aethercert
Certificate deployment

Automated TLS certificate deployment

A renewal is only finished when the service is using the new certificate. aethercert installs every certificate where TLS actually terminates - a Windows role, a web server, a load balancer, a firewall - and reloads or activates it there.

Every Target Registry package is available on every plan, including Community. Custom scripts require Standard or higher. See plans and limits

A deploy target running its package steps on the agent host.
01Certificate deployment

What it does

After a certificate is issued or renewed, the agent that holds its private key runs the deploy target you attached to it. A deploy target is a signed Target Registry package: a reviewed sequence of steps that imports the certificate, binds it to the service, reloads or commits the configuration and, where the product allows it, checks that the new certificate is the one being served.

Targets on the same host run locally - PowerShell on Windows, files plus a service reload on Linux. Appliances and platforms with a management API (NetScaler, F5 BIG-IP, FortiGate, PAN-OS, vCenter, Kubernetes and others) are reached over that API by an agent on your network. Nothing connects in from the internet.

How it works

  1. 01

    Choose a target

    Pick a Target Registry package for the system - Microsoft IIS, Exchange, NetScaler ADC and others - or save one as a reusable deploy target with its connection details.

  2. 02

    The agent gets the material

    The private key never leaves the agent that generated it. For appliance targets the agent sends certificate and key to the appliance over its management API, from inside your network.

  3. 03

    The package runs its steps

    Import, bind, reload or commit, in the order the package defines. Each step is logged; a failed step stops the run and reports the step that failed.

  4. 04

    Result and retry

    Success is recorded on the certificate and in the event log. A failure is classified as permanent or temporary; temporary failures are retried before the job is marked failed and an alert is raised.

Key capabilities

29 first-party targets

Windows roles, Citrix and VMware, load balancers, firewalls, hypervisors, nginx, HAProxy, Docker and Kubernetes - every one a signed package maintained by aethercert.

Bindings, not just files

Packages bind the certificate to the service that uses it: IIS site bindings, Exchange services, the RDP listener, the SQL Server instance, a NetScaler certkey, an F5 client-SSL profile.

Verification where the product allows it

IIS, Exchange, StoreFront, Remote Desktop Services and nginx packages check the result after installing. Other packages report the outcome of their API calls.

Clean-up of old certificates

Windows packages can remove the certificate they replaced, so stores do not fill up with expired copies.

Custom scripts

When no package fits, a .ps1 or .sh script you place in a root- or administrator-owned directory on the agent host can run instead, with variables passed as environment variables.

Manual handoff by email

For a system nobody can automate, aethercert can send the issued certificate notice through your own Microsoft 365 or SMTP server so someone installs it.

Compared with deploying by hand

By handWith aethercert
Export a PFX, copy it to the server, import it, change the binding, restart - repeated per host.The same signed package runs on every host, in the same order, every time.
Appliance certificates are uploaded through a web UI and committed manually.The package uploads, binds and commits over the appliance API.
Private keys travel by email, file share or USB stick.The key is generated on the agent and goes only to the system it is installed on.
Nobody notices a failed import until the old certificate expires.A failed step fails the job, raises an event and, on Pro plans, an alert.

Supported infrastructure

Every first-party package, grouped by where it runs. Each one links to its integration page with versions, authentication and prerequisites.

All integrations

Security considerations

Signed packages

Target Registry packages are signed, and the agent verifies the signature before it runs one. Community packages are disabled by default and governed by your organization policy.

Admin-only configuration

Only organization admins and owners can create or change deploy targets, because they run code on your hosts.

Encrypted credentials

Appliance passwords and API tokens are stored as secrets, encrypted at rest, and released to the agent only for the job that needs them.

Example: a renewed certificate on IIS

The steps of the Microsoft IIS package, as the agent runs them.

  1. importImport certificate and key into LocalMachine\My on web-01.
  2. ensureBindingCreate the HTTPS binding for the site if it does not exist yet.
  3. assignBindingPoint the binding at the new certificate.
  4. verifyBindingConfirm the binding now references the new thumbprint.
  5. cleanupRemove the certificate that was replaced, if configured.

Frequently asked questions

Certificate deployment

Does the private key leave my server?

No. The agent generates the key and the signing request locally. For a target on the same host the key is used there; for an appliance target the agent sends it directly to that appliance over its management API from inside your network. The aethercert control plane never receives it.

What if my product is not in the list?

Use a custom script on the agent host, or build a Target Registry package for it - from a JSON manifest, with the package builder, or by drafting one with an AI assistant over MCP.

Does every target verify the deployment?

No. IIS, Exchange, StoreFront, Remote Desktop Services and nginx packages include a verification step. For other targets aethercert reports the result of the API calls or commands the package ran.

Can one certificate go to several servers?

Yes, through an agent group or a certificate policy. Each agent runs the deploy target for its own host.

Install your next certificate automatically

Enroll an agent, choose a target, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.