dotnet-certes 5.0.0-beta.1

This is a prerelease version of dotnet-certes.
dotnet tool install --global dotnet-certes --version 5.0.0-beta.1
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local dotnet-certes --version 5.0.0-beta.1
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=dotnet-certes&version=5.0.0-beta.1&prerelease
                    
nuke :add-package dotnet-certes --version 5.0.0-beta.1
                    

dotnet-certes

dotnet-certes is a command-line ACME client built on the Certes library. It manages ACME accounts, orders and challenges, and exports issued certificates as PEM or PFX.

Requires the .NET 10 runtime.

New in 5.0.0-beta.1

The CLI uses Spectre.Console.Cli 0.55.0 with asynchronous dispatch and Ctrl+C cancellation. A cancelled invocation exits with code 130 (0 for success, 1 for other failures). A second Ctrl+C permits immediate termination.

With explicit --out, account creation and certificate finalization save generated keys before sending the request. Existing output files are atomically replaced; the file remains if the request fails or is cancelled. Use dedicated paths and retain those keys. See the v5 upgrade guide for completion races and recovery limits without explicit key output.

This is a prerelease; DNS-PERSIST-01 is not included, and public-CA interoperability has not been re-verified for this beta.

New in 4.1

  • Select a certificate profile with order new --profile, and associate a replacement order with an earlier certificate using --replaces.
  • Query a certificate's suggested renewal window with cert renewal-info; no account key is required for this query.
  • Pass IP addresses to order new to create IP identifiers automatically.
  • Select tls-alpn challenges with order authz and order validate. The CLI outputs the key authorization; the validation certificate must be created separately, for example with the library's TlsAlpnCertificate helper.

Profile, ARI, and IP certificate support depends on the ACME server. See the CLI guide for the complete workflow.

Getting started

dotnet tool install --global dotnet-certes --version 5.0.0-beta.1
certes --help

Settings, including the account key, are stored in a user settings file. Keep that file private.

Documentation

Licensed under the MIT license.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
5.0.0-beta.1 34 9/29/2026
4.1.0 93 9/27/2026
4.0.0 102 9/23/2026
4.0.0-beta.1 59 9/23/2026
3.0.4 6,067 1/4/2023
3.0.3 5,618 10/4/2021
3.0.2-beta0008 548 10/4/2021
3.0.0 3,952 7/18/2021
3.0.0-beta0122 503 10/4/2021
3.0.0-beta0119 565 7/18/2021
3.0.0-beta0001 506 7/18/2021
2.4.0-beta0001 466 6/1/2021
1.0.6 5,287 4/5/2020
1.0.5 4,001 4/4/2020
1.0.4 3,875 3/27/2020
1.0.3 6,100 7/25/2018
1.0.2 4,738 7/13/2018
1.0.1 4,807 5/31/2018
Loading failed

First v5 prerelease, focused on cancellable library operations and CLI commands.
DNS-PERSIST-01 is not included. See the
[v5 upgrade guide](https://github.com/fszlin/certes/blob/v5.0.0-beta.1/docs/v5-upgrade.md)
before upgrading. Public-CA interoperability has not been re-verified for this
prerelease; automated issuance checks use the local Pebble test CA.

### Breaking changes
- Core asynchronous interfaces, implementations, and convenience extensions now
 accept a final optional `CancellationToken`. This replaces the old signatures:
 recompile consumers and update custom implementations, mocks, callbacks, and
 method-group delegates. Most ordinary calls continue to compile unchanged.
 Library target frameworks and runtime dependency minimums are unchanged.

### Added
- Cancellation throughout ACME discovery, HTTP requests, bad-nonce retries,
 authorization lookups, order pagination, alternate-chain downloads, and polling
 delays ([#299](https://github.com/fszlin/certes/issues/299)). Cancellation is
 cooperative and does not interrupt synchronous cryptographic operations or roll
 back requests already accepted by a CA.
- CLI Ctrl+C cancellation with exit code **130**; success remains **0** and
 parsing/operation errors remain **1**. A second Ctrl+C permits immediate process
 termination. HTTP timeouts remain operation errors, not user cancellations.

### Changed
- Upgrade the CLI to Spectre.Console.Cli 0.55.0 and asynchronous dispatch
 ([#405](https://github.com/fszlin/certes/issues/405)), preserving command names,
 options, and normal JSON result shapes.
- With explicit `--out`, `account new` saves the account key before requesting
 account creation, and `order finalize` saves a newly generated certificate key
 before sending the CSR. Existing output files are atomically replaced before
 sending; the saved file remains even when the subsequent request fails or is
 cancelled. Use dedicated output paths and retain the keys for recovery.
- When account/order creation succeeds but cancellation stops the follow-up
 resource lookup, the CLI emits the returned `location` in JSON and exits 130.
 Requests cancelled before a response arrives still require reconciliation with
 the CA. Without explicit key output, in-flight cancellation can still lose a
 generated key; see the upgrade guide for persistence and recovery limits.
- Refresh CLI/build/test dependencies and add Linux unit-coverage reporting and
 CodeQL analysis. Retire the obsolete Azure Functions integration-test helper;
 integration tests use local Pebble.

### Fixed
- Preserve complete ACME responses and terminal protocol errors when cancellation
 arrives late, including account/order locations and successful account key
 changes. Cancelled discovery does not cache a cancelled task.

Full changelog: https://github.com/fszlin/certes/blob/v5.0.0-beta.1/docs/CHANGELOG.md