# 🪄 Get a Real Certificate Without Buying a Domain

**URL:** <https://onehack.st/t/get-a-real-certificate-without-buying-a-domain/323544>\
**Category:** Tutorials & Methods\
**Tags:** freebies, tips-tricks\
**Created:** [July 2, 2026, 3:16am UTC](https://onehack.st/t/get-a-real-certificate-without-buying-a-domain/323544 "2026-07-02T03:16:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BCBC](https://onehack.st/user_avatar/onehack.st/bcbc/32/174133_2.png) [@BCBC](https://onehack.st/u/BCBC)\
**Post date:** [July 2, 2026, 3:16am UTC](https://onehack.st/t/get-a-real-certificate-without-buying-a-domain/323544/1 "2026-07-02T03:16:16Z")

</div>

# 🔐 Free Trusted Certs for EVERYTHING You Own

_Public sites, private 192.168 boxes, wildcards, routers, no-domain machines. All free, all auto-renewing._

`verified` · `linux` · `homelab`

* * *

 ![image](https://onehack.st/uploads/default/original/3X/d/f/df5e69ca7081e6a4524929fd37540a16ac1fab80.jpeg)

* * *

**Why care:** browsers and apps now break on plain HTTP. The green 🔒 stops the “Not Secure” nag on your NAS/Proxmox/cameras — free, forever. The trick nobody spells out: prove ownership with a **DNS record** , not an open port, and you can cert boxes the internet can’t even reach.

* * *

> **🕳️ The one switch that certs unreachable boxes**
>
> Port-80 validation (HTTP-01) dies behind NAT. **DNS-01** = drop a `_acme-challenge` TXT record instead → box never exposed, and it’s the _only_ way to get a **wildcard** (`*.example.com` = one cert, every subdomain).
> 
> ```bash
> certbot certonly --dns-cloudflare \
> --dns-cloudflare-credentials ~/.secrets/cf.ini \
> -d "*.home.example.com" -d home.example.com
> 
> ```
> 
> > 💡 Scope the DNS token to **edit-only**. Leak = attacker edits records, can’t steal the box.

> **🧨 Lighter than Certbot — one client per job**
>
> | Tool | For | Link |
> | --- | --- | --- |
> | **acme.sh** | Shell, no Python, wildcards | [git](https://github.com/acmesh-official/acme.sh) |
> | **Caddy** | Web server that certs itself | [site](https://caddyserver.com) |
> | **uacme** | Routers / OpenWRT / embedded | [git](https://github.com/ndilieto/uacme) |
> | **win-acme** | Windows / IIS `.exe` | [git](https://github.com/PKISharp/win-acme) |
> | **lego** | One Go binary, 100+ DNS APIs | [git](https://github.com/go-acme/lego) |
> 
> ```bash
> acme.sh --issue --dns dns_cf -d example.com -d '*.example.com'
> acme.sh --install-cert -d example.com \
> --fullchain-file /etc/nginx/ssl/full.pem --key-file /etc/nginx/ssl/key.pem \
> --reloadcmd "systemctl reload nginx"
> 
> ```
> 
> > 💡 Full client list: [acmeclients.com](https://acmeclients.com).

> **🪄 Real cert, no domain bought**
>
> **Tailscale** → real LE cert on `*.ts.net`: `sudo tailscale cert nas.tailnet.ts.net` ([docs](https://tailscale.com/docs/how-to/set-up-https-certificates)).  
> **DuckDNS** → free subdomain that does DNS-01, so you get a public wildcard:
> 
> ```bash
> acme.sh --issue --dns dns_duckdns -d you.duckdns.org -d '*.you.duckdns.org'
> 
> ```

> **🏠 Your own Let's Encrypt for the LAN**
>
> [step-ca](https://github.com/smallstep/certificates) runs a private ACME server → internal boxes auto-renew from _your_ CA, offline, any hostname. Trust once: `step certificate install root_ca.crt`.  
> Instant lab certs, zero config → [mkcert](https://github.com/FiloSottile/mkcert):
> 
> ```bash
> mkcert -install
> mkcert nas.home "*.home" localhost 127.0.0.1
> 
> ```
> 
> > 💡 Guard `rootCA-key.pem` — it can sign anything.

> **🎛️ 5-line HTTPS that renews itself**
>
> [Caddy](https://caddyserver.com), whole public site:
> 
> ```plaintext
> example.com { reverse_proxy localhost:3000 }
> 
> ```
> 
> Internal box, real HTTPS, no warning: add `tls internal`. `sudo caddy trust` installs its root. Staples OCSP by default.

