Integrations

Certificates deployed where you already run

LapseZero issues certificates from Let's Encrypt, renews them before they expire, and deploys them to your servers and cloud products automatically. It works with 8 DNS providers, 14 deployment targets and 7 notification channels.

DNS providers (8)

Connect your DNS provider and LapseZero handles domain validation for you. With Alibaba Cloud, Tencent Cloud and AWS, the same credentials also deploy to their cloud products.

DNS hosted somewhere else? Add one CNAME record instead. It works with any DNS host and needs no DNS credentials. See DNS delegation.

ProviderUsed forCredentials
Alibaba Cloud logo
Alibaba Cloud (Alibaba Cloud DNS)
DNS + Cloud deploymentAccessKey ID / AccessKey Secret
Tencent Cloud logo
Tencent Cloud (DNSPod)
DNS + Cloud deploymentSecretId / SecretKey
Cloudflare logo
Cloudflare
DNSAPI Token
AWS logo
AWS (Route 53)
DNS + Cloud deploymentAccess Key ID / Secret Access Key
Huawei Cloud logo
Huawei Cloud DNS
DNSAccess Key ID / Secret Access Key
GoDaddy logo
GoDaddy
DNSAPI Key / API Secret
Volcengine logo
Volcengine TrafficRoute
DNSAccess Key ID / Secret Access Key
Google Cloud logo
Google Cloud DNS
DNSService Account JSON Key

Deployment targets (14)

After every issuance and renewal, LapseZero uploads the new certificate and switches your resources to it. No more logging in to each console to replace certificates by hand.

TargetWhat gets updatedPermissions used
SSH serverCertificate and key files at the paths you choose, written over SFTP. An optional command runs afterwards.An SSH account (password or private key) on the host
Alibaba Cloud CDNThe HTTPS certificate of a CDN domain.
  • cdn:DescribeUserDomains
  • cdn:SetCdnDomainSSLCertificate
Alibaba Cloud CLB (formerly SLB)Uploaded as a CLB server certificate and set on an HTTPS listener.
  • slb:DescribeLoadBalancers
  • slb:DescribeLoadBalancerHTTPSListenerAttribute
  • slb:UploadServerCertificate
  • slb:SetLoadBalancerHTTPSListenerAttribute
  • slb:DescribeServerCertificates
  • slb:DescribeRules
  • slb:CreateDomainExtension
  • slb:SetDomainExtensionAttribute
Alibaba Cloud ALBUploaded to Certificate Management Service and set as the listener's default certificate.
  • alb:ListLoadBalancers
  • alb:ListListeners
  • alb:GetListenerAttribute
  • alb:UpdateListenerAttribute
  • alb:ListListenerCertificates
  • alb:AssociateAdditionalCertificatesWithListener
  • alb:DissociateAdditionalCertificatesFromListener
  • cas:UploadUserCertificate
  • cas:GetUserCertificateDetail
Alibaba Cloud DCDNThe HTTPS certificate of a DCDN domain.
  • dcdn:DescribeDcdnUserDomains
  • dcdn:SetDcdnDomainSSLCertificate
Alibaba Cloud WAF 3.0Uploaded to WAF and set as the certificate of a protected domain.
  • yundun-waf:DescribeInstance
  • yundun-waf:DescribeDomains
  • yundun-waf:CreateCerts
  • yundun-waf:ModifyDomainCert
Alibaba Cloud OSSThe certificate of a custom domain bound to a bucket.
  • oss:ListBuckets
  • oss:GetBucketCname
  • oss:PutBucketCname
Tencent Cloud CDNUploaded to Tencent Cloud SSL Certificates and set on a CDN domain.
  • ssl:UploadCertificate
  • cdn:DescribeDomains
  • cdn:DescribeDomainsConfig
  • cdn:ModifyDomainConfig
Tencent Cloud CLBUploaded to Tencent Cloud SSL Certificates and set on an HTTPS listener.
  • ssl:UploadCertificate
  • clb:DescribeLoadBalancers
  • clb:DescribeListeners
  • clb:ModifyListener
  • clb:ModifyDomainAttributes
  • clb:DescribeTaskStatus
Tencent Cloud EdgeOneUploaded to Tencent Cloud SSL Certificates and set on an EdgeOne domain.
  • ssl:UploadCertificate
  • teo:DescribeZones
  • teo:DescribeAccelerationDomains
  • teo:ModifyHostsCertificate
Amazon CloudFrontImported into ACM in us-east-1 and set as the distribution's viewer certificate.
  • acm:ImportCertificate
  • acm:ListCertificates
  • acm:GetCertificate
  • cloudfront:GetDistribution
  • cloudfront:UpdateDistribution
  • cloudfront:ListDistributions
AWS Application Load BalancerImported into ACM in the listener's region and set as the HTTPS listener's default certificate.
  • acm:ImportCertificate
  • acm:ListCertificates
  • acm:GetCertificate
  • acm:DescribeCertificate
  • elasticloadbalancing:DescribeLoadBalancers
  • elasticloadbalancing:DescribeListeners
  • elasticloadbalancing:ModifyListener
  • elasticloadbalancing:DescribeListenerCertificates
  • elasticloadbalancing:AddListenerCertificates
  • elasticloadbalancing:RemoveListenerCertificates
AWS Network Load BalancerImported into ACM in the listener's region and set as the TLS listener's default certificate.
  • acm:ImportCertificate
  • acm:ListCertificates
  • acm:GetCertificate
  • acm:DescribeCertificate
  • elasticloadbalancing:DescribeLoadBalancers
  • elasticloadbalancing:DescribeListeners
  • elasticloadbalancing:ModifyListener
  • elasticloadbalancing:DescribeListenerCertificates
  • elasticloadbalancing:AddListenerCertificates
  • elasticloadbalancing:RemoveListenerCertificates
Amazon API GatewayImported into ACM (us-east-1 for edge-optimized REST APIs, otherwise the API's region) and set on the custom domain name.
  • acm:ImportCertificate
  • acm:ListCertificates
  • acm:GetCertificate
  • apigateway:GET /domainnames
  • apigateway:PATCH /domainnames/*
  • apigatewayv2:GetDomainNames
  • apigatewayv2:GetDomainName
  • apigatewayv2:UpdateDomainName
  • Grant just the actions above to a sub-account. For an Alibaba Cloud or Tencent Cloud key used only for deployment, also add alidns:DescribeDomains or dnspod:DescribeDomainList, which LapseZero uses to check the key when you save it.

SSH deployment

  • Sign in with a password or private key. The connection is tested when you save the host.
  • Ready-made file layouts for Nginx, Apache, HAProxy and Tomcat (PKCS#12), written over SFTP to the paths you choose.
  • Files are updated in place, so ownership and symlinks stay as they are. An optional command such as a reload runs once all files are written.
  • If a write or the command fails, the original files are restored automatically and your server keeps serving the current certificate. You are notified either way.

Notification channels (7)

Get notified where your team already works when a certificate is issued, deployed or about to expire, or when something needs your attention. Each channel picks the events it receives.

EmailWebhookDingTalkFeishu / LarkWeComSlackTelegram

Certificate authority

  • Certificates are issued by Let's Encrypt, trusted by all major browsers, with an RSA 2048 key generated for you. No CSR needed.
  • Need a copy for somewhere else? Download the certificate and key in Nginx, Apache, Tomcat, IIS (PFX) or HAProxy format.