How does this generator work?
Let’s Encrypt is a non-profit certificate authority that issues free certificates trusted by every browser. To get one, you prove that you control the domain name through the ACME protocol. This is usually done by software installed on the server (Certbot, for example). This generator does the same thing right in your browser, for the cases where you cannot install anything.
- Your keys are created in your browser (WebCrypto): your Let’s Encrypt account key and the certificate’s private key are never sent to our server.
- Your browser talks to Let’s Encrypt directly: account, order, validation, then certificate download.
- Our server is only used to check, before validation, that the file or DNS record is in place. A browser cannot run that check by itself.
- An interruption is not a problem: the order in progress is saved in your browser. Reload the page and you can resume it. The “Erase everything” button deletes this data.
HTTP or DNS: which method?
HTTP validation means placing a small file on your website, in the /.well-known/acme-challenge/ folder. It is the fastest method if you can access the files (cPanel File Manager or FTP) and your site already answers on port 80.
DNS validation means adding a TXT record named _acme-challenge to the domain’s DNS zone. It is required for a wildcard certificate (*.example.com) and works even if the site is not online yet. Allow a few minutes for propagation: our check button tells you when the record is visible. You can also look at your records with our DNS lookup.
Let’s Encrypt’s limits
Let’s Encrypt applies limits to protect its service (figures published in August 2026). Because the requests come from your browser, these limits apply to your own IP address and account:
- 5 certificates at most for exactly the same names every 7 days: the limit people hit when they start over several times;
- 50 certificates per registered domain (example.com and all its subdomains) every 7 days;
- 5 failed validations per name per hour: check before validating;
- 10 new accounts per IP address every 3 hours.
To practise safely, tick “Test certificate”: Let’s Encrypt’s test environment has much wider limits.
Plan the renewal
A Let’s Encrypt certificate is valid for 90 days today. Let’s Encrypt is shortening this step by step: 64 days from February 2027, then 45 days in 2028. Let’s Encrypt no longer sends e-mails before expiry, so add the reminder to your calendar at the end of the process, then come back to generate a new certificate. If you would rather not deal with it, hosting with automatic SSL does it for you: that is the case for the websites we build as part of our website development service.
Read our guide: choosing web hosting (with SSL included).
Are you an agency? We work white-label →
Frequently asked questions
Is the certificate really free?
Yes. It is issued by Let’s Encrypt, a non-profit certificate authority trusted by every browser. Our tool is free too, with no sign-up.
Is my private key sent to IT LABS PRO?
No. It is created in your browser and only leaves it when you download it. Our server only checks that the validation file or DNS record is in place.
How long is the certificate valid?
90 days today. Let’s Encrypt is shortening this: 64 days from February 2027, then 45 days in 2028. You need to renew it regularly, hence the calendar reminder.
Can I get a wildcard certificate?
Yes, with DNS validation: add *.your-domain.com to the list of names, then the TXT record shown to the domain’s DNS zone.
What if validation fails?
Read the message shown: most often the file is not in the right place, or the DNS record has not propagated yet. Fix it, use “Check before validating”, then create a new order.
