dotnet-certes
4.1.0
See the version list below for details.
dotnet tool install --global dotnet-certes --version 4.1.0
dotnet new tool-manifest
dotnet tool install --local dotnet-certes --version 4.1.0
#tool dotnet:?package=dotnet-certes&version=4.1.0
nuke :add-package dotnet-certes --version 4.1.0
dotnet-certes
dotnet-certes is a command-line ACME client built on the
Certes library. It manages ACME
accounts, orders and challenges, and exports issued certificates as PEM or PFX.
Requires the .NET 10 runtime.
New in 4.1
- Select a certificate profile with
order new --profile, and associate a replacement order with an earlier certificate using--replaces. - Query a certificate's suggested renewal window with
cert renewal-info; no account key is required for this query. - Pass IP addresses to
order newto create IP identifiers automatically. - Select
tls-alpnchallenges withorder authzandorder validate. The CLI outputs the key authorization; the validation certificate must be created separately, for example with the library'sTlsAlpnCertificatehelper.
Profile, ARI, and IP certificate support depends on the ACME server. See the CLI guide for the complete workflow.
Getting started
dotnet tool install --global dotnet-certes
certes --help
Settings, including the account key, are stored in a user settings file. Keep that file private.
Documentation
Licensed under the MIT license.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 5.0.0-beta.1 | 34 | 9/29/2026 |
| 4.1.0 | 95 | 9/27/2026 |
| 4.0.0 | 102 | 9/23/2026 |
| 4.0.0-beta.1 | 59 | 9/23/2026 |
| 3.0.4 | 6,067 | 1/4/2023 |
| 3.0.3 | 5,618 | 10/4/2021 |
| 3.0.2-beta0008 | 549 | 10/4/2021 |
| 3.0.0 | 3,952 | 7/18/2021 |
| 3.0.0-beta0122 | 504 | 10/4/2021 |
| 3.0.0-beta0119 | 565 | 7/18/2021 |
| 3.0.0-beta0001 | 506 | 7/18/2021 |
| 2.4.0-beta0001 | 466 | 6/1/2021 |
| 1.0.6 | 5,287 | 4/5/2020 |
| 1.0.5 | 4,001 | 4/4/2020 |
| 1.0.4 | 3,875 | 3/27/2020 |
| 1.0.3 | 6,100 | 7/25/2018 |
| 1.0.2 | 4,738 | 7/13/2018 |
| 1.0.1 | 4,807 | 5/31/2018 |
### Added
- IP address identifiers (RFC 8738): `IdentifierType.Ip`, and `NewOrder`,
`NewOrderWithProfile` and `NewReplacementOrder` overloads accepting typed
`Identifier` lists. IP values are validated and sent in canonical form.
- Certificate profile discovery through `DirectoryMeta.Profiles`, selection via
`NewOrderWithProfile`, and the selected `Order.Profile`
([#330](https://github.com/fszlin/certes/issues/330)). Profile orders can also
include an ARI replacement certificate ID.
- ACME Renewal Information (ARI, RFC 9773): `Directory.RenewalInfo`,
`GetRenewalInfoCertificateId()` for `CertificateChain` and `IEncodable`,
`GetRenewalInfo()` (suggested window, explanation URL and `Retry-After`) and
`NewReplacementOrder()` extension methods on `IAcmeContext`, and `Order.Replaces`.
Based on the proposal in [#329](https://github.com/fszlin/certes/issues/329)
by @WhitWaldo.
- CLI: `order new --profile` and `--replaces`, `cert renewal-info <cert-path>`,
and the `tls-alpn` challenge type for `order authz`/`order validate` (with
`dns-01`, `http-01` and `tls-alpn-01` aliases). IP addresses passed to
`order new` are ordered as IP identifiers.
### Changed
- `NewOrder`, `NewOrderWithProfile` and `NewReplacementOrder` string overloads
now send values that strictly parse as IP addresses as `ip` identifiers in
canonical form, instead of `dns`. CAs reject IP addresses as DNS identifiers, so
previously such orders always failed.
- `IOrderContext.Authorization(value, IdentifierType.Ip)` compares IP identifiers
by address rather than by text.
- `CertificationRequestBuilder` encodes subject alternative names that are IP
addresses as IP SANs instead of DNS names, and `TlsAlpnCertificate` does the same
for its subject name.
- When `CsrInfo.CommonName` is not set, `Finalize`/`Generate` use the first DNS
name of at most 64 characters as the common name, instead of always the first
identifier. IP-only orders produce a CSR without a common name.
### Fixed
- CLI: `cert pfx --help` described the command as exporting PEM.
Full changelog: https://github.com/fszlin/certes/blob/v4.1.0/docs/CHANGELOG.md