# Rate Limit Clarification (acme/new-cert)

**URL:** <https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458>\
**Category:** Help\
**Created:** [November 1, 2017, 5:24pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458 "2017-11-01T17:24:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pd-aray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pd-aray/32/37894_2.png) [@pd-aray](https://community.letsencrypt.org/u/pd-aray)\
**Post date:** [November 1, 2017, 5:24pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458/1 "2017-11-01T17:24:29Z")

</div>

Hey there!

As a very brief introduction, we're an organization in the position of requesting SSL certificates for other organizations. We're running a custom ACME client which we've used to successfully provision a couple dozen certificates so far. I'll venture to say we have a basic understanding of the ACME protocol and Let's Encrypt's published rate limits ([Rate Limits - Let's Encrypt](https://letsencrypt.org/docs/rate-limits/)).

However, we've hit a "Certificates per Registered Domain" rate limit in our attempts to obtain a certificate for the [go.linuxfoundation.org](http://go.linuxfoundation.org) domain:

> Error creating new cert :: too many certificates already issued for: [linuxfoundation.org](http://linuxfoundation.org)

This is confusing because a search on crt.sh ([https://crt.sh/?q=linuxfoundation.org](https://crt.sh/?q=linuxfoundation.org)) reveals that there have been 5 certificates issued by Let's Encrypt for the [linuxfoundation.org](http://linuxfoundation.org) domain in the past week. Including our request, this should be well under the 20/week limit published in the rate limit documentation.

Can anyone provide any insight or clarify any misunderstanding on our part here?

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [November 1, 2017, 5:36pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458/2 "2017-11-01T17:36:19Z")

</div>

Hi @pd-aray,

> [@pd-aray](#):
>
> This is confusing because a search on crt.sh ([https://crt.sh/?q=linuxfoundation.org](https://crt.sh/?q=linuxfoundation.org))

There are more than 5 certficates... keep in mind that your search is not covering certificates issued for subdomains.

Use this to search for subdomains: [https://crt.sh/?q=%.linuxfoundation.org](https://crt.sh/?q=%25.linuxfoundation.org)

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![pd-aray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pd-aray/32/37894_2.png) [@pd-aray](https://community.letsencrypt.org/u/pd-aray)\
**Post date:** [November 1, 2017, 6:00pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458/3 "2017-11-01T18:00:31Z")

</div>

Thanks so much for pointing that out @sahsanu, that’s exactly what I was missing!

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [November 1, 2017, 6:44pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458/4 "2017-11-01T18:44:41Z")

</div>

And if you remove the dot after the `%`, you’ll get everything: the base domain ánd all subdomains…

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 1, 2017, 6:44pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification-acme-new-cert/45458/5 "2017-12-01T18:44:55Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
