I have successfully switched all the sites that I host myself to use #Actalis TLS certificates instead of ZeroSSL or Let's Encrypt. Actalis is an Italian CA, and the only European CA (RIP Buypass), that provides unlimited free certificates via ACME.
Their site is flaky and does crash sometimes, but after you signed up (no KYC needed, an email is enough!) and got your EAB credentials, you'll never have to touch them again! The only downside I can think of is them not offering wildcard certificates, but I never used those, so ¯\_(ツ)_/¯
Für den Fall das jemand nach einem kostenlosen #smime #zertifikat sucht um seine E-Mails zu signieren oder zu verschlüsseln.
Bei #actalis actalis.com kann man sich kostenlose eins für ein Postfach für 1 Jahr anfordern und herunterladen.
@benjojo Thanks. I was curious and checked https://acmeclients.com/certificate-authorities/. This way I found #Actalis, a trusted Italian CA. They clearly offer some ACME support, but their free plan has no wildcard support and only a single domain (total or per certificate?) https://www.actalis.com/subscription
You are absolutely right, they do, but it is the only free certificate available at the moment, which is still trusted by the email clients and CAs.
Buying a certificate with a proper CSR as you described, is the correct approach, but it costs 8 EUR per year per email account.
In a way that is why I prefer #openpgp, you are absolutely right in pointing out that #actalis has access to the private key, which is an unacceptable security risk for any application different than just signing trivial emails.