Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCDR / GOpenCDR certificate subscriber agreement

GOpenCDR certificate subscriber agreement

What you agree to when you obtain a certificate from the GOpenCDR certificate authority: control of the name, care of the key, public logging, and when a certificate is revoked.

Last updated 27 September 2026 Auf Deutsch lesen →

On this page

  1. This agreement
  2. What you promise
  3. What you accept
  4. What we do
  5. Everything else

This agreement

This agreement is between Gelhaus Solutions, operating the GOpenCDR certificate authority, and you, whenever you obtain a certificate from it. You accept it when you create an ACME account and agree to the terms of service the ACME directory links to, which is this page. The certificate policy and practice statement sets out how the certificate authority works, and applies to you with this agreement.

What you promise

  • You control every name in each request you make, and you keep controlling it for as long as you use a certificate for it.
  • What you put in a request is accurate.
  • You generated the key pair yourself. You keep the private key secret and under your control, and share it with nobody who is not entitled to act for the names.
  • You use a certificate only for TLS server authentication for the names in it, only on servers that serve those names, and only lawfully and within the acceptable use policy.
  • You request revocation at once if the private key is or may be compromised, if you lose control of a name in the certificate, or if anything in it becomes inaccurate. You stop using a certificate once it has expired or been revoked.
  • You answer promptly when we contact you about a possible compromise or a wrongly issued certificate.

What you accept

  • Every certificate is public. It is recorded in the GOpenCDR certificate transparency log with every name in it, and the entry is permanent.
  • Only people who installed the GOpenCDR root trust your certificate. It is not part of the public web PKI, and browsers do not trust it by default.
  • A certificate lasts at most 45 days. Renew it automatically.
  • We revoke for the reasons in the certificate policy and practice statement: among them, when your registration of a name ends or passes to someone else, when a name is withdrawn under the IANA rule, when its TLD leaves GOpenCDR, and when this agreement is broken.

What we do

We issue only after checking your control of each name with DNSSEC-validated lookups and checking its CAA records, we log every certificate before it is used, we revoke within 24 hours of establishing a reason, and we publish revocation lists at least every 24 hours.

Everything else

Certificates are free. No warranty is given and no service level applies. For what is given away, liability is limited to intent and gross negligence (Section 521 BGB), and otherwise it is as the general terms of service set out. You may close your ACME account at any time; a certificate already issued stays valid until it expires unless you or we revoke it. German law applies.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform Billing
  • GOpenCDR

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany