Let's Encrypt can now issue certificates containing IP addresses, so older information saying that Let's Encrypt cannot issue IP certificates is outdated.
However, there are important limitations.
Let's Encrypt IP-address certificates are short-lived — approximately six days — and require automated renewal. IP validation uses HTTP-01 or TLS-ALPN-01, not DNS-01.
For private internal addresses such as:
10.10.20.25
172.16.10.50
192.168.1.100
you should not assume that the new public IP-certificate capability automatically solves the certificate requirement for an internal-only application. The required validation must be possible under Let's Encrypt's rules.
A Private CA can issue certificates for private IP addresses as part of an organization's internal PKI, without requiring the internal server to be publicly reachable.
In short: Let's Encrypt now supports IP certificates, but organizations using private IP-based applications should evaluate the validation, renewal and trust requirements before choosing a public CA.
Related: What Is the Difference Between Let's Encrypt and a Private CA?
No Comments Yet.
Copyright © 2026 Secure Network Traffic. All rights reserved. SecureNT is a registered trademark of Secure Network Traffic.