Integrations
Certificates deployed where you already run
LapseZero issues certificates from Let's Encrypt, renews them before they expire, and deploys them to your servers and cloud products automatically. It works with 8 DNS providers, 14 deployment targets and 7 notification channels.
DNS providers (8)
Connect your DNS provider and LapseZero handles domain validation for you. With Alibaba Cloud, Tencent Cloud and AWS, the same credentials also deploy to their cloud products.
DNS hosted somewhere else? Add one CNAME record instead. It works with any DNS host and needs no DNS credentials. See DNS delegation.
| Provider | Used for | Credentials |
|---|---|---|
| DNS + Cloud deployment | AccessKey ID / AccessKey Secret | |
| DNS + Cloud deployment | SecretId / SecretKey | |
| DNS | API Token | |
| DNS + Cloud deployment | Access Key ID / Secret Access Key | |
| DNS | Access Key ID / Secret Access Key | |
| DNS | API Key / API Secret | |
| DNS | Access Key ID / Secret Access Key | |
| DNS | Service Account JSON Key |
Deployment targets (14)
After every issuance and renewal, LapseZero uploads the new certificate and switches your resources to it. No more logging in to each console to replace certificates by hand.
| Target | What gets updated | Permissions used |
|---|---|---|
| SSH server | Certificate and key files at the paths you choose, written over SFTP. An optional command runs afterwards. | An SSH account (password or private key) on the host |
| Alibaba Cloud CDN | The HTTPS certificate of a CDN domain. |
|
| Alibaba Cloud CLB (formerly SLB) | Uploaded as a CLB server certificate and set on an HTTPS listener. |
|
| Alibaba Cloud ALB | Uploaded to Certificate Management Service and set as the listener's default certificate. |
|
| Alibaba Cloud DCDN | The HTTPS certificate of a DCDN domain. |
|
| Alibaba Cloud WAF 3.0 | Uploaded to WAF and set as the certificate of a protected domain. |
|
| Alibaba Cloud OSS | The certificate of a custom domain bound to a bucket. |
|
| Tencent Cloud CDN | Uploaded to Tencent Cloud SSL Certificates and set on a CDN domain. |
|
| Tencent Cloud CLB | Uploaded to Tencent Cloud SSL Certificates and set on an HTTPS listener. |
|
| Tencent Cloud EdgeOne | Uploaded to Tencent Cloud SSL Certificates and set on an EdgeOne domain. |
|
| Amazon CloudFront | Imported into ACM in us-east-1 and set as the distribution's viewer certificate. |
|
| AWS Application Load Balancer | Imported into ACM in the listener's region and set as the HTTPS listener's default certificate. |
|
| AWS Network Load Balancer | Imported into ACM in the listener's region and set as the TLS listener's default certificate. |
|
| Amazon API Gateway | Imported into ACM (us-east-1 for edge-optimized REST APIs, otherwise the API's region) and set on the custom domain name. |
|
- Grant just the actions above to a sub-account. For an Alibaba Cloud or Tencent Cloud key used only for deployment, also add
alidns:DescribeDomainsordnspod:DescribeDomainList, which LapseZero uses to check the key when you save it.
SSH deployment
- Sign in with a password or private key. The connection is tested when you save the host.
- Ready-made file layouts for Nginx, Apache, HAProxy and Tomcat (PKCS#12), written over SFTP to the paths you choose.
- Files are updated in place, so ownership and symlinks stay as they are. An optional command such as a reload runs once all files are written.
- If a write or the command fails, the original files are restored automatically and your server keeps serving the current certificate. You are notified either way.
Notification channels (7)
Get notified where your team already works when a certificate is issued, deployed or about to expire, or when something needs your attention. Each channel picks the events it receives.
Certificate authority
- Certificates are issued by Let's Encrypt, trusted by all major browsers, with an RSA 2048 key generated for you. No CSR needed.
- Need a copy for somewhere else? Download the certificate and key in Nginx, Apache, Tomcat, IIS (PFX) or HAProxy format.