Table of Contents [expand]
Last updated October 08, 2026
By default, Automated Certificate Management (ACM) issues certificates with a Rivest-Shamir-Adleman (RSA) key. To have ACM issue certificates with an Elliptic Curve Digital Signature Algorithm (ECDSA) key instead, enable the Heroku Labs acm-ec-cert feature.
Features added through Heroku Labs are experimental and may change without notice. These features are non-SFDC applications. Refer to your Main Services Agreement for additional information.
Overview
After enabling the acm-ec-cert feature, ACM issues your app’s certificates with an ECDSA key instead of a 2048-bit RSA key. The ECDSA key uses the P-256 elliptic curve.
The feature changes only certificates that ACM issues, such as:
- Common Runtime apps: Certificates for custom domain apps with ACM enabled. It doesn’t change certificates on default
herokuapp.comdomain apps. - Cedar-generation Private Space and Shield Private Space apps: Doesn’t change these apps’ certificates. ACM keeps issuing RSA certificates even with this feature enabled.
- Certificates you upload yourself: Doesn’t change these apps’ certificates.
When the change takes effect:
- A certificate that ACM issues after enabling the feature, such as one for a custom domain, has an ECDSA key.
- An existing RSA certificate keeps its RSA key until ACM issues the next certificate for that domain. For example, when it renews the certificate one month before it expires. Until ACM issues the new certificate, the domain keeps serving its current one.
To see when a custom domain’s certificate expires, run heroku certs and check the Expires column:
$ heroku certs -a example-app
Name Common Name(s) Expires Trusted Type
────────────── ───────────────────────────────── ───────────────────── ──────── ───
example-81798 example-app.runtime.herokai.com 2026-12-30 23:39 UTC True ACM
Each domain serves one certificate. After a domain’s certificate switches to ECDSA, clients that don’t support ECDSA can’t connect to it over Hypertext Transfer Protocol Secure (HTTPS). The switch happens when ACM issues the next domain certificate, often weeks after you enable the feature. Disabling the feature switches back only when ACM issues the next certificate. Before enabling, make sure your app’s clients support ECDSA.
Enable
To have ACM issue ECDSA certificates for your app, enable the feature with the command:
$ heroku labs:enable acm-ec-cert -a example-app
Check a Domain’s Key Type
To see which key type a domain’s certificate has, run this OpenSSL command. Replace www.example.com with your domain:
$ openssl s_client -connect www.example.com:443 -servername www.example.com </dev/null 2>/dev/null | openssl x509 -noout -text | grep "Public Key Algorithm"
A certificate with an ECDSA key prints Public Key Algorithm: id-ecPublicKey. A certificate with an RSA key prints Public Key Algorithm: rsaEncryption. id-ecPublicKey.
Disable
To have ACM go back to issuing RSA certificates for your app, disable the feature with the command:
$ heroku labs:disable acm-ec-cert -a example-app
A certificate that already has an ECDSA key keeps it until ACM issues the next certificate for that domain, for example when it renews the certificate.