Automated TLS certificate deployment
A renewal is only finished when the service is using the new certificate. aethercert installs every certificate where TLS actually terminates - a Windows role, a web server, a load balancer, a firewall - and reloads or activates it there.
Every Target Registry package is available on every plan, including Community. Custom scripts require Standard or higher. See plans and limits
agent web-01 · package windows-iis-target 3.0.0
importensureBindingassignBindingverifyBindingcleanupwhen configured
What it does
After a certificate is issued or renewed, the agent that holds its private key runs the deploy target you attached to it. A deploy target is a signed Target Registry package: a reviewed sequence of steps that imports the certificate, binds it to the service, reloads or commits the configuration and, where the product allows it, checks that the new certificate is the one being served.
Targets on the same host run locally - PowerShell on Windows, files plus a service reload on Linux. Appliances and platforms with a management API (NetScaler, F5 BIG-IP, FortiGate, PAN-OS, vCenter, Kubernetes and others) are reached over that API by an agent on your network. Nothing connects in from the internet.
How it works
- 01
Choose a target
Pick a Target Registry package for the system - Microsoft IIS, Exchange, NetScaler ADC and others - or save one as a reusable deploy target with its connection details.
- 02
The agent gets the material
The private key never leaves the agent that generated it. For appliance targets the agent sends certificate and key to the appliance over its management API, from inside your network.
- 03
The package runs its steps
Import, bind, reload or commit, in the order the package defines. Each step is logged; a failed step stops the run and reports the step that failed.
- 04
Result and retry
Success is recorded on the certificate and in the event log. A failure is classified as permanent or temporary; temporary failures are retried before the job is marked failed and an alert is raised.
Key capabilities
29 first-party targets
Windows roles, Citrix and VMware, load balancers, firewalls, hypervisors, nginx, HAProxy, Docker and Kubernetes - every one a signed package maintained by aethercert.
Bindings, not just files
Packages bind the certificate to the service that uses it: IIS site bindings, Exchange services, the RDP listener, the SQL Server instance, a NetScaler certkey, an F5 client-SSL profile.
Verification where the product allows it
IIS, Exchange, StoreFront, Remote Desktop Services and nginx packages check the result after installing. Other packages report the outcome of their API calls.
Clean-up of old certificates
Windows packages can remove the certificate they replaced, so stores do not fill up with expired copies.
Custom scripts
When no package fits, a .ps1 or .sh script you place in a root- or administrator-owned directory on the agent host can run instead, with variables passed as environment variables.
Manual handoff by email
For a system nobody can automate, aethercert can send the issued certificate notice through your own Microsoft 365 or SMTP server so someone installs it.
Compared with deploying by hand
| By hand | With aethercert |
|---|---|
| Export a PFX, copy it to the server, import it, change the binding, restart - repeated per host. | The same signed package runs on every host, in the same order, every time. |
| Appliance certificates are uploaded through a web UI and committed manually. | The package uploads, binds and commits over the appliance API. |
| Private keys travel by email, file share or USB stick. | The key is generated on the agent and goes only to the system it is installed on. |
| Nobody notices a failed import until the old certificate expires. | A failed step fails the job, raises an event and, on Pro plans, an alert. |
Supported infrastructure
Every first-party package, grouped by where it runs. Each one links to its integration page with versions, authentication and prerequisites.
Microsoft and Windows Server
Citrix and VMware
Load balancers
Firewalls
Virtualization
Security considerations
Signed packages
Target Registry packages are signed, and the agent verifies the signature before it runs one. Community packages are disabled by default and governed by your organization policy.
Admin-only configuration
Only organization admins and owners can create or change deploy targets, because they run code on your hosts.
Encrypted credentials
Appliance passwords and API tokens are stored as secrets, encrypted at rest, and released to the agent only for the job that needs them.
Example: a renewed certificate on IIS
The steps of the Microsoft IIS package, as the agent runs them.
importImport certificate and key into LocalMachine\My on web-01.ensureBindingCreate the HTTPS binding for the site if it does not exist yet.assignBindingPoint the binding at the new certificate.verifyBindingConfirm the binding now references the new thumbprint.cleanupRemove the certificate that was replaced, if configured.
Frequently asked questions
Certificate deployment
Does the private key leave my server?
No. The agent generates the key and the signing request locally. For a target on the same host the key is used there; for an appliance target the agent sends it directly to that appliance over its management API from inside your network. The aethercert control plane never receives it.
What if my product is not in the list?
Use a custom script on the agent host, or build a Target Registry package for it - from a JSON manifest, with the package builder, or by drafting one with an AI assistant over MCP.
Does every target verify the deployment?
No. IIS, Exchange, StoreFront, Remote Desktop Services and nginx packages include a verification step. For other targets aethercert reports the result of the API calls or commands the package ran.
Can one certificate go to several servers?
Yes, through an agent group or a certificate policy. Each agent runs the deploy target for its own host.
Install your next certificate automatically
Enroll an agent, choose a target, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.