01 / The origin

AUTOMATED CERTIFICATE MANAGEMENT

Trust.
Kept intact.

aethercert discovers, renews and deploys TLS certificates across your systems automatically. Expiry tracking, renewal reminders and recurring manual handoffs disappear from the routine.

Community plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.

Discover the aether

02 / The aether

The invisible layer in between.

In Greek mythology, aether was the clear upper air beyond the visible world. Modern infrastructure has an invisible layer of its own: certificates that establish identity and secure connections between systems.

aethercert makes that layer visible, manageable and traceable.

Clarity · Transparency · Knowledge

Down to what matters

03 / Your world

Where infrastructure has to work.

Your applications, your team, your customers. A certificate only matters when the service using it works. aethercert renews and deploys certificates where they are actually needed.

The recurring work disappears. Control stays with you.

  • Windows and Linux systems
  • Automatic renewal and deployment
  • No inbound firewall rules

04 / The foundation

Automation proves itself in operation. Certificates have to renew on time, reach the right destination and be picked up by the service that depends on them.

What we build on
What we build on

Engineering that holds up in production.

Our standards show up in architecture, product decisions and day-to-day operation, not in slogans.

01

Reliability

Every renewal attempt is recorded. Failures stay visible and successful runs remain verifiable.

02

Clarity

Certificates, expiry dates, states and next actions are available in one place.

03

Security

Private keys are generated on your servers and never leave them.

04

Traceability

Architecture, data flows, boundaries and relevant events are documented.

05

Knowledge

Clear documentation makes technical context accessible and decisions easier.

06

Responsibility

We distinguish clearly between what aethercert automates, what runs locally and where administrative decisions remain.

07

Resilience

Installed certificates keep working even when aethercert is temporarily unavailable.

08

Rigor

From first discovery to the next renewal, certificate operations are treated as infrastructure, not as an afterthought.

The approach

One operating model for the certificate lifecycle

aethercert handles every managed TLS certificate through the same sequence: discover what is installed, issue or renew it before expiry, deploy it where the service actually uses it and record every step.

  1. 01Discover
  2. 02Issue / renew
  3. 03Deploy
  4. 04Verify
The problem

Certificate outages are preventable. They still happen.

Not because teams are careless. Expiry dates, systems and responsibilities are distributed across the infrastructure while the services around them are expected to keep running.

Shorter lifetimes increase the cadence

Publicly trusted certificate lifetimes are being reduced in stages to 47 days. Processes that were manageable by hand become impractical at that frequency.

Certificates are spread across the infrastructure

Web servers, mail systems, internal applications and front-end appliances all use their own certificates and installation paths.

The real work starts after issuance

The new certificate still has to reach the right system, enter the right store and be picked up by the service that uses it.

Manual inventories age quickly

Spreadsheets and calendar reminders stay complete only when every infrastructure change is recorded consistently.

Failures remain quiet until they matter

Without central monitoring, a failed renewal is often discovered through a browser warning, a broken integration or a user report.

Responsibility crosses team boundaries

Web operations, infrastructure teams and external providers often share the job. Without a defined process, ownership gaps are easy to create.

No individual step is difficult. The challenge is repeating all of them, on time and on every system, for as long as the service exists. aethercert takes over that recurring operation.

How it works

Set it up once. Let the lifecycle run.

Install and configure the agent once per server. From then on, aethercert handles the recurring workflow.

1
Install

Install the agent on the target systems

One elevated command enrolls the Windows or Linux server and installs the agent as a service. The agent only makes outbound connections. No inbound firewall rule, VPN or public IP address is required.

2
Inventory

See what is already installed

The agent reports locally installed certificates with their expiry dates. You then choose which hostnames aethercert should manage, which authority issues them and where each certificate should be deployed.

3
Automate

Hand over renewal and deployment

aethercert schedules renewal ahead of expiry. The agent generates a new private key, requests the certificate, installs it at the configured target and reloads the service. Every attempt is recorded.

At a glance: what is nearing expiry, what is running and where a job has failed.
The lifecycle

Four stages. One repeatable lifecycle.

The sequence is the same for a public certificate on a web server and an internal certificate from your own CA. Configure it once, then let the agent repeat the workflow.

  1. 01Discover

    Make the existing estate visible

    Each agent inventories certificate stores and certificate directories on its own host and reports what it finds with expiry dates. Discovery stays local: the agent does not probe the surrounding network or read private key material.

  2. 02Issue / renew

    A new certificate before the old one expires

    aethercert schedules renewal with a defined lead time, 30 days by default. The agent generates a new key on the server and requests a certificate from the selected authority. The existing certificate remains active until the new one is installed. Failed attempts are retried automatically.

  3. 03Deploy

    Install it where the service uses it

    Renewal is not complete until the service is using the new certificate. The agent writes it to IIS bindings, Exchange or Remote Desktop configuration, NGINX or Apache directories, or a load balancer API. It applies required key permissions and reloads the service.

  4. 04Verify

    Confirm it and keep the record

    Every issuance, renewal and deployment is written to an immutable log. The record includes the triggering actor and, on failure, the original error returned by the authority or agent.

Traceability

Every change stays explainable

The dashboard shows the current state. The history shows how it got there.

  • The dashboard prioritizes what needs attention

    See certificates expiring within 30 days, certificates already expired, agents without a recent check-in and job status across the last month.

  • Every attempt remains on record

    Issuance, renewal, installation and administrative changes are written to an immutable log. Even an owner cannot edit or delete entries. Retention is 7, 30 or 90 days depending on the plan.

  • Failures keep the technical cause

    Failed jobs include the original error from the authority or agent, making diagnosis possible without losing detail behind a generic message.

  • Existing monitoring stays useful

    On Pro, aethercert exposes fleet metrics for CheckMK, Prometheus and Grafana. Relevant events can also be forwarded by webhook, Syslog/CEF or SNMP trap.

One searchable history for the entire organization.
Deployment

Install where TLS actually terminates

Renewal is only complete when the service has picked up the new certificate. The agent installs it directly at the configured target.

Windows
  • IIS site bindings
  • Exchange: SMTP, IIS, POP, IMAP
  • Remote Desktop and full RDS roles
  • WinRM HTTPS listener
  • Windows certificate store
Linux
  • NGINX and Apache
  • Postfix and Dovecot
  • Services that read certificates from disk
  • systemd reload after installation
Appliances and containers
  • Citrix NetScaler through its API
  • Applications in Docker containers
  • Local scripts already present on the agent host
Certificate authorities

Public CA, private PKI or your own ACME server

Let's Encrypt is available without additional CA configuration. Google Trust Services, ZeroSSL, SSL.com and Actalis connect through an EAB key pair. The same applies to other ACME servers, including self-hosted instances such as step-ca or EJBCA. Active Directory Certificate Services connects through a connector on the CA host. The CSR travels directly from the agent through the connector to the CA and does not leave your network.

Automate a private PKI

Let's Encrypt

no additional CA configuration

EAB authorities

Google Trust Services, ZeroSSL, SSL.com, Actalis

Self-hosted ACME

step-ca, EJBCA, your own server

AD CS

through the CA connector

Architecture

Outbound by design. Private keys stay local.

These are the details infrastructure teams typically review before approving an agent on production systems. They describe the current implementation.

Outbound only

The agent opens an HTTPS connection to the control plane and accepts no incoming connections. No inbound firewall rule, VPN or public address is required. It works unchanged behind NAT or a proxy.

Quiet when idle, responsive when work arrives

The default check-in interval is three hours and can be reduced to 30 minutes on Pro. When a job is queued, the control plane shortens the interval to about ten seconds.

Private keys are created at the target

At first issuance and every renewal, a new private key is generated on the server that will use the certificate. It is never transmitted. The control plane stores the serial number, fingerprint and validity period.

One optional internal listener

The CA connector for Active Directory Certificate Services is the only component that listens for connections. It is intended only for your own agents on the internal network.

Architecture in detail

Your network

aethercert agents

on your servers

CA connector

optional, internal only

HTTPS, outbound only

aethercert control plane

metadata only, hosted in Germany

Under the hood

What your technical review should know

The main agent properties relevant to architecture, security and operational approval.

Private keys stay on the server

The private key is generated on the host that will use it at first issuance and at every renewal. It is never transmitted. The control plane stores certificate metadata only, including serial number, fingerprint and validity period.

