01 / The origin
AUTOMATED CERTIFICATE MANAGEMENT
Trust.
Kept intact.
aethercert discovers, renews and deploys TLS certificates across your systems automatically. Expiry tracking, renewal reminders and recurring manual handoffs disappear from the routine.
Community plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.
Discover the aether02 / The aether
The invisible layer in between.
In Greek mythology, aether was the clear upper air beyond the visible world. Modern infrastructure has an invisible layer of its own: certificates that establish identity and secure connections between systems.
aethercert makes that layer visible, manageable and traceable.
Clarity · Transparency · Knowledge
Down to what matters03 / Your world
Where infrastructure has to work.
Your applications, your team, your customers. A certificate only matters when the service using it works. aethercert renews and deploys certificates where they are actually needed.
The recurring work disappears. Control stays with you.
- Windows and Linux systems
- Automatic renewal and deployment
- No inbound firewall rules
04 / The foundation
Automation proves itself in operation. Certificates have to renew on time, reach the right destination and be picked up by the service that depends on them.
What we build onEngineering that holds up in production.
Our standards show up in architecture, product decisions and day-to-day operation, not in slogans.
Reliability
Every renewal attempt is recorded. Failures stay visible and successful runs remain verifiable.
Clarity
Certificates, expiry dates, states and next actions are available in one place.
Security
Private keys are generated on your servers and never leave them.
Traceability
Architecture, data flows, boundaries and relevant events are documented.
Knowledge
Clear documentation makes technical context accessible and decisions easier.
Responsibility
We distinguish clearly between what aethercert automates, what runs locally and where administrative decisions remain.
Resilience
Installed certificates keep working even when aethercert is temporarily unavailable.
Rigor
From first discovery to the next renewal, certificate operations are treated as infrastructure, not as an afterthought.
One operating model for the certificate lifecycle
aethercert handles every managed TLS certificate through the same sequence: discover what is installed, issue or renew it before expiry, deploy it where the service actually uses it and record every step.
- 01Discover
- 02Issue / renew
- 03Deploy
- 04Verify
Certificate outages are preventable. They still happen.
Not because teams are careless. Expiry dates, systems and responsibilities are distributed across the infrastructure while the services around them are expected to keep running.
Shorter lifetimes increase the cadence
Publicly trusted certificate lifetimes are being reduced in stages to 47 days. Processes that were manageable by hand become impractical at that frequency.
Certificates are spread across the infrastructure
Web servers, mail systems, internal applications and front-end appliances all use their own certificates and installation paths.
The real work starts after issuance
The new certificate still has to reach the right system, enter the right store and be picked up by the service that uses it.
Manual inventories age quickly
Spreadsheets and calendar reminders stay complete only when every infrastructure change is recorded consistently.
Failures remain quiet until they matter
Without central monitoring, a failed renewal is often discovered through a browser warning, a broken integration or a user report.
Responsibility crosses team boundaries
Web operations, infrastructure teams and external providers often share the job. Without a defined process, ownership gaps are easy to create.
No individual step is difficult. The challenge is repeating all of them, on time and on every system, for as long as the service exists. aethercert takes over that recurring operation.
Set it up once. Let the lifecycle run.
Install and configure the agent once per server. From then on, aethercert handles the recurring workflow.
Install the agent on the target systems
One elevated command enrolls the Windows or Linux server and installs the agent as a service. The agent only makes outbound connections. No inbound firewall rule, VPN or public IP address is required.
See what is already installed
The agent reports locally installed certificates with their expiry dates. You then choose which hostnames aethercert should manage, which authority issues them and where each certificate should be deployed.
Hand over renewal and deployment
aethercert schedules renewal ahead of expiry. The agent generates a new private key, requests the certificate, installs it at the configured target and reloads the service. Every attempt is recorded.
Four stages. One repeatable lifecycle.
The sequence is the same for a public certificate on a web server and an internal certificate from your own CA. Configure it once, then let the agent repeat the workflow.
- 01Discover
Make the existing estate visible
Each agent inventories certificate stores and certificate directories on its own host and reports what it finds with expiry dates. Discovery stays local: the agent does not probe the surrounding network or read private key material.
