Automic VaultAutomic Vault

brew

acme.sh mit Homebrew, Nix, apk, apt, pacman installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für acme.sh in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install acme.sh

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#acme-sh

nixpkgs package indexes · pkgs/by-name/ac/acme-sh/package.nix · Quelle: api.github.com

Alpine Linux apkverifiziert · 92%
sudo apk add acme.sh

Alpine Linux edge package indexes · acme.sh · Quelle: dl-cdn.alpinelinux.org

Debian aptverifiziert · 92%
sudo apt install acme.sh

Debian stable package indexes · acme.sh · Quelle: deb.debian.org

Arch Linux pacmanverifiziert · 92%
sudo pacman -S acme.sh

Arch Linux sync databases · acme.sh · Quelle: geo.mirror.pkgbuild.com

Überblick

Paketzusammenfassung

ACME client

Befehle und Aliase

  • acme.sh

Verlauf

Projektgeschichte und Nutzung

acme.sh is a pure Unix shell ACME client for issuing, renewing, and installing TLS certificates. It is designed around a small shell script, broad Unix compatibility, no Python dependency, and automated renewals through cron.

Projektgeschichte

The GitHub repository was created in December 2015, shortly after Let's Encrypt made ACME-based certificate automation a practical mainstream workflow. The official README describes acme.sh as a full ACME protocol implementation written in Unix shell and tested across Linux, BSDs, macOS, Solaris-family systems, Haiku, and Windows via Cygwin.

The project grew from a Let's Encrypt-oriented client into a general ACME client. Its README lists support for multiple CAs including ZeroSSL, Let's Encrypt, SSL.com, Google Public CA, Actalis, Pebble, and any RFC 8555-compliant CA, while the wiki documents the large DNS API surface used for automated DNS-01 validation.

Adoptionsgeschichte

acme.sh became a popular package-manager ACME client because it fits shared hosting, appliances, routers, and small servers where a shell-only dependency profile matters. The official README's 'Who Uses acme.sh?' section names deployments and integrations such as FreeBSD.org, Proxmox, pfSense/OPNsense-adjacent tooling, and other hosting/control-panel environments.

The input package-manager facts show acme.sh packaged across Homebrew, Alpine, Debian, Nix, and Arch. The GitHub API reports a large public repository with tens of thousands of stars and thousands of forks, consistent with broad operational adoption.

Wie es verwendet wird

Typical package usage installs the acme.sh command, stores working state under ~/.acme.sh by default, creates a cron renewal job, and issues certificates with webroot, standalone, TLS-ALPN, Apache, Nginx, DNS, DNS alias, stateless, or DNS persist modes. DNS API credentials are exported once and then saved into ~/.acme.sh/account.conf for later renewal runs.

Warum Paket-Nerds sich dafür interessieren

acme.sh matters to package nerds because it is a rare security-critical tool whose portability comes from plain POSIX-ish shell rather than a language runtime. That makes it attractive for Homebrew, distro, appliance, and container packaging, while its large dnsapi collection creates a sprawling map of DNS provider integrations in one scriptable package.

Zeitleiste

  • 2015-12-26: GitHub repository created.
  • 2016-04-06: Earliest GitHub release metadata in the current repository lists version 1.2.2.
  • 2016-07-02: Version 2.3.0 tag commit appears in the repository tag history.
  • 2024: 3.0.x releases continue regular bug-fix and integration work.
  • 2026-04-28: Release 3.1.3 published.

Related projects

  • Related projects include Let's Encrypt, ZeroSSL, Certbot, Pebble, RFC 8555 ACME servers, and the DNS provider APIs supported by acme.sh's dnsapi wiki.

Quellen

  • Official README, official wiki, official dnsapi wiki page, GitHub repository/release metadata, and source_facts.package-manager.

Sicherheitslage

Risikostufe: blue

broad file, network, media, or database tool signal.

Risikoklassifikator

blue Risiko · mittel Konfidenz · tool

Warum

  • broad file, network, media, or database tool signal

Signale

  • text:client

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 1 Plattformziele verfügbar.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.acme.sh/

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.acme.sh/account.conf

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
acme.shcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version3.1.4
Manager aktualisiert2026-07-17
lokale DatenOK
Upstreamaktuell
neueste erkannte Version3.1.4

https://github.com/acmesh-official/acme.sh

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:acme.sh
Version3.1.4
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/acme.sh
Homepagehttps://github.com/acmesh-official/acme.sh
Repositoryhttps://github.com/acmesh-official/acme.sh
Upstream-Dokumentationhttps://github.com/acmesh-official/acme.sh#readme
LizenzGPL-3.0-only
Quellarchivhttps://github.com/acmesh-official/acme.sh/archive/refs/tags/3.1.4.tar.gz
Zuletzt aktualisiert2026-07-17T03:06:02Z
Pulseupdated
Bottleverfügbar (auf all)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameacme.sh
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Debian apt95%

acme.sh 3.1.1-1

Pure unix shell script implementing ACME client protocol

https://github.com/acmesh-official/acme.sh

sudo apt install acme.sh
  • Section: web
  • Architecture: all
  • 2 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Acme Sh
Debian stable package indexes · deb.debian.org · Debian stable package indexes: acme.sh from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

acme-sh

nix profile install nixpkgs#acme-sh
  • normalized package name match
  • Abgeglichen nach: Acme Sh
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ac/acme-sh/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

acme.sh 3.1.3-r0

ACME Shell script, an acme client alternative to certbot

https://github.com/acmesh-official/acme.sh

sudo apk add acme.sh
  • License: GPL-3.0-only
  • Architecture: x86_64
  • Source Package: acme.sh
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Acme Sh
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: acme.sh from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
pacman95%

acme.sh 3.1.3-1

An ACME Shell script, an acme client alternative to certbot

https://github.com/acmesh-official/acme.sh

sudo pacman -S acme.sh
  • License: GPL-3.0-only
  • Architecture: any
  • 1 Abhängigkeiten
  • 3 optionale Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Acme Sh
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: acme.sh from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment