Trustico® Certificate as a Service (CaaS) automates the entire SSL Certificate lifecycle through the industry-standard Automatic Certificate Management Environment (ACME) protocol.
It removes manual SSL Certificate ordering, validation steps, and the need to track expiry dates. With this service-based model, you pay per domain and receive unlimited SSL Certificates, fully automated.
Trustico® Certificate as a Service (CaaS) in Practice
When you purchase Trustico® Certificate as a Service (CaaS), you receive External Account Binding (EAB) credentials that connect your ACME client to your pre-paid service.
These credentials include your EAB Key ID as your unique account identifier, your EAB MAC Key as your secure authentication key, and your dedicated ACME Server URL.
Configure your preferred ACME client such as Certbot, acme.sh, Lego, or any ACME-compatible tool with these credentials, and you are ready to go. Your client will then automatically request and install SSL Certificates for any domains in your service, with no manual intervention.
Tip : If your website runs on cPanel, the Trustico® Certificate as a Service (CaaS) cPanel Plugin brings automated SSL Certificate management directly into your hosting control panel, without the command line. It retrieves, installs, and reissues your SSL Certificates from within cPanel itself. Explore the Trustico® cPanel Plugin 🔗
On cPanel hosting, the plugin sets up and runs the ACME client for you, so the steps above are handled automatically.
Complete Automation Benefits
Trustico® Certificate as a Service (CaaS) eliminates all manual processes from SSL Certificate management. There is no need to generate Certificate Signing Requests (CSRs), handle approval e-mails, or track expiry dates.
Your ACME client handles domain validation and SSL Certificate issuance automatically for as long as your paid service is active.
SSL Certificates install automatically before expiration, ensuring your websites and applications never experience downtime due to expired SSL Certificates. This hands-off approach saves a great deal of administrative work while reducing human error.
Associated Fully Qualified Domain Name (FQDN) Included Free
We recommend excluding the www part of the domain during our ordering process as we will include it free of charge as an associated Fully Qualified Domain Name (FQDN) during the activation process.
Predictable Pricing Model
Trustico® Certificate as a Service (CaaS) uses a simple fee structure per domain, making budgeting straightforward and predictable. Each service covers one primary domain along with any associated free additional domains, such as www subdomains for root domains or subdomains when using wildcard SSL Certificates.
Once you purchase a domain service, you can issue via your ACME client, unlimited SSL Certificates for that domain and its included variations without additional costs per SSL Certificate.
This means you can secure your primary domain, www version, and any subdomains covered by wildcard SSL Certificates under a single service.
If you need to secure additional domains beyond your current service simply purchase its own separate Trustico® Certificate as a Service (CaaS) with dedicated credentials and management.
This transparent pricing model removes surprise costs and makes financial planning easier for growing businesses by providing clear, predictable costs for each domain you need to protect.
Keeping Your Service Active
Automated SSL Certificate installation and management through Trustico® Certificate as a Service (CaaS) operates seamlessly only while your paid service remains active.
Your ACME client will continue to automatically reissue SSL Certificates and maintain continuous protection as long as your service subscription is current.
To ensure truly seamless SSL Certificate management without interruption, keep your Trustico® Certificate as a Service (CaaS) license current before it expires, or set up automatic billing for uninterrupted service continuity.
If your service expires, your ACME client will be unable to reissue SSL Certificates, potentially leading to SSL Certificate expiration and website downtime until service is restored.
Unlimited Flexibility
Your Trustico® Certificate as a Service (CaaS) provides unlimited SSL Certificates per domain service, making it perfect for complex infrastructure needs.
Secure multiple servers, development environments, staging systems, and production applications all under one service.
The service fits into existing infrastructure and deployment pipelines. Whether you are running load balancers, failover systems, or distributed applications, Trustico® Certificate as a Service (CaaS) scales with your architecture without extra complexity or cost.
