aethercert
Firewalls

Automated certificates for WatchGuard Firebox

For Fireboxes managed in WatchGuard Cloud, the package creates the renewed certificate in your WatchGuard Cloud account and installs it on the device.

The deployment steps defined in this package's manifest.

At a glance

Package
watchguard-target 2.0.0
Compatibility
Firebox >=12.0 <13.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
OAuth 2.0
Capabilities
Import certificate and keyActivate configuration
Deployment steps
createCertificate → installCertificate
Rollback
None
Key usage
No requirement

What it does

The agent authenticates to the WatchGuard Cloud API for your region with OAuth2 (access ID, access password and API key), creates the certificate and installs it on the configured Firebox.

The agent needs outbound access to the WatchGuard Cloud API host, not to the Firebox itself.

How it runs

  1. 01

    createCertificate

    The certificate is created in WatchGuard Cloud.

  2. 02

    installCertificate

    It is installed on the configured Firebox.

What you configure

  • WatchGuard Cloud API host for your region
  • Account id, access id, access password and API key (secrets stored encrypted)
  • Firebox device id
  • Certificate name

Prerequisites

  • Fireboxes managed through WatchGuard Cloud
  • WatchGuard Cloud API credentials

Limitations

  • Locally managed Fireboxes not connected to WatchGuard Cloud are not covered.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate WatchGuard Firebox

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.