For small and mid-sized companies

Your IT has better things to do

You have a few servers, a website, a mail system and some internal applications - and one or two people who look after all of it. Certificate renewals should not be one more thing on that list, and with aethercert they are not.

Free plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.

One certificate, start to finish - and then again, on its own, before it expires.

What changes

Four recurring tasks that stop existing

Not a new system to administer. One less category of work.

No spreadsheet of expiry dates

The agent on each server reports what is installed there, so the list maintains itself instead of being reconstructed every few months by whoever has time.

No calendar reminders

A renewal is queued a month before the expiry date and carried out without anybody being told to do it. Nothing to snooze, nothing to hand over when someone leaves.

No emergency renewals

Failed attempts retry on their own and show up in the dashboard with the reason. The certificate that is already installed keeps serving while that happens.

No need to become a PKI expert

Name the hostname, pick where the certificate should be installed from a list, and leave the rest. Let's Encrypt is set up on every account and needs no configuration at all.

TodayWith aethercert
Someone notices a certificate expires next weekThe renewal already happened a month ago
Find out where it is installed, and howThe dashboard says which server and which service
Renew it, download the files, copy them overA new key is generated on the server itself
Import it, update the binding, restart the serviceInstalled and the service reloaded automatically
Hope nothing else expires this monthSee everything that expires in the next 30 days
Day one

It starts by telling you what you already have

Before anything is automated, the agents report the certificates already installed on your servers. For most companies that list is the first complete one they have ever had - and it is usually where the unpleasant surprises are.

  • Sorted by whichever expires next, so the urgent one is at the top
  • Includes the certificates aethercert did not issue - the ones a predecessor installed and nobody wrote down
  • Says which server each one is on, and who issued it
dash.aethercert.com/dashboard/manage/certificates
The certificates screen showing issued and already-installed certificates side by side, sorted by expiry date, with expired ones marked.
Managed and discovered certificates in one list, soonest expiry first.
What it covers

The systems a business like yours actually runs

A certificate is only done when the service is serving it. These are the places aethercert installs one for you, rather than leaving a file for someone to move.

Your website and web applications

IIS, where aethercert also updates the site's HTTPS binding, and NGINX or Apache on Linux, where it writes the files, fixes the key permissions the web server needs and reloads the service. Applications in Docker containers are covered too.

Your mail server

For Exchange, the certificate is imported and enabled for the services you choose - SMTP, IIS, POP, IMAP. For a Linux mail server, the certificate and key are written to the paths Postfix or Dovecot already read and the service is reloaded.

Remote access

The Remote Desktop listener on a single server, or a full Remote Desktop Services deployment - Gateway, Web Access, Connection Broker or Licensing. WinRM's HTTPS listener as well, for PowerShell remoting.

Internal applications nobody can reach from outside

With a DNS provider connected, certificates are validated over DNS, so a hostname that only resolves inside your network still gets a publicly trusted certificate. Wildcards work the same way.

Load balancers and appliances in front

A Citrix NetScaler is updated over its management API by any agent that can reach it, on either operating system.

Everything else

Any service that reads a certificate and key from disk: give aethercert the two paths and the command that restarts it. For anything more involved, it runs a script you have already placed on that server yourself.

The full list, with what each one needs on the host, is in the documentation.

Before you install anything

What this actually puts on your servers

A small service that dials out. That is the whole footprint, and it is worth being precise about it.

  • It only makes outbound connections

    Nothing listens, so there is no firewall rule to open, no VPN and no need for a public address. It works from behind NAT exactly as it does anywhere else.

  • It only looks at its own machine

    The agent inventories the certificates on the server it is installed on. It does not probe the rest of your network.

  • Your private keys never leave that server

    Each key is created on the machine that will use it and stays there. We hold the serial number, the fingerprint and the expiry date - nothing that could be used to impersonate you.

  • Nobody can push code through the dashboard

    If you want a script run after a renewal, you put it on the server yourself. The dashboard can only name a script that is already there.

  • It runs in Germany

    Application in Nuremberg, database in Frankfurt. Storage and processing stay inside the country.

Security and data handling, in detail

An external IT provider looks after your servers?

That works either way round. They can run aethercert for you from their own account, or you can keep the account and invite them into it - as an administrator who configures everything, or with read-only access so you can see the state of your certificates without changing anything.

How providers use aethercert

Try it on one server first

The Free plan covers one certificate on one server with Let's Encrypt and needs no payment details. That is enough to see the whole thing work on something real before it goes anywhere near the rest of your infrastructure.

Free plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.