In the same spirit of minimal and light weight there is also testssh.sh [2] for testing TLS on HTTPS/SMTPS servers that also depends on bash and openssl.
They also provide a CA to go with it, if you need internal certs.
http://git.9front.org/plan9front/plan9front/HEAD/sys/src/cmd...
It works quite well, and if you mount your unix machines via sshfs, it's pretty easy to dump the certs into the right place with them.
And unlike most ACME clients, it works seamlessly with DNS authentication, which allows you to easily grab wildcard certs.
I maintain my own patch, so tiny-acme supports an '--outfile' option (it originally only writes to stdout). This comes in handy when it is run by systemd service/timer.
The pull request is on hold, because the code then exceeds then 200 lines threshold :shrug:
Disclaimer: I'm affiliated with Caddy
[0]: https://caddy.community/t/using-caddy-to-keep-certificates-r...
In the end does anyone really care if it’s a 10MB tarball versus a 330kb tarball?
I never had a problem with how long it took to install dependencies until I had to do it multiple times over in quick succession.