Overview

CAcert was founded in 2003 and is headquartered in Australia. It is a community-driven open-source SSL certificate authority (CA). CAcert's core philosophy is to make digital certificates freely available to everyone—all SSL/TLS server certificates, code signing certificates, and email certificates are issued free of charge with fully transparent operations, allowing community members to participate in CA governance and certificate issuance verification.

Unlike commercial CAs, CAcert operates without profit pressure. Its certificate issuance process is maintained by a global community of volunteers. As of 2026, CAcert has issued free certificates to over 2 million users worldwide, making it one of the largest community-driven CAs globally. Although CAcert's root certificates are not pre-installed in mainstream browsers, it maintains a loyal user base in open-source communities, educational institutions, and non-commercial projects.

Key Strengths

  • Completely Free with No Hidden Costs: All certificate types are issued free of charge with no certification fees or annual costs—only community identity verification (Assurance) is required. Compared to commercial CAs charging hundreds of dollars per year, CAcert offers a viable solution for zero-cost SSL needs.
  • Open and Transparent Operations: All CAcert software code, CA operational specifications, and certificate issuance records are publicly auditable. For open-source projects and privacy advocates, this fully open operational model is unmatched by commercial CAs.
  • Multiple Certificate Types: In addition to SSL/TLS server certificates, CAcert offers code signing certificates and email certificates, covering various digital signing needs for developers and organizations. Code signing certificates can be used for software release signing to ensure distribution integrity.
  • Community Governance and Decentralization: CAcert is managed by CAcert Inc., a community association where major decisions are made by member vote, independent of any commercial entity. This decentralized governance ensures operational independence and long-term sustainability.

Product Ecosystem

SSL/TLS Server Certificates

CAcert's SSL/TLS server certificates are used for website HTTPS encryption and support major web servers including Apache, Nginx, and IIS. Certificates are Domain Validation (DV) level with identity verification completed through the community Assurance process. While not broadly trusted by browsers, CAcert certificates are a viable zero-cost option for internal systems, test environments, and educational purposes.

Code Signing Certificates

CAcert code signing certificates allow developers to digitally sign software, scripts, and drivers, ensuring code integrity and verifiable publisher identity. For open-source projects and non-commercial software distribution, free code signing certificates meet basic signing requirements.

Email Certificates (S/MIME)

CAcert also offers S/MIME email certificates for encrypting and signing email communications. Compared to commercial email certificates, CAcert's version is completely free, suitable for individuals and open-source organizations protecting email communication security.

Limitations

  • Limited Browser Trust: CAcert's root certificates are not pre-installed in major browsers (Chrome, Firefox, Safari, Edge) or operating systems. Websites using CAcert certificates may display security warnings to visitors. For public-facing websites, this negatively impacts user experience and website trust signals. An alternative with broad browser trust is Let's Encrypt.
  • Cumbersome Offline Verification: CAcert requires applicants to undergo in-person or video identity verification (Assurance process) through community members. While this enhances certificate credibility, it adds time and geographic barriers for online applicants.
  • No Enterprise Support: CAcert is operated by community volunteers with no paid technical support channels or SLA guarantees. For enterprise SSL deployments requiring 24/7 response, commercial CAs are more reliable.
  • Short Certificate Validity: CAcert-issued certificates typically have a 6-month validity period with no automatic renewal tools, requiring users to manually track renewal schedules and increasing operational overhead.

Use Cases

  • Personal Projects and Learning (★★★★☆): For individual developers learning SSL/TLS configuration, building internal systems, or testing environments, CAcert provides a zero-cost certificate solution. Combine with environment deployment best practices for quick setup.
  • Open Source Projects and Community Sites (★★★☆☆): Open-source projects that don't require public browser trust can use CAcert certificates to save costs. For projects needing browser trust, pair with Let's Encrypt.
  • Enterprise Production Environments (★☆☆☆☆): Due to browser trust issues and lack of SLA support, CAcert is not suitable for enterprise production environments. Commercial CAs such as DigiCert or Sectigo are recommended.
  • Educational and Research Institutions (★★★★☆): For SSL deployment teaching demonstrations and lab environments in universities and research institutions, CAcert's zero-cost nature is ideal for budget-constrained scenarios.

Pricing

Item Price Notes
SSL/TLS Server Certificate Free Requires Assurance verification
Code Signing Certificate Free Requires Assurance verification
Email Certificate Free Requires Assurance verification
Assurance Verification Free Provided by community members voluntarily

All certificates are free with no fees. However, due to browser trust limitations, CAcert certificates are not recommended for public-facing production environments.

FAQ

  • Why aren't CAcert certificates trusted by browsers? CAcert's root certificates have not applied to join mainstream browser root store programs, as CAcert's operational model does not fully comply with CA/Browser Forum baseline requirements. For free certificates with universal browser trust, use Let's Encrypt.

  • How does the Assurance process work? Assurance is CAcert's identity verification mechanism. Applicants need to find a community member who has already passed Assurance (an Assurer) and verify identity through in-person meeting or video call. Once verified by the Assurer, applicants gain certificate issuance eligibility—see CDN and SSL/TLS best practices.

  • Can CAcert certificates be used on e-commerce sites? Not recommended. E-commerce sites handling payment information need browser green security indicators to build user trust. Due to trust limitations, CAcert certificates may lead to user attrition. E-commerce sites should use EV SSL certificates—see CDN and SSL/TLS best practices.

  • What's the difference between CAcert and Let's Encrypt? Let's Encrypt is an automated CA using the ACME protocol for 90-day certificate auto-issuance and renewal, trusted by all major browsers. CAcert is a fully community-driven manual verification CA with lower browser trust but offering more certificate types like code signing and email certificates. See CDN and SSL/TLS best practices.

  • Is CAcert still active? Yes, the CAcert community continues to operate and maintain the platform. However, due to browser trust issues, its influence has diminished compared to modern CAs like Let's Encrypt—see CDN and SSL/TLS best practices.