dotnet-certes 4.1.0

There is a newer prerelease version of this package available.
See the version list below for details.
dotnet tool install --global dotnet-certes --version 4.1.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local dotnet-certes --version 4.1.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=dotnet-certes&version=4.1.0
                    
nuke :add-package dotnet-certes --version 4.1.0
                    

dotnet-certes

dotnet-certes is a command-line ACME client built on the Certes library. It manages ACME accounts, orders and challenges, and exports issued certificates as PEM or PFX.

Requires the .NET 10 runtime.

New in 4.1

  • Select a certificate profile with order new --profile, and associate a replacement order with an earlier certificate using --replaces.
  • Query a certificate's suggested renewal window with cert renewal-info; no account key is required for this query.
  • Pass IP addresses to order new to create IP identifiers automatically.
  • Select tls-alpn challenges with order authz and order validate. The CLI outputs the key authorization; the validation certificate must be created separately, for example with the library's TlsAlpnCertificate helper.

Profile, ARI, and IP certificate support depends on the ACME server. See the CLI guide for the complete workflow.

Getting started

dotnet tool install --global dotnet-certes
certes --help

Settings, including the account key, are stored in a user settings file. Keep that file private.

Documentation

Licensed under the MIT license.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
5.0.0-beta.1 34 9/29/2026
4.1.0 95 9/27/2026
4.0.0 102 9/23/2026
4.0.0-beta.1 59 9/23/2026
3.0.4 6,067 1/4/2023
3.0.3 5,618 10/4/2021
3.0.2-beta0008 549 10/4/2021
3.0.0 3,952 7/18/2021
3.0.0-beta0122 504 10/4/2021
3.0.0-beta0119 565 7/18/2021
3.0.0-beta0001 506 7/18/2021
2.4.0-beta0001 466 6/1/2021
1.0.6 5,287 4/5/2020
1.0.5 4,001 4/4/2020
1.0.4 3,875 3/27/2020
1.0.3 6,100 7/25/2018
1.0.2 4,738 7/13/2018
1.0.1 4,807 5/31/2018
Loading failed

### Added
- IP address identifiers (RFC 8738): `IdentifierType.Ip`, and `NewOrder`,
 `NewOrderWithProfile` and `NewReplacementOrder` overloads accepting typed
 `Identifier` lists. IP values are validated and sent in canonical form.
- Certificate profile discovery through `DirectoryMeta.Profiles`, selection via
 `NewOrderWithProfile`, and the selected `Order.Profile`
 ([#330](https://github.com/fszlin/certes/issues/330)). Profile orders can also
 include an ARI replacement certificate ID.
- ACME Renewal Information (ARI, RFC 9773): `Directory.RenewalInfo`,
 `GetRenewalInfoCertificateId()` for `CertificateChain` and `IEncodable`,
 `GetRenewalInfo()` (suggested window, explanation URL and `Retry-After`) and
 `NewReplacementOrder()` extension methods on `IAcmeContext`, and `Order.Replaces`.
 Based on the proposal in [#329](https://github.com/fszlin/certes/issues/329)
 by @WhitWaldo.
- CLI: `order new --profile` and `--replaces`, `cert renewal-info <cert-path>`,
 and the `tls-alpn` challenge type for `order authz`/`order validate` (with
 `dns-01`, `http-01` and `tls-alpn-01` aliases). IP addresses passed to
 `order new` are ordered as IP identifiers.

### Changed
- `NewOrder`, `NewOrderWithProfile` and `NewReplacementOrder` string overloads
 now send values that strictly parse as IP addresses as `ip` identifiers in
 canonical form, instead of `dns`. CAs reject IP addresses as DNS identifiers, so
 previously such orders always failed.
- `IOrderContext.Authorization(value, IdentifierType.Ip)` compares IP identifiers
 by address rather than by text.
- `CertificationRequestBuilder` encodes subject alternative names that are IP
 addresses as IP SANs instead of DNS names, and `TlsAlpnCertificate` does the same
 for its subject name.
- When `CsrInfo.CommonName` is not set, `Finalize`/`Generate` use the first DNS
 name of at most 64 characters as the common name, instead of always the first
 identifier. IP-only orders produce a CSR without a common name.

### Fixed
- CLI: `cert pfx --help` described the command as exporting PEM.

Full changelog: https://github.com/fszlin/certes/blob/v4.1.0/docs/CHANGELOG.md