Sovereign Certificate Authority

The Sovereign Certificate Authority is an internal certificate authority that brings the Let’s Encrypt experience to your own network — same ACME protocol, same standard clients, no public Certificate-Transparency-log exposure of internal hostnames.

In this section

  • ACME clients — How to point standard clients (certbot, acme.sh, lego, Caddy, Traefik) at the internal CA, plus the few small differences from public-CA workflows.

At a glance

  • Protocol — ACME (RFC 8555) — identical to Let’s Encrypt.
  • Coverage — Internal domains, .local zones, service-mesh mTLS, employee-device client certificates.
  • Renewal — Automatic every 60–90 days, like Let’s Encrypt.
  • CT-log exposure — None. Internal hostnames stay internal.

For the business case, see the Sovereign Certificate Authority portfolio entry.