# \[ANN\] ocaml-letsencrypt, an OCaml way to get TLS certificates

**URL:** <https://discuss.ocaml.org/t/ann-ocaml-letsencrypt-an-ocaml-way-to-get-tls-certificates/17975>\
**Category:** Ecosystem\
**Tags:** certificates, announce\
**Created:** [April 10, 2026, 7:57am UTC](https://discuss.ocaml.org/t/ann-ocaml-letsencrypt-an-ocaml-way-to-get-tls-certificates/17975 "2026-04-10T07:57:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinosaure](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/dinosaure/32/16_2.png) [@dinosaure](https://discuss.ocaml.org/u/dinosaure)\
**Post date:** [April 10, 2026, 7:57am UTC](https://discuss.ocaml.org/t/ann-ocaml-letsencrypt-an-ocaml-way-to-get-tls-certificates/17975/1 "2026-04-10T07:57:42Z")

</div>

I am delighted to announce the release of [ocaml-letsencrypt](https://github.com/robur-coop/ocaml-letsencrypt) (version 2.1.0). This version introduces a new API that allows it to operate independently of a scheduler and an HTTP client. It is also a rewrite using our brand-new [jws](https://github.com/robur-coop/jws) library, which now utilises the [jsont](https://erratique.ch/logiciel/jsont) library (rather than [yojson](https://github.com/ocaml-community/yojson)).

`ocaml-letsencrypt` implements [challenges](https://letsencrypt.org/fr/docs/challenge-types/) needed to obtain a certificate via the three ways: DNS, HTTP and ACME-TLS. It therefore enables a website deployment strategy (implemented with [Vif](https://github.com/robur-coop/vif), for example) to be provided entirely in OCaml.

We use it within our cooperative for projects such as:

- [`dns-letsencrypt-secondary`](https://github.com/robur-coop/dns-letsencrypt-secondary/), a unikernel that acts as a secondary DNS server capable of performing the DNS challenge for a specific domain and uploading the certificate as a TLSA record. It generally works in tandem with our [`primary-git`](https://github.com/robur-coop/dns-primary-git), our primary DNS server.
- [`contruno`](https://github.com/dinosaure/contruno), a unikernel that acts as a TLS reverse proxy and is capable of performing HTTP challenges. The latter is currently being completely rewritten using [`mnet`](https://discuss.ocaml.org/t/ann-mnet-a-new-tcp-ip-stack-for-unikernels-in-ocaml/17851).

Good luck with deploying your websites, and happy hacking! Here’s hoping that `jws` also finds its place as a library within the OCaml ecosystem.

---

<div class="post-metadata">

**Author:** ![hannes](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/hannes/32/2302_2.png) [@hannes](https://discuss.ocaml.org/u/hannes)\
**Post date:** [April 10, 2026, 3:48pm UTC](https://discuss.ocaml.org/t/ann-ocaml-letsencrypt-an-ocaml-way-to-get-tls-certificates/17975/2 "2026-04-10T15:48:10Z")

</div>

Great stuff!

I noticed I wrote several years back (end of 2019) about the DNS & let’s encrypt story with MirageOS – things have changed since then (esp.in respect to deployment, binaries we ship, ..) – see the old blog article [Deploying authoritative OCaml-DNS servers as MirageOS unikernels](https://hannes.robur.coop/Posts/DnsServer)