The dashboard cannot upload executable code

A deployment target can run a reload command or a local script with root privileges. Custom scripts must already exist on the agent host. The dashboard only references them. Variables are passed as environment variables and are not interpolated into a shell.

Roles are enforced in the database

Viewer, member, admin and owner roles are enforced through row-level security, not only in the interface. Configuring a deployment target requires admin rights because it is closer to a deployment action than a certificate preference. Multi-factor authentication is mandatory and cannot be disabled.

Hosted in Germany

The application runs on Hetzner in Nuremberg and the database on Supabase in Frankfurt. Cloudflare acts as the TLS-terminating proxy and processes traffic but does not store application data. Private keys and certificates remain on your own systems.

Common questions

How it works

What happens when a certificate is about to expire?

For certificates issued by aethercert, renewal is scheduled 30 days before expiry by default. The existing certificate remains active until the replacement is installed. Failed attempts are retried up to three times, and the authority's original error appears in job history. Certificates that aethercert has discovered but does not yet manage cannot be renewed automatically, but they remain visible in the same expiry-sorted view.

How does renewal actually work?

Technically, renewal is a new issuance. The agent generates a new private key on the server, requests a new certificate, installs it at the configured deployment target and reloads the service. The replacement receives a new serial number and fingerprint, so configurations that use certificate pinning need to account for that change.

Can aethercert manage certificates I already have?

Agents inventory existing certificates and report their expiry dates to the dashboard. Because aethercert does not have the original private key or issuance configuration, it cannot renew those certificates directly. To bring one under management, create a managed certificate for the same names. Future issuance and renewal then run through aethercert.

What happens if a server is temporarily offline?

The pending job remains queued and the agent picks it up at the next check-in. The certificate already installed on the server continues to work. The default 30-day renewal window provides enough margin for temporary outages.

Access and security

Does aethercert need inbound access to my network?

No. Agents make outbound HTTPS connections only. No inbound firewall rule, VPN or public IP address is required. The optional connector for Active Directory Certificate Services is the only component with a listener, and it is intended for your own agents on the internal network. It does not need to be reachable from the internet.

What does the agent have access to?

Access is limited to the host where the agent is installed. It runs there with administrative privileges because changes to the Windows certificate store and service reloads require them. The agent reads local certificate stores and certificate directories for inventory and writes managed certificates only to configured targets. It does not inspect other systems on the network.

What happens to private keys?

The agent generates a private key on the server that will use it at every issuance and renewal. The key is never transmitted. aethercert stores certificate metadata such as serial number, fingerprint and validity period. The platform therefore cannot recover a lost key. After a server loss, the certificate is issued again.

Where does aethercert run?

The control plane and dashboard are hosted in Germany. The application runs on Hetzner in Nuremberg and the database on Supabase in Frankfurt. Cloudflare provides TLS termination and DDoS protection but does not store application data. Agents run inside your own infrastructure.

What happens if aethercert itself is unavailable?

Installed certificates continue to work without a connection to aethercert. During an outage, only the scheduling of new jobs pauses. Pending renewals resume when the control plane becomes available again. The default 30-day lead time provides sufficient margin for short interruptions.

Fit

Which servers are supported?

Windows Server is supported through an agent running as a Windows service, and Linux through an agent running under systemd. The agent needs local administrator or root privileges and outbound HTTPS access to the control plane. Certificates can also be deployed to Citrix NetScaler and running Docker containers.

Do I need to understand ACME, DNS-01 or PKI to use aethercert?

No. To configure a certificate, specify the hostname, choose a certificate authority and select the deployment target. Let's Encrypt is preconfigured. The underlying mechanics are documented, but routine operation does not require PKI expertise.

Can an IT service provider manage multiple customer environments?

Yes. On the MSP plan, each customer is a separate organization with its own data, agents and access controls. All customers are managed from one account with a consolidated invoice. Staff access can be limited to specific customers and roles.

Is there a free plan I can try?

Yes. Community includes three Let's Encrypt certificates on up to three servers for one domain, with no payment details required - enough for a homelab or a small business, and to run the full lifecycle on real servers. Registration is invite-only while the platform scales, so sign-up starts with a short waitlist.

Find more detail in the documentation. The pricing page shows what each plan includes.

Take certificate renewal off the manual checklist

Start free with one server and one certificate in your own infrastructure. If the workflow fits, expand deployment step by step.

Community plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.