Skip Navigation
Heroku Dev Center Dev Center
  • Get Started
  • Documentation
  • Changelog
  • Search
Heroku Dev Center Dev Center
  • Get Started
    • Node.js
    • Ruby on Rails
    • Ruby
    • Python
    • Java
    • PHP
    • Go
    • Scala
    • Clojure
    • .NET
  • Documentation
  • Changelog
  • More
    Additional Resources
    • Home
    • Elements
    • Products
    • Pricing
    • Careers
    • Help
    • Status
    • Events
    • Podcasts
    • Compliance Center
    Heroku Blog

    Heroku Blog

    Find out what's new with Heroku on our blog.

    Visit Blog
  • Log in or Sign up
Show nav
View categories

Categories

  • Heroku Architecture
    • Compute (Dynos)
      • Dyno Management
      • Dyno Concepts
      • Dyno Behavior
      • Dyno Reference
      • Dyno Troubleshooting
    • Stacks (operating system images)
    • Networking & DNS
    • Platform Policies
    • Platform Principles
    • Buildpacks
  • Developer Tools
    • AI Tools
    • Command Line
    • Heroku VS Code Extension
  • Deployment
    • Deploying with Git
    • Deploying with Docker
    • Deployment Integrations
  • Continuous Delivery & Integration (Heroku Flow)
    • Continuous Integration
  • Language Support
    • .NET
      • Working with .NET
    • Clojure
    • Front-end
    • Go
      • Go Dependency Management
    • Java
      • Java Behavior in Heroku
      • Working with Java
      • Working with Maven
      • Working with Spring Boot
      • Troubleshooting Java Apps
    • Node.js
      • Troubleshooting Node.js Apps
      • Node.js Behavior in Heroku
      • Working with Node.js
    • PHP
      • Working with PHP
      • PHP Behavior in Heroku
    • Python
      • Working with Python
      • Background Jobs in Python
      • Python Behavior in Heroku
      • Working with Django
    • Ruby
      • Rails Support
        • Working with Rails
      • Working with Bundler
      • Working with Ruby
      • Ruby Behavior in Heroku
      • Troubleshooting Ruby Apps
    • Scala
  • Databases & Data Management
    • Heroku Postgres
      • Postgres Basics
      • Postgres Getting Started
      • Postgres Performance
      • Postgres Data Transfer & Preservation
      • Postgres Availability
      • Postgres Special Topics
      • Migrating to Heroku Postgres
      • Heroku Postgres Advanced
    • Heroku Key-Value Store
    • Apache Kafka on Heroku
    • Other Data Stores
  • AI
    • Inference Essentials
    • Inference API
    • Inference Quick Start Guides
    • AI Models
    • Tool Use
    • AI Integrations
    • Vector Database
  • Monitoring & Metrics
    • Logging
  • App Performance
  • Add-ons
    • All Add-ons
  • Collaboration
  • Security
    • App Security
    • Identities & Authentication
      • Single Sign-on (SSO)
    • Private Spaces
      • Infrastructure Networking
    • Compliance
  • Heroku Enterprise
    • Enterprise Accounts
    • Enterprise Teams
  • Patterns & Best Practices
  • Extending Heroku
    • Platform API
    • App Webhooks
    • Heroku Labs
    • Building Add-ons
      • Add-on Development Tasks
      • Add-on APIs
      • Add-on Guidelines & Requirements
    • Building CLI Plugins
    • Developing Buildpacks
    • Dev Center
  • Accounts & Billing
  • Troubleshooting & Support
  • Integrating with Salesforce
    • Heroku AppLink
      • Getting Started with Heroku AppLink
      • Working with Heroku AppLink
      • Heroku AppLink Reference
    • Heroku Connect (Salesforce sync)
      • Heroku Connect Administration
      • Heroku Connect Reference
      • Heroku Connect Troubleshooting
    • Other Salesforce Integrations
  • Extending Heroku
  • Heroku Labs
  • Heroku Labs: Change Automated Certificate Management Keys

Heroku Labs: Change Automated Certificate Management Keys

Table of Contents [expand]

  • Overview
  • Enable
  • Check a Domain’s Key Type
  • Disable

Last updated October 08, 2026

By default, Automated Certificate Management (ACM) issues certificates with a Rivest-Shamir-Adleman (RSA) key. To have ACM issue certificates with an Elliptic Curve Digital Signature Algorithm (ECDSA) key instead, enable the Heroku Labs acm-ec-cert feature.

