aethercert
Network appliances

Certificate automation for firewalls and load balancers

Appliances are where certificate renewal is still done by hand: export, log in to the web UI, upload, bind, commit. aethercert does it through each appliance's management API from an agent inside your network.

An excerpt of a first-party Target Registry manifest.
01Network appliances

The problem

Load balancers, VPN gateways and firewalls terminate TLS for the most visible services - the website, the VPN portal, the remote-access gateway - but no ACME client runs on them.

GUI-only routines

Uploading a certificate and key, updating the certificate object and committing is a manual procedure on most appliances.

Keys in transit

Generating a CSR on a workstation and carrying the key to the appliance exposes it more than necessary.

Commit and sync

A forgotten commit or save leaves the old certificate in place after a reboot.

Business impact

Visible outages

An expired certificate on the VPN portal or load balancer affects every user at once.

Change windows

Manual appliance changes are scheduled, reviewed and executed by scarce network staff.

Shorter lifetimes

With 100- and 47-day certificates, appliance renewals become a monthly task.

The technical problem

Every vendor has a different API: NITRO on NetScaler, iControl REST on F5, the FortiOS REST API, the PAN-OS XML API with a separate commit, WatchGuard Cloud with OAuth2, the FMC REST API with domain UUIDs. Each also has its own idea of certificate objects and activation.

Scripts that bridge them tend to live on one admin's machine, with stored credentials and no record of what ran.

The aethercert approach

One signed package per appliance family, run by an agent you already trust, with credentials released only for the job.

  1. 01

    Place an agent near the appliance

    Any Windows or Linux agent with network access to the management interface can run REST packages.

  2. 02

    Store the API credential

    Username and password, API key or token, encrypted at rest.

  3. 03

    Attach the package

    NetScaler, F5, Kemp, FortiGate, PAN-OS, Sophos, WatchGuard, Cisco FMC - or vCenter, Nutanix and Proxmox for virtualization platforms.

  4. 04

    Renew and deploy together

    Upload, bind, commit or save - the package runs the vendor's sequence on every renewal.

Architecture

The appliance is never reached from the internet.

Agent as the bridge

The agent that generated the key connects to the appliance management API on your internal network.

Declared destinations

A REST package can only connect to the host built from your configuration.

Outbound control

The agent receives jobs by polling aethercert over HTTPS.

Security

Keys stay inside

The private key travels from the agent to the appliance directly, over your network, never through aethercert's cloud.

Secrets per job

Appliance credentials are released to the agent only for the job that uses them.

Signed, versioned packages

Each appliance package is signed and pinned per installation; updates are explicit.

Implementation considerations

API accounts

Create a dedicated API user or token per appliance with only the certificate permissions it needs.

First binding

Bind the certificate object to virtual servers, VPN portals or profiles once; renewals update the same object.

Management certificates

If the appliance management interface uses a self-signed certificate, the package can be told to accept it.

Commits

PAN-OS commits and FMC deployments include other pending changes; coordinate with your change process.

Frequently asked questions

Firewalls and load balancers

Does the agent have to run on the appliance?

No. Any aethercert agent on your network that can reach the appliance management interface runs the package.

What if my appliance is not supported?

If it has a REST API, a package can be built for it - from JSON, with the visual builder, from its OpenAPI description or with an AI assistant over MCP.

Are commits automatic?

Where the package includes it - PAN-OS commit, NetScaler save config, WatchGuard install, FMC deploy - yes.

Take appliances off the manual list

Connect one appliance through an agent you already run and let the next renewal install itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.