> **🕵️ DNS-01 without keys living on the box**
>
> [acme-dns](https://github.com/joohoi/acme-dns) = tiny DNS server that only answers `_acme-challenge`. Box holds creds for **one** TXT record, nothing else (EFF-endorsed). Set once:
> 
> ```plaintext
> _acme-challenge.example.com CNAME <id>.auth.example.org
> 
> ```
> 
> > 💡 Trust nobody? Self-host via **RFC2136/nsupdate** to your own BIND — acme.sh `dns_nsupdate`.

> **🚪 Port 80 blocked + old-device fixes**
>
> ```bash
> acme.sh --issue --alpn -d example.com # 443-only (TLS-ALPN-01)
> certbot certonly --preferred-chain "ISRG Root X1" -d ex.com # works on old Android
> certbot certonly --must-staple -d example.com # revoked = fails closed
> 
> ```

> **🔓 Free-CA menu + lock the door**
>
> [ZeroSSL](https://zerossl.com) · BuyPass Go (longer validity) · [Google TS](https://pki.goog) · [Cloudflare Origin CA](https://developers.cloudflare.com/ssl/) (15-year). Lock who can issue:
> 
> ```plaintext
> example.com. CAA 0 issue "letsencrypt.org"
> 
> ```
> 
> > 💡 A wildcard logs as `*.example.com` — internal names never leak into public logs.

> **👁️ Watch every cert on earth (recon + defense)**
>
> Point lookup: `https://crt.sh/?q=example.com`. Live firehose: [CertStream](https://certstream.calidog.io) + [phishing\_catcher](https://github.com/x0rz/phishing_catcher) pings you the second someone certs a lookalike of your domain. Audit your own TLS: [testssl.sh](https://github.com/drwetter/testssl.sh).

> **🩹 Classic nginx path + the stuff that bites**
>
> ```bash
> certbot --nginx --test-cert -d bchicbcow.com -d www.bchicbcow.com \
> --agree-tos --email bcbctechtools@bchicbcow.com --redirect # practice, no limit
> certbot --nginx -d bchicbcow.com -d www.bchicbcow.com \
> --agree-tos --email bcbctechtools@bchicbcow.com --redirect # real (drop --test-cert)
> certbot renew --dry-run # catch renewal breakage today, not on day 89
> 
> ```
> 
> > 💡 LE limits: a few dozen certs/domain/week. That’s why staging + alt CAs exist.

* * *

> **💥 Where this actually saves you**
>
> - **NAS / Proxmox / camera** screaming “Not Secure” → real padlock, box never exposed.
> - **One `*.home` wildcard** → covers every service you’ll ever add. No re-issue.
> - **A Pi or router with no domain** → `tailscale cert` / DuckDNS certs it in seconds.
> - **Someone registers `yourbank-login.com`** → CertStream pings you before their scam goes live.
> - **ISP blocks port 80** → TLS-ALPN-01 gets it on 443 alone.

* * *

**⚡ Quick Hits**

| Job | Grab |
| --- | --- |
| 🌐 Public site, dead simple | [Caddy](https://caddyserver.com) |
| 🏠 Internal box | DNS-01 / [step-ca](https://github.com/smallstep/certificates) |
| 🔑 Keys off the box | [acme-dns](https://github.com/joohoi/acme-dns) |
| 🪄 No domain | [tailscale cert](https://tailscale.com/docs/how-to/set-up-https-certificates) / [DuckDNS](https://www.duckdns.org) |
| 📟 Router / embedded | [uacme](https://github.com/ndilieto/uacme) |
| 👁 Cert recon | [CertStream](https://certstream.calidog.io) · [crt.sh](https://crt.sh) |

_A locked port is a wall; a DNS record is a key you already hold._

---

<div class="post-metadata">

**Author:** ![system](https://onehack.st/user_avatar/onehack.st/system/32/165705_2.png) [@system](https://onehack.st/u/system)\
**Post date:** [July 2, 2026, 3:16am UTC](https://onehack.st/t/get-a-real-certificate-without-buying-a-domain/323544/2 "2026-07-02T03:16:24Z")

</div>

> [@BCBC](#):
>
> 🔐 Free Trusted Certs for EVERYTHING You Own Public sites, private 192.168 boxes, wildcards, routers, no-domain machines. All free, all…

**♻ Fresh news: the Core-Community’s AI just upgraded the post above.**

---

<div class="post-metadata">

**Author:** ![BCBC](https://onehack.st/user_avatar/onehack.st/bcbc/32/174133_2.png) [@BCBC](https://onehack.st/u/BCBC)\
**Post date:** [July 3, 2026, 3:33am UTC](https://onehack.st/t/get-a-real-certificate-without-buying-a-domain/323544/3 "2026-07-03T03:33:00Z")

</div>

Yes the Ore Community AI did ty it looks amazing. I’m busy and not very artsy, Thank you for your help. You guys at 1H RULE!! Enjoy everybody.
