Let's Encrypt or ZeroSSL for ACME automation: is the CA choice or the client the real decision?
When you automate certificate issuance, what are you actually choosing between? Both Let's Encrypt and ZeroSSL speak ACME (Automatic Certificate Management Environment, RFC 8555), so the protocol is identical. The differentiators sit elsewhere.
Let's Encrypt issues 90-day certificates, enforces rate limits per registered domain, and runs on a well-documented, heavily mirrored infrastructure. ZeroSSL also speaks ACME but layers in 90-day free and longer paid options plus a dashboard, and historically required EAB (External Account Binding) credentials for ACME — a friction point in pure automation.
The client matters more than the CA in practice. Certbot is the reference but heavyweight; acme.sh is a portable shell client with broad DNS-provider hooks; lego and Caddy's built-in ACME handle issuance in-process. Your renewal reliability is mostly a property of the client and its scheduling, not the CA's logo.
— Pick Let's Encrypt for the simplest unauthenticated ACME flow.
— Pick ZeroSSL when you want a fallback issuer or its account features, accepting EAB setup.
— Run two CAs behind one client for resilience against a single-CA outage.
Further reading: RFC 8555; RFC 8737 for the ACME TLS-ALPN challenge.
Bottom line: the CA is nearly fungible under ACME; invest your attention in the client and in multi-CA redundancy.
Handshake Papers
@HandshakePapers
Let's Encrypt or ZeroSSL for ACME automation: is the CA choice or the client the real decision?
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.