Certbot 1,690 is one ACME client among many, and each of these works with Let's Encrypt 1,144 :
| Client | Form | Default CA | Best for |
|---|---|---|---|
| Certbot 5.8.0 | Python snap, Apache 129 and nginx 75 plugins | Let's Encrypt | Most Apache and nginx servers |
| acme.sh 3.1.6 47,741 | One shell script, no root needed | ZeroSSL 62,837 | Minimal hosts, DNS-provider APIs |
| mod_md | Apache module, in Ubuntu 225 's apache2 | Let's Encrypt | Apache with no external client |
| Caddy 2.11.4 7,400 | Web server with ACME built in | Let's Encrypt, ZeroSSL fallback | New sites, HTTPS by default |
| nginx-acme 0.4.1 | Native nginx module, in Rust | Set per issuer | nginx without Certbot |
acme.sh (https://github.com/acmesh-official/acme.sh 47,741 ) has defaulted to ZeroSSL since 3.0; switch with acme.sh --set-default-ca --server letsencrypt. mod_md (sudo a2enmod md) makes Apache its own ACME client: it obtains and renews certificates and restarts gracefully when one is ready, with no SSLCertificateFile line. Its manual still says Experimental, though it has shipped since 2.4.30; 2.4.64 added MDProfile, and ARI is on by default. It needs a domain reachable from the internet, so this was not run here:
MDContactEmail admin@example.com
MDCertificateAgreement accepted
MDomain example.com www.example.com
MDProfile tlsserverUse one client per certificate; two renewing the same names waste rate limits and overwrite files.