Features added through Heroku Labs are experimental and may change without notice. These features are non-SFDC applications. Refer to your Main Services Agreement for additional information.

Overview

After enabling the acm-ec-cert feature, ACM issues your app’s certificates with an ECDSA key instead of a 2048-bit RSA key. The ECDSA key uses the P-256 elliptic curve.

The feature changes only certificates that ACM issues, such as:

  • Common Runtime apps: Certificates for custom domain apps with ACM enabled. It doesn’t change certificates on default herokuapp.com domain apps.
  • Cedar-generation Private Space and Shield Private Space apps: Doesn’t change these apps’ certificates. ACM keeps issuing RSA certificates even with this feature enabled.
  • Certificates you upload yourself: Doesn’t change these apps’ certificates.

When the change takes effect:

  • A certificate that ACM issues after enabling the feature, such as one for a custom domain, has an ECDSA key.
  • An existing RSA certificate keeps its RSA key until ACM issues the next certificate for that domain. For example, when it renews the certificate one month before it expires. Until ACM issues the new certificate, the domain keeps serving its current one.

To see when a custom domain’s certificate expires, run heroku certs and check the Expires column:

$ heroku certs -a example-app
 Name            Common Name(s)                   Expires               Trusted  Type
 ────────────── ───────────────────────────────── ───────────────────── ──────── ───
 example-81798   example-app.runtime.herokai.com  2026-12-30 23:39 UTC  True     ACM

Each domain serves one certificate. After a domain’s certificate switches to ECDSA, clients that don’t support ECDSA can’t connect to it over Hypertext Transfer Protocol Secure (HTTPS). The switch happens when ACM issues the next domain certificate, often weeks after you enable the feature. Disabling the feature switches back only when ACM issues the next certificate. Before enabling, make sure your app’s clients support ECDSA.

Enable

To have ACM issue ECDSA certificates for your app, enable the feature with the command:

$ heroku labs:enable acm-ec-cert -a example-app

Check a Domain’s Key Type

To see which key type a domain’s certificate has, run this OpenSSL command. Replace www.example.com with your domain:

$ openssl s_client -connect www.example.com:443 -servername www.example.com </dev/null 2>/dev/null | openssl x509 -noout -text | grep "Public Key Algorithm"

A certificate with an ECDSA key prints Public Key Algorithm: id-ecPublicKey. A certificate with an RSA key prints Public Key Algorithm: rsaEncryption. id-ecPublicKey.

Disable

To have ACM go back to issuing RSA certificates for your app, disable the feature with the command:

$ heroku labs:disable acm-ec-cert -a example-app

A certificate that already has an ECDSA key keeps it until ACM issues the next certificate for that domain, for example when it renews the certificate.

Feedback

Log in to submit feedback.

Information & Support

  • Getting Started
  • Documentation
  • Changelog
  • Compliance Center
  • Training & Education
  • Blog
  • Support Channels
  • Status

Language Reference

  • Node.js
  • Ruby
  • Java
  • PHP
  • Python
  • Go
  • Scala
  • Clojure
  • .NET

Other Resources

  • Careers
  • Elements
  • Products
  • Pricing
  • RSS
    • Dev Center Articles
    • Dev Center Changelog
    • Heroku Blog
    • Heroku News Blog
    • Heroku Engineering Blog
  • Twitter
    • Dev Center Articles
    • Dev Center Changelog
    • Heroku
    • Heroku Status
  • Github
  • LinkedIn
  • © 2026 Salesforce, Inc. All rights reserved. Various trademarks held by their respective owners. Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States
  • heroku.com
  • Legal
  • Terms of Service
  • Privacy Information
  • Responsible Disclosure
  • Trust
  • Contact
  • Cookie Preferences
  • Your Privacy Choices