Certificate policies for server groups
Fifty servers that each need their own certificate should not mean fifty certificate requests. A certificate policy is a standing rule on an agent group: every member gets its certificate now, and every server that joins the group later gets one too.
Agent groups and certificate policies require Standard or higher. See plans and limits
- CA
- Corp Issuing CA
- template
- {hostname}.corp.example.com
What it does
A policy combines a certificate authority, a hostname template, a key type, a renewal window and a deploy target, and applies to an agent group. aethercert creates one certificate per member, built from that agent's own hostname, and keeps it renewed.
Agents enrolled with a multi-provision token can join a group automatically, so a server built from a golden image, cloud-init or Group Policy receives its certificate without anyone opening the dashboard. Each policy decides in advance whether a certificate it no longer covers keeps renewing or is retired and revoked.
How it works
- 01
Group the agents
Put servers with the same role in an agent group - for example all RD Session Hosts or all WinRM endpoints.
- 02
Define the rule
Choose CA, hostname template such as {hostname}.corp.example.com, key type, renewal window and deploy target.
- 03
Roll out
The policy creates a certificate job per member in batches and shows rollout progress.
- 04
Keep it current
New members are picked up automatically; every certificate renews on its own schedule.
Key capabilities
One certificate per agent
Each server gets its own key and certificate, generated on that server.
Hostname templates
Build names from each agent's hostname, so one policy covers the whole group.
Automatic for new members
A server that joins the group later receives its certificate without further action.
Rollout state
See which members have their certificate, which are pending and which failed.
Keep or retire
When a policy stops applying to an agent, its certificate either keeps renewing or is retired: auto-renew off and a revoke job queued.
Unattended enrollment
Multi-provision tokens for golden images, cloud-init, configuration management and Group Policy.
Compared with requesting per server
| By hand | With aethercert |
|---|---|
| A certificate request per server, per year, per person who remembers. | One policy, applied to every member of the group. |
| New servers go into production without a certificate. | Joining the group is enough to get one. |
| Decommissioned servers keep certificates nobody tracks. | A policy set to retire revokes the certificate when the server leaves the group. |
Typical targets
Policies fit roles where every server needs its own certificate for its own name.
Security considerations
Keys stay per host
Each member generates its own key; no key is copied between servers.
Template-bound AD CS issuance
With the CA connector, the AD CS template pinned to the request decides what may be issued.
Scoped enrollment tokens
Multi-provision tokens can be limited and revoked like any other enrollment credential.
Example: certificates for every RD Session Host
A policy on the group rdsh, issued from AD CS.
policyCA: Corp Issuing CA · template {hostname}.corp.example.com · target: RDP listener.rollout12 members, 12 certificate jobs queued in batches.joinrdsh-13 is built from the golden image and enrolls into the group.issuerdsh-13.corp.example.com is issued and bound to its RDP listener.
Frequently asked questions
Certificate policies
Can one certificate be shared by all members?
Per-agent mode - one certificate per member - works with every authority. A single shared certificate is only available for certificates ordered through the certificate connector, which keeps the key on its own host.
What happens when an agent leaves the group?
That depends on the policy. With Keep (the default) the certificate stays and keeps renewing, no longer managed by the policy. With Retire, auto-renew is switched off and a revoke job is queued.
Do policies work with Let's Encrypt?
Yes, with any authority your plan allows. With ACME authorities each name still needs to be validated, typically with DNS-01.
Cover a whole server role with one rule
Create an agent group, attach a policy, and new servers get their certificates on their own.
Community plan, no card required. Open registration - your account is ready in a few minutes.