- 02Issue / renew
A new certificate before the old one expires
aethercert schedules renewal with a defined lead time, 30 days by default. The agent generates a new key on the server and requests a certificate from the selected authority. The existing certificate remains active until the new one is installed. Failed attempts are retried automatically.
- 03Deploy
Install it where the service uses it
Renewal is not complete until the service is using the new certificate. The agent writes it to IIS bindings, Exchange or Remote Desktop configuration, NGINX or Apache directories, or a load balancer API. It applies required key permissions and reloads the service.
- 04Verify
Confirm it and keep the record
Every issuance, renewal and deployment is written to an immutable log. The record includes the triggering actor and, on failure, the original error returned by the authority or agent.
Every change stays explainable
The dashboard shows the current state. The history shows how it got there.
The dashboard prioritizes what needs attention
See certificates expiring within 30 days, certificates already expired, agents without a recent check-in and job status across the last month.
Every attempt remains on record
Issuance, renewal, installation and administrative changes are written to an immutable log. Even an owner cannot edit or delete entries. Retention is 7, 30 or 90 days depending on the plan.
Failures keep the technical cause
Failed jobs include the original error from the authority or agent, making diagnosis possible without losing detail behind a generic message.
Existing monitoring stays useful
On Pro, aethercert exposes fleet metrics for CheckMK, Prometheus and Grafana. Relevant events can also be forwarded by webhook, Syslog/CEF or SNMP trap.
certificate.issuedapp.example.com · EC-256 · 90 daysagent web-012m agojob.succeededdeploy to nginx :443, reloadedagent web-012m agocertificate.renewed*.internal.corp via Corp Issuing CAagent adcs-011h agojob.retry_scheduledvpn.example.com deploy failed, retry 2/3agent ns-adc3h agocertificate.discoveredportal.example.com found on ns-adcscan6h agoInstall where TLS actually terminates
Renewal is only complete when the service has picked up the new certificate. The agent installs it directly at the configured target.
- IIS site bindings
- Exchange: SMTP, IIS, POP, IMAP
- Remote Desktop and full RDS roles
- WinRM HTTPS listener
- Windows certificate store
- NGINX and Apache
- Postfix and Dovecot
- Services that read certificates from disk
- systemd reload after installation
- Citrix NetScaler through its API
- Applications in Docker containers
- Local scripts already present on the agent host
Public CA, private PKI or your own ACME server
Let's Encrypt is available without additional CA configuration. Google Trust Services, ZeroSSL, SSL.com and Actalis connect through an EAB key pair. The same applies to other ACME servers, including self-hosted instances such as step-ca or EJBCA. Active Directory Certificate Services connects through a connector on the CA host. The CSR travels directly from the agent through the connector to the CA and does not leave your network.
Automate a private PKILet's Encrypt
no additional CA configuration
EAB authorities
Google Trust Services, ZeroSSL, SSL.com, Actalis
Self-hosted ACME
step-ca, EJBCA, your own server
AD CS
through the CA connector
Outbound by design. Private keys stay local.
These are the details infrastructure teams typically review before approving an agent on production systems. They describe the current implementation.
Outbound only
The agent opens an HTTPS connection to the control plane and accepts no incoming connections. No inbound firewall rule, VPN or public address is required. It works unchanged behind NAT or a proxy.
Quiet when idle, responsive when work arrives
The default check-in interval is three hours and can be reduced to 30 minutes on Pro. When a job is queued, the control plane shortens the interval to about ten seconds.
Private keys are created at the target
At first issuance and every renewal, a new private key is generated on the server that will use the certificate. It is never transmitted. The control plane stores the serial number, fingerprint and validity period.
One optional internal listener
The CA connector for Active Directory Certificate Services is the only component that listens for connections. It is intended only for your own agents on the internal network.
Your network
aethercert agents
on your servers
CA connector
optional, internal only
aethercert control plane
metadata only, hosted in Germany
For IT teams without a dedicated PKI team
aethercert is built for companies and service providers that need reliable certificate operations without turning them into a separate discipline in day-to-day IT.
What your technical review should know
The main agent properties relevant to architecture, security and operational approval.
Private keys stay on the server
The private key is generated on the host that will use it at first issuance and at every renewal. It is never transmitted. The control plane stores certificate metadata only, including serial number, fingerprint and validity period.
