aethercert
Linux and containers

Automated certificates for Linux services

Most Linux services read their certificate from two PEM files and pick up a new one on reload. The Linux package covers all of them: Apache, Postfix, Dovecot, and anything else that works the same way.

The deployment steps defined in this package's manifest.

At a glance

Package
linux-file-target 2.0.0
Compatibility
Linux (systemd) >=1.0 <2.0
Runs from
A Linux agent on the server
Mechanism
Files on disk · Service reload or restart
Authentication
Local - no remote login
Capabilities
Import certificateImport private keyReload service
Deployment steps
writeCertificate → writePrivateKey → reloadService*
Rollback
None
Key usage
No requirement

* conditional step

What it does

The agent on the server writes the certificate followed by its chain to one path and the private key to another, then reloads the systemd unit you name.

For nginx and HAProxy there are dedicated packages with service-specific defaults - nginx also verifies the served certificate. For services that need more than files and a reload, use a custom shell script.

How it runs

  1. 01

    writeCertificate

    Certificate plus chain is written to the certificate path.

  2. 02

    writePrivateKey

    The key is written to the key path.

  3. 03

    reloadService

    The systemd unit is reloaded, if one is set.

What you configure

  • Certificate path
  • Private key path
  • systemd unit to reload, for example apache2, postfix or dovecot

Prerequisites

  • A Linux agent on the server
  • A systemd-managed service that reads PEM files

Limitations

  • No built-in verification step; use the nginx package or a custom script when you need one.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Linux servers (Apache, Postfix, Dovecot)

Does it work for Postfix and Dovecot?

Yes. Point the paths at the files smtpd_tls_cert_file / ssl_cert reference and reload the service.

What about services that need a combined PEM?

HAProxy has its own package that writes a combined bundle. Anything else can use a custom script.

Automate Linux servers (Apache, Postfix, Dovecot)

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.