Free SSL Certificate Generator (Let’s Encrypt in Your Browser)
A real Let’s Encrypt certificate, with keys that never leave your device.
- Domains
- Prove control
- Download
2. Prove that you control each domain
Press Check only when the file or record is in place: each failed check counts towards Let’s Encrypt’s limit of 5 failures per name an hour, and a failed order cannot be checked again.
3. Your certificate
This is a test certificate from Let’s Encrypt’s staging environment: browsers do not trust it. Use it to try your set-up, then choose “Real certificate” and start again.
Renewal reminder
Let’s Encrypt sends no expiry e-mails. The calendar file adds two all-day events with an alarm: the day to renew and the last day before the certificate expires.
How to install it
Your Let’s Encrypt account key (optional)
About the Free SSL Certificate Generator (Let’s Encrypt in Your Browser)
Get a real, browser-trusted SSL/TLS certificate from Let’s Encrypt without installing anything. This page is an ACME client — the protocol Let’s Encrypt uses (RFC 8555) — that runs entirely in your browser: it makes your keys with Web Crypto, creates the Let’s Encrypt account and the order, shows you exactly which file to upload or which DNS record to add for each domain, asks Let’s Encrypt to check them and then downloads the certificate chain.
The private key is made on your device and never sent anywhere, so the page makes you save it (optionally encrypted with a passphrase) before you finish: it cannot be recovered later. You can also paste your own CSR instead, so the key never leaves your server. Before you go, add the renewal date to your calendar: Let’s Encrypt sends no expiry e-mails.
How to use it
- Type the domain names, one per line (for example example.com and www.example.com). Choose Test run (staging) first if you want to practise without using up Let’s Encrypt’s limits.
- Pick the key type (RSA 2048-bit works everywhere; ECDSA P-256 is smaller and faster), tick the Subscriber Agreement box and press Start: create the order.
- For each name, either upload the small file the page shows to /.well-known/acme-challenge/ on your web server, or add the TXT record it shows in your DNS. Wildcard names need the DNS record.
- Open the file address (or look the record up) to make sure it is live, then press Check. Let’s Encrypt checks each name from several places on the internet.
- When every name is verified, the page makes the private key and the certificate request in your browser and downloads the certificate. Save privkey.pem first, then the certificate files — or one password-protected .pfx file for Windows — and add the renewal reminder to your calendar.
- Install the files on your server (nginx, Apache, a hosting control panel or IIS — the page shows how), then check the site with the SSL Certificate Checker.
Examples
example.org www.example.org
Two files to upload to /.well-known/acme-challenge/ → privkey.pem, fullchain.pem, cert.pem and chain.pem
In a control panel, paste cert.pem as the certificate, privkey.pem as the private key and chain.pem as the CA bundle.
*.example.org example.org
Two TXT values for the same name, _acme-challenge.example.org → one certificate for example.org and all its first-level subdomains
Add both values as separate TXT records and keep both until the certificate is issued.
-----BEGIN CERTIFICATE REQUEST----- … (from openssl req)
A certificate for the names in the CSR; no private key is made in the browser
The key stays on the server where you made the CSR. The page checks the CSR’s signature and names before it starts.
Common uses
- Websites on hosting that has no automatic SSL, or where the automatic certificate stopped renewing.
- Small agencies and freelancers setting up a client’s site without shell access to the server.
- Wildcard certificates for internal-facing subdomains whose DNS is public.
- Routers, NAS boxes, mail servers and appliances that accept an uploaded certificate but cannot run a certificate client.
- Trying a certificate set-up end to end on Let’s Encrypt’s staging environment before going live.
How the page gets a certificate
- Account: a new account key (ECDSA P-256) is made in your browser and registered with Let’s Encrypt, with your agreement to the Subscriber Agreement. No e-mail address is asked for: Let’s Encrypt no longer sends expiry e-mails and no longer keeps account e-mail addresses (announcement).
- Order: the page asks for a certificate for your names. Let’s Encrypt answers with one authorization per name and the checks it accepts.
- Checks: for each name you publish a value made from Let’s Encrypt’s token and your account key’s thumbprint (RFC 8555 §8.3 and §8.4), then the page tells Let’s Encrypt it is ready, and waits for the result.
- Certificate: the page makes the certificate key and a certificate signing request (CSR) in your browser, sends the CSR — it holds only the public key — and downloads the chain. It then checks that the certificate covers exactly your names and belongs to your key.
Every request is signed with your account key (a JWS, RFC 7515). The tool talks to no outside service but Let’s Encrypt: the only addresses this page adds to its Content-Security-Policy are Let’s Encrypt’s two ACME servers (production and staging).
File on the web server or DNS record?
The file check (HTTP-01) is easiest when you can upload files to the site: Let’s Encrypt fetches http://<your domain>/.well-known/acme-challenge/<token>. It works only on port 80; Let’s Encrypt follows up to 10 redirects (to http or https on ports 80 and 443) and does not check the certificate of an https page it is redirected to, so an expired certificate does not stop it. It cannot be used for wildcard names.
The DNS check (DNS-01) works for any name whose DNS you can edit, also for wildcards and for servers that are not reachable from the internet: you add a TXT record at _acme-challenge.<your domain>. DNS changes can take a while to be seen everywhere — Let’s Encrypt mentions waiting as much as an hour — so check that the record is visible before you press Check. Several TXT records with the same name are fine; remove old ones when you are done (Let’s Encrypt: challenge types).
Which files go where
- privkey.pem — the private key (PKCS#8). It must stay secret; anyone who has it can pretend to be your site.
- fullchain.pem — your certificate followed by the intermediate certificate. nginx (
ssl_certificate) and Apache 2.4.8 or later (SSLCertificateFile) want this one. - cert.pem and chain.pem — the certificate alone and the intermediate (the “CA bundle”), for forms that ask for them separately, as most hosting control panels do.
