aethercert
How it works

How aethercert works

A hosted control plane decides what should happen and when. Agents and connectors on your own network do the work - generating keys, talking to certificate authorities and installing certificates - and only ever connect outward.

aethercert's components and the direction of every connection.
01Components

Four parts, one direction of trust

Everything that touches a private key or your infrastructure runs on your network.

Control plane

The dashboard and API, hosted in Germany. It holds the inventory, schedules renewals, queues jobs and keeps the event log. It stores certificate metadata and encrypted credentials - never private keys.

Agent

A service on Windows or Linux. It polls for jobs, generates keys and CSRs, answers ACME challenges, runs deploy targets and scans its host for installed certificates.

CA connector

A Windows service on your AD CS server. Agents send it signing requests with single-use tokens; it submits them to your templates and reports CA health.

Certificate connector

A service that orders commercial certificates from PSW Group, keeps their keys in an encrypted local store and releases them to approved agents.

02Lifecycle

One certificate, from discovery to renewal

1. Enroll

Install the agent with a one-time or multi-provision token. It registers and starts checking in.

2. Discover

The agent scans its host and reports the certificates already installed.

3. Issue

A job asks the agent for a certificate. It generates the key, validates the domain or calls the CA connector, and receives the signed certificate.

4. Deploy

The agent runs the deploy target - a signed package or your own script - and reports the result.

5. Renew

Before expiry, the control plane queues the next renewal, and the same steps run again with a new key.

6. Monitor

Expiry, failures and offline agents become events, pushed to your monitoring where configured.

03Network

Outbound only

No component needs an inbound connection from the internet.

Agents to the control plane

HTTPS on port 443. By default an idle agent checks in every three hours; when work is queued, it checks in within seconds.

Agents to connectors

Inside your network: the CA connector listens on 8443, the certificate connector on its own port. The control plane never sees this traffic.

Agents to appliances

REST packages reach load balancers and firewalls over their management interfaces on your network.

Challenge validation

Only HTTP-01 and TLS-ALPN-01 need the CA to reach port 80 or 443 on the host, and only while an issuance runs. DNS-01 needs nothing inbound.

04Data

What leaves your network, and what does not

Sent to the control plane

Certificate metadata - serial, fingerprint, names, validity - job results, agent health and the certificates discovered on each host.

Stored encrypted

Credentials you enter: DNS provider tokens, appliance passwords, CA and reseller credentials. Released to an agent only for the job that needs them.

Never sent

Private keys. They are generated by the agent or the certificate connector and stay in your network.

Frequently asked questions

How it works

Do I need to open firewall ports?

Not for the control plane: agents connect out on 443. Inside your network, agents need to reach the CA connector or appliances they deploy to. HTTP-01 and TLS-ALPN-01 require the CA to reach the host; DNS-01 does not.

What happens if the control plane is unreachable?

Certificates already installed keep working. Queued renewals wait until agents can check in again; renewing well before expiry leaves room for that.

Which operating systems does the agent run on?

Windows and Linux. It can also run in a container or under your own process supervisor without registering an operating-system service.

See it on your own servers

Install one agent and follow a certificate from discovery to automatic renewal.

Community plan, no card required. Open registration - your account is ready in a few minutes.