Auto SSL Sectigo ACME
Auto SSL: Sectigo certificates that renew themselves
A per-domain subscription. Paste the keys into the ACME client on your server once — from then on certificates are issued and renewed without you.
Price per domain per year. Wildcard *.domain.kz — $112.50 per year.
Why Auto SSL
-
Nothing to renew by hand
Each certificate lives about 90 days, and the client on your server replaces it ahead of time. No reminders, no expired certificates, no "the site is down" on a Monday morning.
-
Sectigo, a commercial certificate authority
Certificates are issued by Sectigo, one of the largest CAs in the world. Right for cases where a customer or a security team requires a commercial certificate rather than a free one.
-
As many servers as you need
You pay per domain, not per server. A load balancer, two web servers and a staging box on one domain — one subscription.
-
Help in Russian and Kazakh
We will help you connect certbot, acme.sh, ISPmanager, FastPanel, cPanel, BitrixVM or IIS. Payment in tenge, closing documents for companies.
How it works
-
Subscribe
Enter your domains and pay. Your client area will show the ACME server address and two keys.
-
Paste the keys into a command
One command on the server registers your ACME client with the keys. Then request a certificate as usual.
-
Certificates are issued and renewed automatically
The client watches the expiry date and replaces the certificate ahead of time. You do nothing.
Example for acme.sh
# 1. Register the client — once, values from the client area
acme.sh --register-account \
--server https://acme.sectigo.com/v2/DV \
--eab-kid YOUR_EAB_KID \
--eab-hmac-key YOUR_EAB_HMAC_KEY
# 2. Issue a certificate — from now on acme.sh renews it by itself
acme.sh --issue --server https://acme.sectigo.com/v2/DV \
-d example.kz -d www.example.kz \
-w /var/www/example.kz This is an example: replace YOUR_EAB_KID and YOUR_EAB_HMAC_KEY with the values from your client area (Auto SSL service → "Set up"). Separate guides cover certbot, ISPmanager, FastPanel, cPanel, BitrixVM and IIS.
Setup guides
Right for you if…
- you run your own VPS or dedicated server and install certificates yourself;
- you have several domains or servers and are tired of tracking expiry dates;
- a customer, a tender or a security team requires a commercial certificate authority;
- your project runs on Bitrix, on BitrixVM or a separate server;
- you use Kubernetes, Docker, Caddy or Traefik and certificates must be obtained without a human.
Comparison
| Comparison | Let's Encrypt | Regular one-year SSL | Auto SSL |
|---|---|---|---|
| Certificate authority | Let's Encrypt, free | Sectigo and other commercial CAs | Sectigo, commercial |
| Renewal | Automatic | Manual, once a year | Automatic |
| Installation | ACME client | Manual | ACME client |
| Servers per domain | Unlimited | Per licence | Unlimited |
| Issuance limits | Yes | No | No |
| Setup support | No | Yes | Yes, guides for each panel |
| Closing documents | No | Yes | Yes |
| Price | $0 | Depends on the certificate | $31.25 per domain per year |
Plan
Auto SSL
$31.25 per domain per year
- Sectigo certificates, issued in minutes
- Automatic, free renewal — as many times as needed
- www and non-www count as one domain
- Unlimited servers
- Guides and 24/7 support
Auto SSL Wildcard
$112.50 per *.domain.kz per year
- All subdomains of one domain
- Domain is verified through a DNS record — requires access to the domain's DNS
- For domains on ns1/ns2.1host.kz we will help with the records
FAQ
What is ACME?
An open protocol that lets a server talk to a certificate authority on its own: prove the domain is yours, obtain a certificate and renew it. It is used by Let's Encrypt and by commercial CAs, including Sectigo. All you need is a client program on the server.
How is this different from Let's Encrypt?
Same protocol, different CA. Certificates are issued by Sectigo, a commercial certificate authority with a warranty and no issuance limits. On top of that you get our support, payment in tenge and accounting documents. If Let's Encrypt is enough for you, keep using it — that is perfectly fine.
Which client do I need?
Any client that supports ACME with external account binding (EAB): certbot, acme.sh, win-acme for Windows, Caddy, Traefik, cert-manager for Kubernetes, and the built-in tools of ISPmanager, FastPanel and cPanel. There is a guide for each in our knowledge base.
Where do I get the keys?
In your client area after payment: the "Set up" button next to the service. It shows the Server URL, EAB MAC ID and EAB MAC key. You paste them into the client registration command once; after that the client works on its own.
Can I get a wildcard?
Yes, *.domain.kz is a separate item. For wildcards the CA verifies the domain through a DNS record, so the client needs access to the domain's DNS. If the domain is hosted on our ns1/ns2.1host.kz, we will help you set it up.
How many servers can I use it on?
As many as you like. You pay per domain; the server licence is unlimited.
What happens if I do not renew the subscription?
New certificates will stop being issued. Certificates already issued will run until they expire — about 90 days. To keep the site covered, renew the subscription before the last certificate expires. We will remind you in advance.
Who will help me set it up?
ONEHOST support, around the clock, in Russian and Kazakh. The knowledge base has step-by-step guides for certbot, acme.sh, ISPmanager, FastPanel, cPanel, BitrixVM and IIS.
Set it up once — and forget about certificate renewals
Auto SSL — $31.25 per domain per year. Sectigo certificates, unlimited servers, 24/7 support.
Order Auto SSL