SecureNT Intranet SSL

SSL/TLS Certificates for Internal Networks.

Can Let's Encrypt Issue SSL Certificates for Internal IP Addresses ?

Let's Encrypt can now issue certificates containing IP addresses, so older information saying that Let's Encrypt cannot issue IP certificates is outdated.

However, there are important limitations.

Let's Encrypt IP-address certificates are short-lived — approximately six days — and require automated renewal. IP validation uses HTTP-01 or TLS-ALPN-01, not DNS-01.

For private internal addresses such as:

10.10.20.25
172.16.10.50
192.168.1.100

you should not assume that the new public IP-certificate capability automatically solves the certificate requirement for an internal-only application. The required validation must be possible under Let's Encrypt's rules.

A Private CA can issue certificates for private IP addresses as part of an organization's internal PKI, without requiring the internal server to be publicly reachable.

In short: Let's Encrypt now supports IP certificates, but organizations using private IP-based applications should evaluate the validation, renewal and trust requirements before choosing a public CA.

Related: What Is the Difference Between Let's Encrypt and a Private CA?

No Comments Yet.

Copyright © 2026 Secure Network Traffic. All rights reserved. SecureNT is a registered trademark of Secure Network Traffic.