Skip to main content
Server & DevOpsSeptember 30, 20264 min read

Will Your ACME Client Work With Cloudflare's New Free CA?

Get technical support

Patched, monitored, restored on a schedule

Cloudflare plans a free public certificate authority that will only issue to ACME clients supporting ARI, the renewal extension in RFC 9773. certbot, acme.sh, lego and Caddy support it, cert-manager keeps it behind an off-by-default flag, and Traefik does not use it.

What Cloudflare Announced

On September 29, 2026, Cloudflare said it is building a publicly trusted certificate authority that will hand out free TLS certificates. It is not issuing yet, and it gives no date for the first ordinary certificate. It has applied to the Chrome, Apple, Microsoft and Mozilla root programs, and it has signed an agreement to acquire an established root from GlobalSign that has been trusted since 2012.

Issuance will go through ACME only, the protocol Let's Encrypt popularized. Cloudflare's pitch is that a site already using a free CA can move by changing one directory URL. Its reasoning is resilience. Cloudflare points out that most of the free, automated certificate model runs through a single operator, and argues that a second free CA gives the web somewhere to go if that operator has a bad week.

A companion post covers Merkle Tree Certificates, a new certificate format designed for the post-quantum era. Cloudflare expects to issue the first of those in the first quarter of 2027, from ACME software based on Let's Encrypt's own Boulder.

The Condition That Decides Whether You Can Use It

Cloudflare will only issue to clients that support ACME Renewal Information, or ARI, which the IETF standardized as RFC 9773 in June 2025. A subscriber's automation has to poll Cloudflare's renewal endpoint, act on the renewal windows it publishes, and say which certificate each new order replaces.

ARI turns renewal timing into something the CA can steer. For every certificate, the client asks a renewalInfo URL when it should renew and gets back a suggested window. When it orders the replacement, it names the old certificate in a replaces field. The practical benefit shows up in an incident. If a CA has to revoke certificates in bulk, it can pull their renewal windows forward, and clients that follow ARI replace them before anything breaks.

Which Clients Are Ready

ClientARI supportDefault
certbotsince 4.1.0, June 2025on, checked by certbot renew
acme.shsince 3.1.4, July 2026on, NO_ARI=1 turns it off
legosince v4.12.0, replaces since v4.16.0on in the CLI since v4.20.2
Caddysince 2.8.0, May 2024on
cert-managersince v1.21.0, July 2026off, behind the ACMEUseARI feature gate
win-acmedraft version since 2.2.3on, last updated to draft 3 in 2024
Traefiknot supportedrenews on its own schedule

Two rows deserve a second look. Traefik is built on lego, but its certificate resolver does not use lego's ARI support and has no renewal-information code of its own, so it keeps renewing on the interval set by certificatesDuration. And cert-manager, the usual choice on Kubernetes, supports ARI only as an alpha feature that is switched off unless you enable the gate.

For cPanel's AutoSSL and Plesk's certificate tools, we found no documentation of ARI support. On those servers the panel handles renewals, so the answer will come from the vendor's release notes.

Why ARI Is Worth Turning On Anyway

The Cloudflare CA is not the only reason. Let's Encrypt is shortening its certificates. Its default profile moves to 64-day certificates on February 10, 2027 and to 45-day certificates on February 16, 2028, and it warns that a hardcoded 60-day renewal interval will no longer be enough. Its recommendation is ARI, and its rate-limit rules exempt renewals made through ARI from all limits, as long as the new order shares at least one name with the certificate it replaces and that certificate has not already been replaced.

So a fleet that renews on a fixed timer is heading for trouble either way, and the fix is the same.

What to Do Now

  1. Find every client that issues certificates, not just the obvious one. Servers, ingress controllers, load balancers and control panels often each run their own.
  2. Upgrade to a version with ARI. That means certbot 4.1 or later, acme.sh 3.1.4 or later, lego v4.20.2 or later, or Caddy 2.8 or later.
  3. On Kubernetes, cert-manager v1.21 or later can use ARI once ACMEUseARI is enabled. Try it on a staging issuer first, since it is still alpha.
  4. On Traefik, watch its release notes, or move certificate issuance to a client that supports ARI if you plan to use Cloudflare's CA.
  5. Do not switch CAs yet. Cloudflare has not started issuing, so there is nothing to point a client at today.

Running certificates across many domains is a subject of its own, covered in How to Automate Certificates for Hundreds of Client Domains, and keeping renewal automation healthy is part of Servers Management.

Sources

Or read how we handle it in Servers Management.