ACME automation
14+ issuers, live workflow state, DNS-01, and certificate tokens for HAProxy, win-acme, and every RFC 8555 client.
Curiosity Compliance Audit · PASSED
You scanned a sticker with a giant question mark. Respect.
This QR was not malware. We know that is disappointing at a conference.
Incident status
NXDOMAIN on a TXT record. CertLocker runs ACME across major issuers, keeps certs in one place, and issues just-in-time SSH so access is not a PEM file in a wiki.
Or jump straight to the 2am ACME walkthrough →What we actually do
Everything below is on certlocker.io — pick a rabbit hole. No spreadsheet required.
14+ issuers, live workflow state, DNS-01, and certificate tokens for HAProxy, win-acme, and every RFC 8555 client.
Scoped tokens so edges pull the right PEM, chain, and key — no SCP mystery folders.
See what production is actually serving, not just what inventory claims.
PEM material, credentials, and configs with the same RBAC and audit as certificates.
Token-scoped, time-limited bastion access — including a browser terminal on your phone.
For your boss (copy-paste)
We found a mystery QR at the conference. CertLocker centralizes TLS lifecycle and ACME across issuers, plus scoped SSH access — fewer shared keys and fewer renewal surprises.
Blog · certlocker.io · DNS TXT records are enough suffering for one day.