Automatic Paid SSL deployment + more ACME certs
Currently paid SSL certificates can be manually uploaded, but their valid time will be reduced to 100 days, then in 2029 to 47 days.
It would be great to have an option where the user can supply vendor data, keys then certbot/acme.sh would automatically validate domains, then deploy and manage the certs.
Also the panel only support Let's Encrypt certificates automatically, but there are more that can be used like GTS or ZeroSSL. Are you planning to add them?
15.07.2026 13:18
Hi Sandor, thanks for the detailed request. On automating paid SSL deployment: yes, this is a direction we plan to move in.
On adding more ACME CAs (GTS, ZeroSSL, and others): here I'd like to understand the concrete need first. ispmanager already issues free DV certificates automatically via Let's Encrypt, which covers the large majority of cases at no cost. So what would a second or third free CA give you in practice?
28.07.2026 03:59
Thanks for considering the automated paid SSL deployment! Regarding the need for alternative ACME CAs (like ZeroSSL or GTS alongside Let's Encrypt):
If Let's Encrypt experiences downtime, maintenance, or validation service issues, automated renewals fail. Having a secondary ACME provider as a fallback ensures certificates renew or issue is possible. Sometimes Let's Encrypt validation fails due to specific DNS/CAA edge cases or routing issues. Switching to ZeroSSL or GTS serves as an instant workaround.
Let's Encrypt enforces strict rate limits (e.g., 50 certificates per registered domain per week, or limits on duplicate certificates). For multi-tenant hosting, SaaS platforms, or servers managing hundreds of subdomains, hitting these limits is common. Alternative CAs provide an immediate release valve.
Different CAs rely on different root and intermediate certificates. For instance, ZeroSSL uses Sectigo's trusted root, and Google Trust Services relies on Google's widespread trust infrastructure. Certain legacy devices, embedded systems, older smart TVs, or specialized corporate firewalls trust GTS or Sectigo roots better than Let's Encrypt's ISRG Root X1/X2.
03.08.2026 14:52