Your IT has better things to do
You have a few servers, a website, a mail system and some internal applications - and one or two people who look after all of it. Certificate renewals should not be one more thing on that list, and with aethercert they are not.
Free plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.
aethercert
control plane
Let's Encrypt
ACME authority
web-01
aethercert agent
app.example.com
nginx :443
Job dispatched to the agent
issue app.example.comOne certificate, start to finish - and then again, on its own, before it expires.
Four recurring tasks that stop existing
Not a new system to administer. One less category of work.
No spreadsheet of expiry dates
The agent on each server reports what is installed there, so the list maintains itself instead of being reconstructed every few months by whoever has time.
No calendar reminders
A renewal is queued a month before the expiry date and carried out without anybody being told to do it. Nothing to snooze, nothing to hand over when someone leaves.
No emergency renewals
Failed attempts retry on their own and show up in the dashboard with the reason. The certificate that is already installed keeps serving while that happens.
No need to become a PKI expert
Name the hostname, pick where the certificate should be installed from a list, and leave the rest. Let's Encrypt is set up on every account and needs no configuration at all.
It starts by telling you what you already have
Before anything is automated, the agents report the certificates already installed on your servers. For most companies that list is the first complete one they have ever had - and it is usually where the unpleasant surprises are.
- Sorted by whichever expires next, so the urgent one is at the top
- Includes the certificates aethercert did not issue - the ones a predecessor installed and nobody wrote down
- Says which server each one is on, and who issued it

The systems a business like yours actually runs
A certificate is only done when the service is serving it. These are the places aethercert installs one for you, rather than leaving a file for someone to move.
Your website and web applications
IIS, where aethercert also updates the site's HTTPS binding, and NGINX or Apache on Linux, where it writes the files, fixes the key permissions the web server needs and reloads the service. Applications in Docker containers are covered too.
Your mail server
For Exchange, the certificate is imported and enabled for the services you choose - SMTP, IIS, POP, IMAP. For a Linux mail server, the certificate and key are written to the paths Postfix or Dovecot already read and the service is reloaded.
Remote access
The Remote Desktop listener on a single server, or a full Remote Desktop Services deployment - Gateway, Web Access, Connection Broker or Licensing. WinRM's HTTPS listener as well, for PowerShell remoting.
Internal applications nobody can reach from outside
With a DNS provider connected, certificates are validated over DNS, so a hostname that only resolves inside your network still gets a publicly trusted certificate. Wildcards work the same way.
Load balancers and appliances in front
A Citrix NetScaler is updated over its management API by any agent that can reach it, on either operating system.
Everything else
Any service that reads a certificate and key from disk: give aethercert the two paths and the command that restarts it. For anything more involved, it runs a script you have already placed on that server yourself.
The full list, with what each one needs on the host, is in the documentation.
What this actually puts on your servers
A small service that dials out. That is the whole footprint, and it is worth being precise about it.
It only makes outbound connections
Nothing listens, so there is no firewall rule to open, no VPN and no need for a public address. It works from behind NAT exactly as it does anywhere else.
It only looks at its own machine
The agent inventories the certificates on the server it is installed on. It does not probe the rest of your network.
Your private keys never leave that server
Each key is created on the machine that will use it and stays there. We hold the serial number, the fingerprint and the expiry date - nothing that could be used to impersonate you.
Nobody can push code through the dashboard
If you want a script run after a renewal, you put it on the server yourself. The dashboard can only name a script that is already there.
It runs in Germany
Application in Nuremberg, database in Frankfurt. Storage and processing stay inside the country.
An external IT provider looks after your servers?
That works either way round. They can run aethercert for you from their own account, or you can keep the account and invite them into it - as an administrator who configures everything, or with read-only access so you can see the state of your certificates without changing anything.
How providers use aethercertTry it on one server first
The Free plan covers one certificate on one server with Let's Encrypt and needs no payment details. That is enough to see the whole thing work on something real before it goes anywhere near the rest of your infrastructure.
Free plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.