aethercert
Enterprise IT

Certificate lifecycle management for enterprise IT

Large estates do not fail for lack of tools; they fail at the seams between teams, servers and appliances. aethercert gives infrastructure, security and operations one inventory, one renewal process and one audit trail - with the access controls a larger organization expects.

The organization's event log.
01Enterprise IT

The problem

In larger organizations, certificates are owned by many teams and issued by several authorities - public CAs, AD CS, sometimes a commercial reseller - and nobody has the full picture.

Fragmented ownership

Web, Windows, network and platform teams each renew their own certificates their own way.

Multiple authorities

Public ACME, internal AD CS and commercial certificates live in separate processes.

Governance

Security needs to know who changed what, and wants alerts in the SIEM rather than in a mailbox.

Business impact

Outages across team boundaries

A certificate that belongs to nobody in particular is the one that expires.

Audit effort

Answering "who issued and deployed this certificate" means piecing together several systems.

Operational load

Shorter certificate lifetimes multiply every team's renewal work at the same time.

The technical problem

An enterprise estate mixes Windows roles, Linux services, load balancers, firewalls, hypervisors and Kubernetes. Issuance comes from public and private authorities; deployment differs per system; validation differs per domain.

Any platform that covers it needs fine-grained access, an audit trail, integration into existing monitoring and a security model the security team can sign off - without becoming another tool that needs inbound firewall rules.

The aethercert approach

One control plane for every authority and target, with access and audit built in.

  1. 01

    Sign in with Entra ID

    Connect your own Microsoft Entra ID app registration so your Conditional Access decides who gets in; MFA is mandatory.

  2. 02

    Assign roles

    Viewer, member, admin and owner - only admins may configure deploy targets, because they run code on hosts.

  3. 03

    Cover every authority

    ACME CAs, AD CS through the CA connector, internal REST CAs and PSW Group through the certificate connector.

  4. 04

    Scale with policies

    Agent groups and certificate policies issue per server; multi-provision tokens enroll servers unattended.

  5. 05

    Feed your SOC

    Alert-worthy events to syslog/CEF, SNMP or HMAC-signed webhooks; fleet metrics to Prometheus, CheckMK, Grafana or Zabbix.

Architecture

A hosted control plane and components on your network that only connect outward.

Hosted in Germany

The application is hosted at Hetzner in Nuremberg and the database in Frankfurt.

Outbound-only components

Agents, the CA connector and the certificate connector poll over HTTPS. No inbound connections from the internet.

Signed releases, staged rollout

Agent updates are signed and verified before installation, delivered through release channels with staged rollout, pinning and rollback.

Security

Keys never reach the cloud

Private keys are generated on agents or the certificate connector and never stored by the control plane.

Signed, policy-governed packages

Deployment packages are signed; an organization registry policy controls which publishers may run.

Audit trail

Every change is recorded with its actor and kept for 90 days on Pro.

Implementation considerations

Plan sizing

Pro covers up to 1,000 agents, 1,500 certificates and 25 verified domains per organization.

Rollout

Enroll agents with multi-provision tokens through Group Policy, configuration management or golden images.

Network

Agents need outbound HTTPS to aethercert; agents running appliance packages need access to those management interfaces.

Responsibilities

Decide which team owns which deploy targets; only admins can change them.

Frequently asked questions

Enterprise IT

Is aethercert available on premises?

No. aethercert is a hosted service; the components that touch keys and your infrastructure run on your network and connect outward.

Is there a public API?

Not for general automation today. Monitoring has a Prometheus-format metrics API, and Target Registry packages can be drafted over MCP. Everything else is done in the dashboard.

Which identity providers are supported for SSO?

Microsoft Entra ID, using your own app registration. Members can also sign in with email, password and a mandatory second factor, including passkeys.

Evaluate aethercert on your own estate

Start with discovery on a handful of servers and an appliance, then expand by policy.

Open registration - your account is ready in a few minutes.