Updates and releases

ACME: Automate your SSL/TLS certificate renewals

SSL/TLS certificate management is changing. As certificate lifetimes are progressively shortened, businesses will need to renew their certificates more frequently. Against this backdrop, automation is becoming essential to prevent certificate expirations and maintain the availability and security of online services.

To help businesses adapt to these changes, Gandi now offers an ACME-based solution that automates SSL/TLS certificate renewals.

Why does SSL/TLS certificate management need to change?

SSL/TLS certificates secure communications between websites or online services and their users. However, certificates are only valid for a limited period and must be renewed regularly.

Certificate lifetimes are being progressively shortened, with another milestone expected in March 2027. As certificate validity periods decrease, renewals will need to happen more frequently.

For organizations managing multiple domains, websites, or services, a largely manual approach can quickly become cumbersome: more expiration dates to keep track of, more interventions to schedule, and, most importantly, a greater risk of a certificate expiring unexpectedly.

An expired certificate can trigger security warnings in browsers, disrupt access to a website or service, and require urgent intervention from technical teams.

This is exactly the kind of situation that automation can help prevent.

What is the ACME protocol?

ACME (Automated Certificate Management Environment) is a protocol designed to automate SSL/TLS certificate management.

The principle is straightforward: instead of manually renewing a certificate whenever it approaches its expiration date, an ACME-compatible client communicates with the Certificate Authority (CA) to automatically perform the necessary operations.

This makes it possible to integrate certificate renewal directly into an organization’s technical infrastructure.

In practice, ACME replaces the need to monitor and manually renew each individual certificate with a largely automated certificate lifecycle management process.

Why automate certificate renewals?

As certificate lifetimes become shorter, automation offers several key benefits.

1. Reduce the risk of certificate expiration

Certificates are automatically renewed before they expire, reducing the need to rely solely on calendars, reminders, or manual intervention.

2. Save time

Technical teams no longer need to repeat the same renewal tasks for every certificate, freeing them to focus on higher-value work.

3. Simplify certificate management at scale

The more certificates an organization manages, the more valuable automation becomes. ACME makes it easier to manage environments spanning multiple domains and services.

4. Prepare for shorter certificate lifetimes

As certificate lifetimes continue to decrease, renewals will become increasingly frequent. Implementing ACME now allows organizations to adapt their infrastructure before renewal frequency increases further.

How does Gandi’s ACME offering work?

Gandi’s ACME offering combines a 1-, 2-, or 3-year subscription with automated certificate renewals throughout the subscription period.

It is important to distinguish between two concepts: the subscription term and the validity period of each individual certificate.

Even if a certificate needs to be renewed several times during the subscription period, ACME automates those renewals. A multi-year subscription therefore does not mean that a single certificate remains valid for several years. Instead, new certificates are issued as renewals become necessary.

The goal is to make this transition seamless for users.

Which certificates are supported?

The offering is available now for Domain Validation (DV) certificates using Sectigo’s ACME protocol.

DV certificates verify control over a domain name and are well suited to a wide range of websites and online services.

Gandi also plans to introduce optional support for Organization Validation (OV) certificates in the near future. OV certificates include an additional organization validation step, making them suitable for use cases that require a higher level of identity verification.

How do I enable ACME with Gandi?

Getting started is designed to be straightforward.

From your Gandi account, go to the section where you manage your SSL/TLS certificates and select the ACME option. From there, you can subscribe to the service and configure your environment to take advantage of automated certificate renewals.

Once everything is set up, certificates can be renewed automatically throughout your subscription period, without having to wait until each certificate is close to expiring before taking manual action.

Prepare now for shorter-lived certificates

The move toward shorter SSL/TLS certificate lifetimes is gradually transforming certificate management. What was once a relatively occasional task is becoming a recurring process, and one that increasingly benefits from automation.

ACME makes this transition simpler and more reliable by reducing manual intervention and minimizing the risks associated with expired certificates.

Gandi’s ACME offering is available now for DV certificates, with 1-, 2-, or 3-year subscription options and automated renewals throughout the subscription period.

If you have any questions or need help setting up ACME, contact our support team via our help desk.

For more information about enabling ACME on your Gandi account, see our documentation.