aethercert
Certificate authorities

Active Directory Certificate Services automation

The CA connector is a small Windows service on your AD CS server. It lets every aethercert agent request certificates from your Enterprise CA through your own templates - and reports on the health of the CA while it is there.

At a glance

Connector
Windows service on the AD CS server; installed and updated like the agent
Listener
:8443 on your internal network; only agents connect to it
Authorization
Single-use ES256 token per job, verified locally and live with aethercert
Rights needed
Enroll on the template; Issue and Manage Certificates on the CA (for revocation)
Health checks
CRL and delta CRL freshness, CDP reachability, CA certificate expiry, weak keys, ESC6

What it does

Agents send their signing requests to the connector on your internal network. The connector submits them to AD CS with certreq against the template you configured and returns the issued certificate. Every request must carry a short-lived, single-use token minted by aethercert for that specific job, and the requested names are checked against it before anything reaches the CA.

On each check-in the connector also reports the CA's state: base and delta CRL freshness, reachability of every CDP location, CA certificate expiry, weak CA keys or signature algorithms, and whether EDITF_ATTRIBUTESUBJECTALTNAME2 (ESC6) is enabled. Findings appear in the dashboard and the event log; a hardening checklist covers what cannot be checked remotely.

How it runs

  1. 01

    Install and pair

    Run the installer on the CA server with a one-time pairing token. It finds the Enterprise CA in Active Directory and listens on :8443.

  2. 02

    Grant rights

    Give the connector's account Enroll on the template and Issue and Manage Certificates on the CA. A read-only preflight checks every prerequisite.

  3. 03

    Request

    An agent sends its CSR with a job-bound token; the connector verifies it locally and with aethercert, then submits to AD CS.

  4. 04

    Report

    Check-ins report templates and CA health; findings raise events and alerts.

What you configure

  • Certificate template (default WebServer)
  • Listen address (default :8443) and optional own TLS certificate
  • Service account: LocalSystem, a dedicated account or a gMSA

Prerequisites

  • An Enterprise CA in Active Directory
  • Windows Server for the connector, normally the CA server itself
  • Agents able to reach the connector on the internal network

Limitations

  • AD CS requires the Standard plan or higher.
  • The connector reports CA health but never changes the CA, templates or ACLs - remediation stays with you.

Frequently asked questions

Active Directory Certificate Services (AD CS)

Does the connector need inbound access from the internet?

No. Agents on your network connect to it; it connects out to aethercert for check-ins and token verification.

Can aethercert change my CA configuration?

No. The connector only submits and revokes requests and reads CA state. Hardening findings tell you what to change; you change it.

Automate Active Directory Certificate Services (AD CS)

Connect it once in the dashboard; every issuance and renewal uses it from then on.

Community plan, no card required. Open registration - your account is ready in a few minutes.