- A .pfx file (PKCS #12) — the certificate, its chain and the private key in one file protected by a password you choose, for Windows (IIS), the Windows certificate store, Java and other servers that import a single file. The page makes it with AES-256, as current OpenSSL does by default. Servers that accept only the older Triple DES format, Azure App Service among them, need a file made with OpenSSL instead:
openssl pkcs12 -export -keypbe PBE-SHA1-3DES -certpbe PBE-SHA1-3DES -macalg SHA1 -out certificate.pfx -inkey privkey.pem -in fullchain.pem(Microsoft’s instructions).
The chain comes from Let’s Encrypt with the certificate; do not use an intermediate copied from elsewhere, because Let’s Encrypt changes its intermediates from time to time.
Renewing
Let’s Encrypt certificates are short-lived on purpose — never more than 90 days — and Let’s Encrypt is shortening its default lifetime in steps, to 64 days and then 45 days (announcement); the page shows the exact lifetime of yours. Let’s Encrypt advises renewing when a third of the lifetime is left, and publishes a suggested renewal window for every certificate (ACME Renewal Information, RFC 9773); the page reads that window and puts its start in the calendar file, with a second event on the last day before expiry.
To renew, come back and go through the same steps. If you saved the account key and use it again soon, Let’s Encrypt may skip the checks your account passed recently. Where you can run software on the server, an automatic ACME client is the better choice for the long run: Let’s Encrypt lists no browser-based clients, because renewing by hand makes a missed renewal more likely (client options).
Let’s Encrypt’s limits
Let’s Encrypt limits how much one person can ask for (rate limits), among them:
- 5 failed checks per name per account per hour;
- 5 certificates per 7 days for exactly the same set of names, and 50 per registered domain;
- 300 new orders per account every 3 hours, and 10 new accounts per IP address every 3 hours.
A failed check ends its order, so this page asks you to press Check only once the file or record is live. The staging environment has much higher limits: use Test run (staging) to practise.
Limitations
- You install the certificate yourself and renew it by hand before it expires; if your host offers automatic SSL, or you can run an ACME client such as Certbot on the server, use that instead.
- Keep the tab open from the order until you have downloaded the files: the order and the keys live only in this tab, and the private key cannot be recovered afterwards.
- The file check needs port 80 open to the internet; the DNS check needs access to the domain’s DNS. Wildcard names need the DNS check.
- Domain names only, up to 100 per certificate: Let’s Encrypt issues IP address certificates only as 6-day certificates, which suit automatic renewal, not this page.
- The tool talks only to Let’s Encrypt, so it cannot test your file or DNS record before Let’s Encrypt does: open the file address or use a DNS lookup first.
- A domain whose CAA records name only other certificate authorities cannot get a Let’s Encrypt certificate until a CAA record allows letsencrypt.org.
Privacy
Your private keys — the account key and the certificate key — are made in your browser with Web Crypto and never leave it. The page sends Let’s Encrypt only what an ACME client must: the domain names, the public keys, requests signed with your account key and the certificate request (CSR). No names or keys go to MySmartCoPilot, and nothing is stored in your browser except the choices you made (real or test certificate, key type, file or DNS check).
Frequently asked questions
Is the certificate really free, and who issues it?
Yes. Let’s Encrypt, a non-profit certificate authority, issues it at no cost, and it is trusted by all major browsers. MySmartCoPilot only runs the steps in your browser; you do not need an account here.
Is it safe to make the private key in a browser?
The key is made with your browser’s built-in Web Crypto and stays in this tab’s memory; nothing sends it anywhere, and the tool talks only to Let’s Encrypt. If you prefer the key never to exist outside your server, make a CSR there (for example with the command the CSR Generator gives) and paste it under More options.
My host has a free SSL or AutoSSL button. Do I need this?
No. Hosting that sets up and renews certificates for you is the best option. This page is for hosts and devices where that does not exist or has stopped working.
Why did the check fail?
The page shows Let’s Encrypt’s own message and what usually fixes it. The common causes: 404 — the file is not in /.well-known/acme-challenge/ or has an extension (on IIS, the server may not serve files without one: move the StaticFile handler above the ExtensionlessUrlHandler entries for that folder); timeout or connection refused — port 80 is closed, or an old AAAA (IPv6) record points elsewhere; no TXT record / wrong value — the record is not visible yet or was pasted with quotes; CAA — the domain allows other certificate authorities only. A failed order cannot be checked again: fix the cause and press Start a new order.
Can I get a wildcard certificate?
Yes: enter *.example.com (and example.com too, because the wildcard covers only the names one level below it). Wildcards can only be checked with the DNS record; both names use the same record name, so add both TXT values.
What happens if I close the tab in the middle?
The order is lost, and so is any key you have not downloaded. Start again; if you had saved the account key, choose it under More options and Let’s Encrypt may already accept the names it checked recently for that account.
Can I get a .pfx file for IIS or Windows?
Yes, when the private key was made on this page: on the last step, choose a password and download the .pfx file, which holds the certificate, its chain and the key. In IIS Manager, import it under Server Certificates and choose it for the site’s https binding. It is encrypted with AES-256; for servers that accept only the older Triple DES format, such as Azure App Service, the page gives the OpenSSL command that makes one.
How do I get reminded to renew?
Download the calendar file (.ics) on the last step and open it: it adds the renewal day and the last day before expiry, each with an alarm. Let’s Encrypt sends no expiry e-mails, and a forgotten renewal means visitors see a warning page.
What is the “Test run (staging)” option?
Let’s Encrypt’s staging environment: the same steps and checks with much higher limits, but the certificates are not trusted by browsers. Use it to practise or to test a set-up, then run the real thing.