Blog

Andrew Moore
Digital Marketing Writer, Domain Industry

How CentralNic Reseller ACME Simplifies SSL Certificate Management Automation

Automated SSL certificate management arrives on 5 October 2026. Here is what it does, how it works, and what it costs.

Back in February we published a guide to the shrinking SSL/TLS certificate lifetime and what it would mean for businesses managing certificates on behalf of other people. The advice was blunt enough. Audit what you have. Turn on automatic renewal wherever it already exists. And well before you actually need it, make sure your provider supports ACME.

That last one was slightly uncomfortable to write, because at the time we did not support it.

As of 5 October 2026, we do. CentralNic Reseller’s ACME SSL protocol is now available. It is designed to answer that big problem by automating the issuance and renewal of Sectigo DV certificates through whichever ACME-compatible client you already run. This article covers what that means in practice, how we’ve changed to a subscription model, which clients work with it, and everything else you need to know.

Grow Your SSL Business

Where SSL Certificate Lifetimes Stand Today

You do not need another article explaining that certificates are getting shorter. The schedule is published, the dates are fixed, and most people reading this have already absorbed the first cut. So here is the timeline once, briefly, and then we will move on to the part that is actually new.

Effective from Maximum certificate validity
March 2026 200 days
March 2027 100 days
March 2029 47 days

Not long ago the ceiling sat just under 400 days. The first reduction halved it, and at 200 days a certificate needs replacing roughly twice a year. That is an irritation rather than a crisis. It goes in a calendar, somebody remembers, the work gets done on a Tuesday afternoon.

From March 2027 it becomes four times a year. Then in March 2029, eight. Individual certificates do not get harder to install. There are simply far more of them, arriving against a portfolio that is probably growing at the same time. Fifty domains producing a hundred renewal events this year will produce four hundred in 2029.

Somewhere between two renewals a year and eight, a manual process stops being an irritation and becomes a liability. Exactly where that line falls depends on how many names you manage and how much of your reputation is tied to none of them going dark on a Sunday. But it falls on everyone eventually, and the dates are not negotiable.

Which is why we said in February that ACME support would stop being optional. And why we have spent the time since building it.

What Is CentralNic Reseller ACME?

ACME stands for Automatic Certificate Management Environment, a name that only makes sense once you already know what the thing does.

In practice it is an open standard, defined in RFC 8555, that lets software on your infrastructure talk directly to a certificate authority with no person in the middle. A client running on your server asks the CA for a certificate covering a domain name. The CA issues a challenge to prove you genuinely control that name. The client answers it, usually by publishing a file over HTTP or a record in DNS. The certificate is issued. And then, before it expires, the client does the whole thing again without being asked.

Which is the entire point of the ACME certificate protocol: handling your SSL certificate issuance and renewal without needing manual human intervention.

CentralNic Reseller ACME applies that protocol to Sectigo DV certificates. Instead of buying and registering an SSL certificate for a domain, which will expire when its validity runs out, the whole thing is handled through a subscription. You subscribe the domain names that need to be covered with a standard or wildcard SSL certificate. Then you connect a compatible ACME client using the Directory URL and External Account Binding credentials we supply, and from then on, the client requests, validates, installs and renews certificates for those names without anyone having to remember to do it. At least until you end the subscription.

It’s a way for you to automate handling the entire SSL certificate lifecycle through your own reseller infrastructure, without having to worry about anything getting dropped or missed.

Key Benefits of Automating SSL Certificate Management with ACME

We’ve laid out the argument for automating your SSL certificates in previous articles, and in the broadest strokes here as well. But it’s worth going through it point by point, because this will become something that while still entirely optional, practically won’t be.

Reduce manual work

Look, requesting, validating, installing and renewing an SSL certificate by hand is not difficult to do. But even if you’re not handling hundreds of certificates at once, it is exactly the type of repetitive process that could benefit from a machine handling it. Leaving you and your staff with more time to handle other projects.

Lower outage risk

Fewer repetitive manual tasks means fewer opportunities for something to go wrong. Plus, an ACME client renews well before expiry, giving it space to try again on its own if something goes wrong. Even then, you’ll have time to spot an issue before it becomes a live problem.

Fit existing workflows

ACME is an open standard, so you are not installing a proprietary agent or rebuilding your stack around us. If you already run an ACME-compatible client, you just point it at a new directory. If you do not, there is almost certainly one already out there that fits your existing infrastructure.

Environment Example compatible clients
Linux and general server automation Certbot, acme.sh, Lego
Windows and IIS win-acme, Certify The Web, Posh-ACME
Kubernetes and container platforms cert-manager, Traefik, Caddy
CI/CD, cloud and container workflows Lego, acme.sh
Private and internal CA automation step CLI (Smallstep)

Simplify certificate purchasing

A subscription means a predictable, annual cost, in line with how domains themselves are purchased and renewed, instead of having to create new orders every 199 days. With CentralNic Reseller ACME you just pay for the domain names you need to cover, and certain related domains can be added for free.