The dashboard cannot upload executable code
A deployment target can run a reload command or a local script with root privileges. Custom scripts must already exist on the agent host. The dashboard only references them. Variables are passed as environment variables and are not interpolated into a shell.
Roles are enforced in the database
Viewer, member, admin and owner roles are enforced through row-level security, not only in the interface. Configuring a deployment target requires admin rights because it is closer to a deployment action than a certificate preference. Multi-factor authentication is mandatory and cannot be disabled.
Hosted in Germany
The application runs on Hetzner in Nuremberg and the database on Supabase in Frankfurt. Cloudflare acts as the TLS-terminating proxy and processes traffic but does not store application data. Private keys and certificates remain on your own systems.
Common questions
How it works
What happens when a certificate is about to expire?
For certificates issued by aethercert, renewal is scheduled 30 days before expiry by default. The existing certificate remains active until the replacement is installed. Failed attempts are retried up to three times, and the authority's original error appears in job history. Certificates that aethercert has discovered but does not yet manage cannot be renewed automatically, but they remain visible in the same expiry-sorted view.
How does renewal actually work?
Technically, renewal is a new issuance. The agent generates a new private key on the server, requests a new certificate, installs it at the configured deployment target and reloads the service. The replacement receives a new serial number and fingerprint, so configurations that use certificate pinning need to account for that change.
Can aethercert manage certificates I already have?
Agents inventory existing certificates and report their expiry dates to the dashboard. Because aethercert does not have the original private key or issuance configuration, it cannot renew those certificates directly. To bring one under management, create a managed certificate for the same names. Future issuance and renewal then run through aethercert.
What happens if a server is temporarily offline?
The pending job remains queued and the agent picks it up at the next check-in. The certificate already installed on the server continues to work. The default 30-day renewal window provides enough margin for temporary outages.
Access and security
Does aethercert need inbound access to my network?
No. Agents make outbound HTTPS connections only. No inbound firewall rule, VPN or public IP address is required. The optional connector for Active Directory Certificate Services is the only component with a listener, and it is intended for your own agents on the internal network. It does not need to be reachable from the internet.
What does the agent have access to?
Access is limited to the host where the agent is installed. It runs there with administrative privileges because changes to the Windows certificate store and service reloads require them. The agent reads local certificate stores and certificate directories for inventory and writes managed certificates only to configured targets. It does not inspect other systems on the network.
What happens to private keys?
The agent generates a private key on the server that will use it at every issuance and renewal. The key is never transmitted. aethercert stores certificate metadata such as serial number, fingerprint and validity period. The platform therefore cannot recover a lost key. After a server loss, the certificate is issued again.
Where does aethercert run?
The control plane and dashboard are hosted in Germany. The application runs on Hetzner in Nuremberg and the database on Supabase in Frankfurt. Cloudflare provides TLS termination and DDoS protection but does not store application data. Agents run inside your own infrastructure.
What happens if aethercert itself is unavailable?
Installed certificates continue to work without a connection to aethercert. During an outage, only the scheduling of new jobs pauses. Pending renewals resume when the control plane becomes available again. The default 30-day lead time provides sufficient margin for short interruptions.
Fit
Which servers are supported?
Windows Server is supported through an agent running as a Windows service, and Linux through an agent running under systemd. The agent needs local administrator or root privileges and outbound HTTPS access to the control plane. Certificates can also be deployed to Citrix NetScaler and running Docker containers.
Do I need to understand ACME, DNS-01 or PKI to use aethercert?
No. To configure a certificate, specify the hostname, choose a certificate authority and select the deployment target. Let's Encrypt is preconfigured. The underlying mechanics are documented, but routine operation does not require PKI expertise.
Can an IT service provider manage multiple customer environments?
Yes. On the MSP plan, each customer is a separate organization with its own data, agents and access controls. All customers are managed from one account with a consolidated invoice. Staff access can be limited to specific customers and roles.
Is there a free plan I can try?
Yes. Community includes three Let's Encrypt certificates on up to three servers for one domain, with no payment details required - enough for a homelab or a small business, and to run the full lifecycle on real servers. Registration is invite-only while the platform scales, so sign-up starts with a short waitlist.
Find more detail in the documentation. The pricing page shows what each plan includes.
Take certificate renewal off the manual checklist
Start free with one server and one certificate in your own infrastructure. If the workflow fits, expand deployment step by step.
Community plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.