dotnet-certes
5.0.0-beta.1
dotnet tool install --global dotnet-certes --version 5.0.0-beta.1
dotnet new tool-manifest
dotnet tool install --local dotnet-certes --version 5.0.0-beta.1
#tool dotnet:?package=dotnet-certes&version=5.0.0-beta.1&prerelease
nuke :add-package dotnet-certes --version 5.0.0-beta.1
dotnet-certes
dotnet-certes is a command-line ACME client built on the
Certes library. It manages ACME
accounts, orders and challenges, and exports issued certificates as PEM or PFX.
Requires the .NET 10 runtime.
New in 5.0.0-beta.1
The CLI uses Spectre.Console.Cli 0.55.0 with asynchronous dispatch and Ctrl+C cancellation. A cancelled invocation exits with code 130 (0 for success, 1 for other failures). A second Ctrl+C permits immediate termination.
With explicit --out, account creation and certificate finalization save generated
keys before sending the request. Existing output files are atomically replaced;
the file remains if the request fails or is cancelled. Use dedicated paths and
retain those keys. See the
v5 upgrade guide
for completion races and recovery limits without explicit key output.
This is a prerelease; DNS-PERSIST-01 is not included, and public-CA interoperability has not been re-verified for this beta.
New in 4.1
- Select a certificate profile with
order new --profile, and associate a replacement order with an earlier certificate using--replaces. - Query a certificate's suggested renewal window with
cert renewal-info; no account key is required for this query. - Pass IP addresses to
order newto create IP identifiers automatically. - Select
tls-alpnchallenges withorder authzandorder validate. The CLI outputs the key authorization; the validation certificate must be created separately, for example with the library'sTlsAlpnCertificatehelper.
Profile, ARI, and IP certificate support depends on the ACME server. See the CLI guide for the complete workflow.
Getting started
dotnet tool install --global dotnet-certes --version 5.0.0-beta.1
certes --help
Settings, including the account key, are stored in a user settings file. Keep that file private.
Documentation
Licensed under the MIT license.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 5.0.0-beta.1 | 34 | 9/29/2026 |
| 4.1.0 | 93 | 9/27/2026 |
| 4.0.0 | 102 | 9/23/2026 |
| 4.0.0-beta.1 | 59 | 9/23/2026 |
| 3.0.4 | 6,067 | 1/4/2023 |
| 3.0.3 | 5,618 | 10/4/2021 |
| 3.0.2-beta0008 | 548 | 10/4/2021 |
| 3.0.0 | 3,952 | 7/18/2021 |
| 3.0.0-beta0122 | 503 | 10/4/2021 |
| 3.0.0-beta0119 | 565 | 7/18/2021 |
| 3.0.0-beta0001 | 506 | 7/18/2021 |
| 2.4.0-beta0001 | 466 | 6/1/2021 |
| 1.0.6 | 5,287 | 4/5/2020 |
| 1.0.5 | 4,001 | 4/4/2020 |
| 1.0.4 | 3,875 | 3/27/2020 |
| 1.0.3 | 6,100 | 7/25/2018 |
| 1.0.2 | 4,738 | 7/13/2018 |
| 1.0.1 | 4,807 | 5/31/2018 |
First v5 prerelease, focused on cancellable library operations and CLI commands.
DNS-PERSIST-01 is not included. See the
[v5 upgrade guide](https://github.com/fszlin/certes/blob/v5.0.0-beta.1/docs/v5-upgrade.md)
before upgrading. Public-CA interoperability has not been re-verified for this
prerelease; automated issuance checks use the local Pebble test CA.
### Breaking changes
- Core asynchronous interfaces, implementations, and convenience extensions now
accept a final optional `CancellationToken`. This replaces the old signatures:
recompile consumers and update custom implementations, mocks, callbacks, and
method-group delegates. Most ordinary calls continue to compile unchanged.
Library target frameworks and runtime dependency minimums are unchanged.
### Added
- Cancellation throughout ACME discovery, HTTP requests, bad-nonce retries,
authorization lookups, order pagination, alternate-chain downloads, and polling
delays ([#299](https://github.com/fszlin/certes/issues/299)). Cancellation is
cooperative and does not interrupt synchronous cryptographic operations or roll
back requests already accepted by a CA.
- CLI Ctrl+C cancellation with exit code **130**; success remains **0** and
parsing/operation errors remain **1**. A second Ctrl+C permits immediate process
termination. HTTP timeouts remain operation errors, not user cancellations.
### Changed
- Upgrade the CLI to Spectre.Console.Cli 0.55.0 and asynchronous dispatch
([#405](https://github.com/fszlin/certes/issues/405)), preserving command names,
options, and normal JSON result shapes.
- With explicit `--out`, `account new` saves the account key before requesting
account creation, and `order finalize` saves a newly generated certificate key
before sending the CSR. Existing output files are atomically replaced before
sending; the saved file remains even when the subsequent request fails or is
cancelled. Use dedicated output paths and retain the keys for recovery.
- When account/order creation succeeds but cancellation stops the follow-up
resource lookup, the CLI emits the returned `location` in JSON and exits 130.
Requests cancelled before a response arrives still require reconciliation with
the CA. Without explicit key output, in-flight cancellation can still lose a
generated key; see the upgrade guide for persistence and recovery limits.
- Refresh CLI/build/test dependencies and add Linux unit-coverage reporting and
CodeQL analysis. Retire the obsolete Azure Functions integration-test helper;
integration tests use local Pebble.
### Fixed
- Preserve complete ACME responses and terminal protocol errors when cancellation
arrives late, including account/order locations and successful account key
changes. Cancelled discovery does not cache a cancelled task.
Full changelog: https://github.com/fszlin/certes/blob/v5.0.0-beta.1/docs/CHANGELOG.md