acme.sh and mod_md

acme.sh, mod_md and Automatic HTTPS Elsewhere

Certbot 1,690 is one ACME client among many, and each of these works with Let's Encrypt 1,144 :

ACME clients and servers with ACME built in, 23 September 2026
Client Form Default CA Best for
Certbot 5.8.0 Python snap, Apache 129 and nginx 75 plugins Let's Encrypt Most Apache and nginx servers
acme.sh 3.1.6 47,741 One shell script, no root needed ZeroSSL 62,837 Minimal hosts, DNS-provider APIs
mod_md Apache module, in Ubuntu 225 's apache2 Let's Encrypt Apache with no external client
Caddy 2.11.4 7,400 Web server with ACME built in Let's Encrypt, ZeroSSL fallback New sites, HTTPS by default
nginx-acme 0.4.1 Native nginx module, in Rust Set per issuer nginx without Certbot

acme.sh (https://github.com/acmesh-official/acme.sh 47,741 ) has defaulted to ZeroSSL since 3.0; switch with acme.sh --set-default-ca --server letsencrypt. mod_md (sudo a2enmod md) makes Apache its own ACME client: it obtains and renews certificates and restarts gracefully when one is ready, with no SSLCertificateFile line. Its manual still says Experimental, though it has shipped since 2.4.30; 2.4.64 added MDProfile, and ARI is on by default. It needs a domain reachable from the internet, so this was not run here:

Server-wide mod_md settings; the *:443 host then needs only SSLEngine onShell
MDContactEmail admin@example.com
MDCertificateAgreement accepted
MDomain example.com www.example.com
MDProfile tlsserver

Use one client per certificate; two renewing the same names waste rate limits and overwrite files.