Certificate automation for firewalls and load balancers
Appliances are where certificate renewal is still done by hand: export, log in to the web UI, upload, bind, commit. aethercert does it through each appliance's management API from an agent inside your network.
"apiVersion": "registry.aethercert.com/v2""kind": "DeploymentTarget""name": "netscaler-target""version": "2.0.0""versions": [">=13.0 <15.0"]"capabilities": ["certificate.importWithPrivateKey","certificate.inventory", "configuration.activate"]"permissions": { "network": ["{{ config.host }}"] }
The problem
Load balancers, VPN gateways and firewalls terminate TLS for the most visible services - the website, the VPN portal, the remote-access gateway - but no ACME client runs on them.
GUI-only routines
Uploading a certificate and key, updating the certificate object and committing is a manual procedure on most appliances.
Keys in transit
Generating a CSR on a workstation and carrying the key to the appliance exposes it more than necessary.
Commit and sync
A forgotten commit or save leaves the old certificate in place after a reboot.
Business impact
Visible outages
An expired certificate on the VPN portal or load balancer affects every user at once.
Change windows
Manual appliance changes are scheduled, reviewed and executed by scarce network staff.
Shorter lifetimes
With 100- and 47-day certificates, appliance renewals become a monthly task.
The technical problem
Every vendor has a different API: NITRO on NetScaler, iControl REST on F5, the FortiOS REST API, the PAN-OS XML API with a separate commit, WatchGuard Cloud with OAuth2, the FMC REST API with domain UUIDs. Each also has its own idea of certificate objects and activation.
Scripts that bridge them tend to live on one admin's machine, with stored credentials and no record of what ran.
The aethercert approach
One signed package per appliance family, run by an agent you already trust, with credentials released only for the job.
- 01
Place an agent near the appliance
Any Windows or Linux agent with network access to the management interface can run REST packages.
- 02
Store the API credential
Username and password, API key or token, encrypted at rest.
- 03
Attach the package
NetScaler, F5, Kemp, FortiGate, PAN-OS, Sophos, WatchGuard, Cisco FMC - or vCenter, Nutanix and Proxmox for virtualization platforms.
- 04
Renew and deploy together
Upload, bind, commit or save - the package runs the vendor's sequence on every renewal.
Architecture
The appliance is never reached from the internet.
Agent as the bridge
The agent that generated the key connects to the appliance management API on your internal network.
Declared destinations
A REST package can only connect to the host built from your configuration.
Outbound control
The agent receives jobs by polling aethercert over HTTPS.
Integrations
Security
Keys stay inside
The private key travels from the agent to the appliance directly, over your network, never through aethercert's cloud.
Secrets per job
Appliance credentials are released to the agent only for the job that uses them.
Signed, versioned packages
Each appliance package is signed and pinned per installation; updates are explicit.
Implementation considerations
API accounts
Create a dedicated API user or token per appliance with only the certificate permissions it needs.
First binding
Bind the certificate object to virtual servers, VPN portals or profiles once; renewals update the same object.
Management certificates
If the appliance management interface uses a self-signed certificate, the package can be told to accept it.
Commits
PAN-OS commits and FMC deployments include other pending changes; coordinate with your change process.
Frequently asked questions
Firewalls and load balancers
Does the agent have to run on the appliance?
No. Any aethercert agent on your network that can reach the appliance management interface runs the package.
What if my appliance is not supported?
If it has a REST API, a package can be built for it - from JSON, with the visual builder, from its OpenAPI description or with an AI assistant over MCP.
Are commits automatic?
Where the package includes it - PAN-OS commit, NetScaler save config, WatchGuard install, FMC deploy - yes.
Take appliances off the manual list
Connect one appliance through an agent you already run and let the next renewal install itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.