Enterprise-Ready Security
Trustico® Certificate as a Service (CaaS) is built on the industry-standard ACME protocol, ensuring compatibility with existing security frameworks and tools.
The automated reissue process maintains continuous protection without the security gaps that can occur with manual SSL Certificate management.
Your EAB credentials provide secure access to your service while maintaining the flexibility to use multiple ACME clients across different systems. This approach supports enterprise security requirements while simplifying SSL Certificate operations.
Domain Validation SSL Certificates
Trustico® Certificate as a Service (CaaS) offers Domain Validation (DV) SSL Certificates with fast issuance through automated domain validation. These SSL Certificates provide standard encryption suitable for most web applications and services. Learn About The Validation Procedure 🔗
These SSL Certificates are ideal for websites, services, and applications where quick deployment and automatic management are priorities. The automated validation process typically completes within minutes, allowing for rapid SSL Certificate deployment.
Organization Validation SSL Certificates
For businesses requiring enhanced trust indicators, Trustico® Certificate as a Service (CaaS) supports Organization Validation (OV) SSL Certificates.
These SSL Certificates include verified organization information, making them ideal for customer-facing business applications and corporate websites.
These SSL Certificates keep the same automated management as Domain Validation (DV) SSL Certificates, while adding the trust signals that business customers expect.
The ACME protocol handles the technical aspects while maintaining the enhanced validation standards.
Getting Started with Trustico® Certificate as a Service (CaaS)
Getting started with Trustico® Certificate as a Service (CaaS) begins with purchasing the service for the domains you need to secure.
After completing your purchase we will create and send your Trustico® ACME Account and associated EAB credentials via e-mail, including your EAB Key ID, EAB MAC Key, and ACME Server URL. Learn About External Account Binding (EAB) Credentials 🔗
Configure your preferred ACME client with the provided credentials and server address. Once configured, request your first SSL Certificate to confirm everything is working. Learn About The ACME Protocol 🔗
From that point forward, your ACME client handles all SSL Certificate operations automatically, keeping your domains continuously secured.
Service Management
Your Trustico® Certificate as a Service (CaaS) adapts to your changing needs throughout the service period.
Visit our website and extend your service prior to service expiration to ensure uninterrupted service for your critical applications.
Your Trustico® ACME Account ID serves as your unique identifier for all service management tasks, whether handled through our website, Application Programming Interface (API), or customer service team.
We are working on the ability to add new domains at any time, with pro-rated pricing that charges only for the remaining service time. This page will be updated as that becomes available.
Security Best Practices
Your EAB credentials are the secure keys to your Trustico® Certificate as a Service (CaaS) and require proper protection.
Store these credentials in environment variables or secure credential management systems, treating them with the same security standards as API keys or passwords.
Never store EAB credentials in code repositories or unencrypted files.
The same credentials can be used across multiple ACME clients when needed, allowing you to secure multiple servers with a single Trustico® Certificate as a Service (CaaS) while maintaining security best practices.
Reasons to Choose Trustico® Certificate as a Service (CaaS)
Traditional SSL Certificate management involves manual ordering, the need to track expiry dates, time-consuming validation, and unpredictable SSL Certificate costs. Compare Traditional SSL Certificates 🔗
These manual processes create opportunities for human error and SSL Certificate expiration incidents that can cause website downtime.
Trustico® Certificate as a Service (CaaS) replaces that experience with full automation from start to finish.
You avoid expired SSL Certificates, get fast validation and issuance, benefit from predictable pricing, and fit neatly into your existing workflows.
Moving to Automated SSL Certificate Management
Trustico® Certificate as a Service (CaaS) brings automation, predictability, and flexibility together in a single approach to SSL Certificate management.
Choose your domains, configure your ACME client, and let automation handle the rest.
Move to automated SSL Certificate management and join the organizations that have removed manual SSL Certificate work.
Our support team is ready to help you implement Trustico® Certificate as a Service (CaaS) for your infrastructure needs.