aethercert
Load balancers

Automated certificate renewal for Progress Kemp LoadMaster

The LoadMaster package uploads the renewed certificate under a fixed name, replacing it in place, and can bind it to a virtual service.

The deployment steps defined in this package's manifest.

At a glance

Package
kemp-loadmaster-target 2.0.0
Compatibility
LoadMaster >=7.2 <8.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
HTTP basic authentication
Capabilities
Import certificate and keyUpdate binding
Deployment steps
uploadCertificate → bindVirtualService*
Rollback
None
Key usage
No requirement

* conditional step

What it does

An agent on your network calls the LoadMaster API with an API user, adds the certificate on first issue and replaces it in place on renewal.

If you configure a virtual service, the certificate is bound to it in the same run.

How it runs

  1. 01

    uploadCertificate

    Certificate and key are uploaded under the configured name, replacing the previous one.

  2. 02

    bindVirtualService

    The certificate is bound to the virtual service, if configured.

What you configure

  • Management host and port
  • API username and password (stored encrypted)
  • Certificate name
  • Optional virtual service id

Prerequisites

  • An agent with network access to the LoadMaster management interface
  • The LoadMaster API enabled for that user

Limitations

  • One virtual service per deploy target.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Progress Kemp LoadMaster

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.