Skip to main content
Glama

SSL-Zertifikat ausstellen

create_ssl_certificate
Destructive

Stellt ein neues Let's-Encrypt-SSL-Zertifikat für eine Domain aus (über sslit) und ersetzt damit das aktuelle Zertifikat. Sichert standardmäßig die Domain selbst, www und webmail; mail. nur auf Wunsch (include_mail), da das einen bereits existierenden mail.-DNS-Record voraussetzt und sonst mit einer konkreten Fehlermeldung fehlschlägt. Let's Encrypt erlaubt nur 5 identische Zertifikate pro Woche. Dagegen schützen zwei Prüfungen, die beide ihre Grenzen nennen: (1) gezählt werden die Ausstellungen, die in den letzten 7 Tagen ÜBER TURBOPRESS für diese Domain liefen (eigenes Prüfprotokoll) — ab 5 wird abgelehnt; Ausstellungen über das Plesk-Panel oder einen anderen Anbieter zählt diese Zahl nicht mit, sie ist also eine Untergrenze, keine Bilanz des Kontingents. (2) eine Frischeprüfung am live ausgelieferten Zertifikat: Stammt es von Let's Encrypt und ist es weniger als 7 Tage alt, wird ebenfalls abgelehnt — das ist ein Indiz, keine Zählung, und es sagt nur, WAS ausgeliefert wird, nicht wer es ausgestellt hat (ein vorgeschaltetes CDN/Proxy kann ein fremdes sein). force=true übergeht beides. Konnte eine der beiden Prüfungen nicht greifen (TLS-Handshake fehlgeschlagen oder Protokoll unlesbar), fällt der Schutz NICHT stillschweigend aus: Die Antwort sagt dann ausdrücklich, dass er nur unvollständig gegriffen hat. Antwortet mit dem live bestätigten Ergebnis (Aussteller, abgedeckte Namen, Gültigkeit) — oder ausdrücklich als unbestätigt, wenn die Live-Verifikation nicht möglich war.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
forceNoDen Schutz gegen zu häufiges Ausstellen derselben Domain übergehen (Standard: false) — nur setzen, wenn wirklich nötig, z. B. um SANs zu ändern
domainYesDie Domain, z. B. example.com
include_wwwNowww.<domain> mit absichern (Standard: true)
include_mailNomail.<domain> mit absichern — braucht einen existierenden DNS-Record für mail.<domain> (Standard: false)
include_webmailNowebmail.<domain> mit absichern (Standard: true)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Far exceeds the annotations (readOnlyHint=false, destructiveHint=true): it discloses that the existing certificate is replaced, the Let's Encrypt 5-per-week limit, two distinct guards with their explicit limitations, that force bypasses both, that guard failure is reported rather than silently skipped, and what the response contains. This is exactly the destructive/mutating context an agent needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

It is long, but it is front-loaded with the action and replacement semantics, and the remaining sentences carry genuine behavioral facts (rate limit, guard logic, failure reporting). Minor redundancy with the schema's parameter descriptions is the only wasted space.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description explicitly explains the return shape ('live bestätigtes Ergebnis... oder ausdrücklich als unbestätigt'), and covers the mutation's side effects, prerequisites, and safeguards. Nothing needed to invoke it safely is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents all five parameters including defaults and the mail DNS prerequisite. The description largely restates those defaults and the force semantics already present in the schema descriptions, adding little syntax or format detail beyond them. Baseline 3 applies when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

First sentence states a specific verb and resource ('Stellt ein neues Let's-Encrypt-SSL-Zertifikat für eine Domain aus') and adds the critical scope note that it replaces the current certificate. This cleanly separates it from read-only siblings like get_ssl_status and fix_https_redirect.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives concrete operating conditions: which names are covered by default, that include_mail requires an existing mail.<domain> DNS record, and when force should be used. It does not explicitly name a sibling alternative (e.g. 'use get_ssl_status to inspect first'), so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources