How aethercert works
A hosted control plane decides what should happen and when. Agents and connectors on your own network do the work - generating keys, talking to certificate authorities and installing certificates - and only ever connect outward.
Control plane
dashboard · API · scheduler — hosted in Germany
Your network
Agents
Windows · Linux
CA connector
AD CS · :8443
Certificate connector
PSW Group
Four parts, one direction of trust
Everything that touches a private key or your infrastructure runs on your network.
Control plane
The dashboard and API, hosted in Germany. It holds the inventory, schedules renewals, queues jobs and keeps the event log. It stores certificate metadata and encrypted credentials - never private keys.
Agent
A service on Windows or Linux. It polls for jobs, generates keys and CSRs, answers ACME challenges, runs deploy targets and scans its host for installed certificates.
CA connector
A Windows service on your AD CS server. Agents send it signing requests with single-use tokens; it submits them to your templates and reports CA health.
Certificate connector
A service that orders commercial certificates from PSW Group, keeps their keys in an encrypted local store and releases them to approved agents.
One certificate, from discovery to renewal
1. Enroll
Install the agent with a one-time or multi-provision token. It registers and starts checking in.
2. Discover
The agent scans its host and reports the certificates already installed.
3. Issue
A job asks the agent for a certificate. It generates the key, validates the domain or calls the CA connector, and receives the signed certificate.
4. Deploy
The agent runs the deploy target - a signed package or your own script - and reports the result.
5. Renew
Before expiry, the control plane queues the next renewal, and the same steps run again with a new key.
6. Monitor
Expiry, failures and offline agents become events, pushed to your monitoring where configured.
Outbound only
No component needs an inbound connection from the internet.
Agents to the control plane
HTTPS on port 443. By default an idle agent checks in every three hours; when work is queued, it checks in within seconds.
Agents to connectors
Inside your network: the CA connector listens on 8443, the certificate connector on its own port. The control plane never sees this traffic.
Agents to appliances
REST packages reach load balancers and firewalls over their management interfaces on your network.
Challenge validation
Only HTTP-01 and TLS-ALPN-01 need the CA to reach port 80 or 443 on the host, and only while an issuance runs. DNS-01 needs nothing inbound.
What leaves your network, and what does not
Sent to the control plane
Certificate metadata - serial, fingerprint, names, validity - job results, agent health and the certificates discovered on each host.
Stored encrypted
Credentials you enter: DNS provider tokens, appliance passwords, CA and reseller credentials. Released to an agent only for the job that needs them.
Never sent
Private keys. They are generated by the agent or the certificate connector and stay in your network.
Related features
Frequently asked questions
How it works
Do I need to open firewall ports?
Not for the control plane: agents connect out on 443. Inside your network, agents need to reach the CA connector or appliances they deploy to. HTTP-01 and TLS-ALPN-01 require the CA to reach the host; DNS-01 does not.
What happens if the control plane is unreachable?
Certificates already installed keep working. Queued renewals wait until agents can check in again; renewing well before expiry leaves room for that.
Which operating systems does the agent run on?
Windows and Linux. It can also run in a container or under your own process supervisor without registering an operating-system service.
See it on your own servers
Install one agent and follow a certificate from discovery to automatic renewal.
Community plan, no card required. Open registration - your account is ready in a few minutes.