letsencrypt/boulder

An ACME-based certificate authority, written in Go.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 29 minutes ago
Added to GitGenius on September 11th, 2026
Created on December 21st, 2014
Open Issues & Pull Requests: 228 (+0)
GitHub issues: Enabled
Number of forks: 648
Total Stargazers: 5,747 (+0)
Total Subscribers: 131 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 44.0 hours
Mean response time: 106.2 days
90th percentile: 202.2 days
Tracked items: 411

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 85% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. 35% of tracked open issues have had no activity in three months. Only 7% of issues opened in the past year have been closed. Three people close 85% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 120
New in 7 days: 6
Closed in 7 days: 2
Avg open age: 462 days
Stale 30+ days: 91
Stale 90+ days: 75

Recent activity

Opened in 7 days: 6
Closed in 7 days: 2
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • starter (31)
  • kind/enhancement (7)
  • kind/feature (7)
  • area/ra (6)
  • area/ca (5)
  • area/sa (5)
  • area/va (5)
  • area/wfe (4)

Detailed Description

Boulder is an ACME-based certificate authority written in Go that implements the ACME protocol to automate certificate issuance and revocation.

Boulder solves the problem of building a scalable, secure certificate authority by separating concerns across multiple components with distinct security contexts. The system divides functionality into Web Front Ends, Registration Authority, Validation Authority, Certificate Authority, Storage Authority, Publisher, and CRL Updater. This component model allows internet-facing services to be isolated from those requiring higher security. The tool models its logic around five ACME resource types—accounts, authorizations, challenges, orders, and certificates—and uses gRPC for inter-component communication, enabling components to run remotely when needed.

Boulder is the software powering Let's Encrypt and suits organizations building their own ACME-based certificate authorities or those needing to understand how a production CA operates. The project provides Docker Compose setup for development and experimentation, though this is not suitable for production deployment. For ACME client developers doing quick testing or continuous integration, the README recommends Pebble as a lighter alternative.

The project maintains a substantial base of adopters who report issues from real-world use rather than the core team driving the issue tracker. Maintainers respond to new issues and pull requests within a few days. Work in the issue tracker centers on starter tasks, feature requests, and registration authority concerns.