doesn't suit you, other good options are Certbot, Lego and step-ca.

DigiCert alternatives are mainly security tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 2 use a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

acme.sh

A lightweight ACME client written purely in Unix shell that issues, renews and installs SSL/TLS certificates without depending on Python.

GitHub stars
48k
Last commit
5 days ago
Latest release
3.1.6
Licence
GPL-3.0
Self-hosted
Yes
acme.shacme.sh homepage screenshot

acme.sh is an ACME protocol client written entirely in Unix shell. It implements the full ACME protocol and uses a single script to issue, renew and install SSL/TLS certificates automatically. It is released under the GPL-3.0 license and works with Bash, dash and sh, with no dependency on Python.

It supports ECDSA certificates as well as SAN and wildcard certificates, and its topics reference certificate authorities such as Let's Encrypt, ZeroSSL and Buypass. The project is described as simple to learn, and it does not need root access.

Since 2021 acme.sh has been sponsored and maintained by ZeroSSL, and it now has a dedicated website. As certificate lifetimes shorten, automated renewal becomes more important, which is the problem the tool addresses. It suits system administrators and developers who want a minimal, scriptable alternative to Certbot for web servers, appliances and containers.

Key features

  • ACME client written purely in shell
  • Issue, renew and install certificates
  • ECDSA, SAN and wildcard certificate support
  • Works with Bash, dash and sh
  • No Python dependency
  • Works with Let's Encrypt and ZeroSSL

Pricing: Free and open source under the GPL-3.0 license; sponsored and maintained by ZeroSSL.

Certbot

Certbot is the Electronic Frontier Foundation's client for obtaining Let's Encrypt certificates and optionally enabling HTTPS on a server.

GitHub stars
33k
Last commit
today
Latest release
v5.8.0
Self-hosted
Yes

Certbot is a command-line tool from the Electronic Frontier Foundation for obtaining TLS certificates from Let's Encrypt and, optionally, switching on HTTPS for your web server. It is written in Python and is a common client for automated certificate issuance.

Beyond Let's Encrypt, Certbot can act as a client for any other certificate authority that supports the ACME protocol, which makes it usable in setups that rely on a different issuer. The repository's topics point to ACME client functionality, certificate management and Let's Encrypt integration. Check the project documentation for supported web servers, plugins and renewal options.

Key features

  • Obtains certificates from Let's Encrypt
  • Optionally enables HTTPS on your server
  • Works with any ACME-compatible certificate authority
  • Command-line client written in Python
Read more about CertbotGitHub

Lego

ACME client and Go library for obtaining and renewing TLS certificates from Let's Encrypt and other certificate authorities.

GitHub stars
9.9k
Last commit
5 days ago
Latest release
v5.5.2
Licence
MIT
go-acme.github.ioLego homepage screenshot

Lego is an ACME client and library written in Go, built to obtain and renew certificates from Let's Encrypt and other ACME certificate authorities. It can be used as a command-line tool or embedded in other Go software, which makes HTTPS certificates easy to automate.

It implements ACME v2 as defined in RFC 8555 and supports related standards, including the TLS-ALPN challenge extension, certificates for IP addresses, Renewal Information and several draft extensions. Its challenge support covers HTTP-01, DNS-01 and TLS-ALPN-01, and it ships with integrations for more than 200 DNS providers. It can register with a CA, obtain certificates from scratch or from an existing CSR, renew and revoke them, and handle SAN certificates and custom challenge solvers.

Lego is released under the MIT license. It is described as an independent, free project that relies on donations, and its documentation is hosted online. If a DNS provider is missing, users are encouraged to open an issue to request support.

Key features

  • ACME v2 client per RFC 8555
  • HTTP-01, DNS-01 and TLS-ALPN-01 challenges
  • More than 200 DNS provider integrations
  • Obtain, renew and revoke certificates
  • SAN certificates and custom solvers
  • Usable as a CLI or Go library

Pricing: Free and open source under the MIT license.

step-ca

step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows.

GitHub stars
8.9k
Last commit
3 days ago
Latest release
v0.30.2
Licence
Apache-2.0
Self-hosted
Yes
smallstep.comstep-ca homepage screenshot

step-ca, published as smallstep/certificates, is an online private certificate authority built for automated certificate management in DevOps environments. It is the server counterpart to the step command-line tool, and both are maintained by Smallstep Labs.

It can issue HTTPS server and client certificates trusted by browsers, as well as TLS certificates for virtual machines, containers, APIs, database connections and Kubernetes pods. It also issues SSH certificates: users can obtain them with single sign-on tokens, and hosts can obtain them using cloud instance identity documents. As an ACME server it supports the popular challenge types, and a Go wrapper and the step CLI help with scripting.

step-ca is written in Go and released under Apache-2.0. It is tuned for a two-tier PKI, and the README points teams that need multiple authorities, active revocation through CRL or OCSP, device attestation or a web admin UI to Smallstep's separate commercial product.

Key features

  • Private certificate authority for X.509
  • SSH certificates for users and hosts
  • ACME server with common challenge types
  • TLS certificates for containers and Kubernetes pods
  • Single sign-on token exchange for SSH access
  • Go wrapper and step CLI automation

Pricing: Open source under Apache-2.0; Smallstep also sells a separate commercial CA product with additional features.

DigiCert alternatives: questions

What is the best open-source alternative to DigiCert?
acme.sh is the top-ranked open-source alternative to DigiCert on Enlisted: A lightweight ACME client written purely in Unix shell that issues, renews and installs SSL/TLS certificates without depending on Python. Other strong options are Certbot, Lego and step-ca.
Are these DigiCert alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of DigiCert alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all