Domain added first Domain added later Additional charge
example.com www.example.com No
*.example.com example.com No
*.shop.example.com example.com Yes
*.shop.example.com www.shop.example.com Yes
www.example.com example.com Yes
example.com *.example.com Yes

What Is Included with CentralNic Reseller ACME?

We’re launching our ACME offering as a subscription with a very focused, very clear set of features that benefit resellers. And there is space to grow over time with more supported certificates and flexible options.

  • Sectigo DV certificates
  • Standard (shop.example.com) and wildcard (*.example.com) coverage
  • 1-, 2- and 3-year subscriptions
  • Unlimited issuance and renewal for subscribed domain names
  • No ACME account or account creation fees
  • Dedicated APIs for account, subscription and domain-coverage management

How the CentralNic Reseller ACME Subscription Works

The simple way to think about it is that you’re no longer buying certificates for a domain name, you’re paying to have a domain name covered by a certificate.

  1. Pre-register an ACME account through the API and choose a one-, two- or three-year term. There is no setup or annual account fee, and nothing is charged at this stage.
  2. Add your first standard or wildcard name. This starts the subscription term, and that name is charged when it is added.
  3. Connect your ACME client using the supplied credentials. This registers your client with Sectigo’s ACME server, bound to your CentralNic Reseller subscription, and allows it to request, validate, install and renew certificates for your subscribed names.
  4. Add more names as you need them. Each new name is priced for its coverage from the day it is added until the subscription’s existing expiration date, and charged at that point. Adding names does not move the end date.
  5. Certificates renew automatically. The ACME protocol handles renewals during the subscription, with no additional charges.
  6. Extend the subscription through the API as the term approaches its end.

The Future of SSL Certificate Automation and ACME Support

With the decreasing lifespan on SSL/TLS certificates, manual processes are going to have to be replaced with automated ones. At CentralNic Reseller, we’ve always created API integrations to make resellers’ lives easier, and their businesses more efficient and more productive. CentralNic Reseller ACME is just the latest step in that process. And we’ve just started on it.

Our first release is deliberately focused: Sectigo DV certificates through a standalone domain subscription. We plan to expand it, adding more certificate authorities, higher validation levels and more subscription models as we go.

And we’re excited to share more details with you as they come.

Get Started with CentralNic Reseller ACME Today

If you read our 47-day SSL/TLS guide in February and added “check ACME support” to a list, you can now cross it off, and get down to adding it to your workflow.

CentralNic Reseller ACME is available now. And it’s robust enough to meet your needs right now, with more capabilities coming in the future. Visit our SSL certificates page to find out more, read the full setup details in the ACME knowledge base, or go straight to the ACME API documentation. And if you want help working out where automation fits in your current setup, our team is ready to talk it through.

Get Started with CentralNic Reseller

FAQ

What is ACME protocol?

ACME (Automatic Certificate Management Environment) is an open standard, defined in RFC 8555, for automated certificate management. It lets your own software request, validate, issue and renew SSL/TLS certificates from a certificate authority without needing manual intervention. Most major certificate authorities, including Sectigo, now support the ACME protocol for automated certificate management.

How does CentralNic Reseller ACME automate SSL certificate management?

It replaces individually ordering SSL certificates with a subscription. Just choose the domain names you want covered and connect a compatible client to the ACME servers. The client then requests, validates, installs and renews Sectigo DV certificates for those names automatically while the subscription is active.

Which SSL certificates are supported by CentralNic Reseller ACME?

At launch, CentralNic Reseller ACME supports Sectigo Domain Validation (DV) certificates for standard and wildcard domain names, each valid for up to 90 days. Additional certificate authorities and validation levels are planned for future releases.

Why is SSL certificate automation important for domain resellers?

Resellers manage certificates across many names for many customers. As SSL certificate lifetimes reduce over the next few years, the number of renewals you will have to do per domain, every year, will skyrocket. Automation keeps that volume manageable.

How can your business benefit from ACME automation?

ACME automation will help your business on multiple fronts. Starting with spending less time on routine certificate work, which means fewer outages caused by missed renewals, which leads to happier clients and less stressed staff. Plus, subscriptions are more predictable for your books than ad hoc certificate renewals.

What are the risks of managing SSL certificates manually?

When SSL certificate management is a manual task, it can be missed or delayed. Downstream of that, an expired certificate means browser warnings and lost visitors for your clients. Manual installation also invites human error. As lifetimes shorten, the number of chances to get something wrong grows with them.

How does ACME help reduce operational overhead?

ACME removes per-certificate tasks from your team’s workload. Instead of placing orders, completing validations and installing certificates by hand, you manage which names are covered and let the client handle the rest.

You may also like