Certificate automation

Set it up once. Never chase a renewal again.

Certificate automation issues, renews, deploys, and verifies your SSL certificates without manual steps, so a certificate never expires because someone forgot. You point one DNS record at CertKit, and the whole cycle runs on its own from then on.

Start free trial See how it works

The manual way doesn't scale

Managing certificates by hand is a standing chore: a spreadsheet of expiry dates, calendar reminders, an OpenSSL command you look up every time, and a renewal job on each server that someone has to babysit. It works until it doesn't, usually at 2am, usually while the person who set it up is on vacation.

It gets harder every year. The 200-day maximum is already in effect, and 47-day certificates are coming by 2029. A renewal that used to happen once a year will happen roughly twelve times a year, on every certificate, on every server. At that cadence, manual renewal stops being a process and becomes a liability. Read about the certificate lifetime mandate.

How certificate automation works

CertKit acts as a central ACME client for all your domains. You add your domains and point one delegated DNS CNAME record at CertKit. After that, CertKit requests and renews every certificate on its own, and the CertKit Agent deploys each one to your servers and appliances and confirms it is being served. That one record is everything required to automate SSL certificate renewal across your fleet.

 ┌───────┐   ┌────────┐   ┌─────────┐   ┌───────┐
 │ Issue │──►│ Deploy │──►│ Monitor │──►│ Renew │──┐
 └───┬───┘   └────────┘   └─────────┘   └───────┘  │
     ▲                                             │
     └──────────── repeats, unattended ────────────┘

Set it up once. CertKit issues, deploys, monitors, and renews on schedule, with nobody in the loop.

No scripts. No cron jobs. No ACME client to install on each box. No 2am alerts when something expires.

Certificate renewal automation, end to end

Renewal is where manual processes break down, because it never stops. CertKit tracks the expiration date of every certificate and renews each one well before its deadline. There is no renewal job to schedule and no reminder to snooze. The renewed certificate is deployed to every server and appliance that uses it, and the old one ages out on its own.

A renewed certificate that never gets deployed is just a file on the wrong server. That gap is why teams with renewal scripts still get expiry outages. When you automate SSL certificate renewal with CertKit, renewal, deployment, and verification run as one motion, so the certificate your users see is always the current one.

Issuance automation is not certificate automation

Plenty of tools automate part of the job. The gap is what happens after a certificate is issued.

Issuance automation

Tools like Certbot automate getting a certificate on the one box they run on. You still wire up the renewal job, the deployment, and the service restart on every server yourself, and nothing reaches the appliances that can't run ACME.

Certificate automation

CertKit automates the whole cycle from one account: issue, renew, deploy to every server and appliance, and verify. There is no per-server script to maintain, and no step left waiting on someone.

Issuance was the easy part all along. Deployment is where certificates actually break, and distribution is the last mile.

Verification is the success signal

Most automation stops at "renewal succeeded." The CA said ok, the client exited 0, a file got written. None of that proves your site is serving the new certificate.

CertKit verifies every deployment from the outside: a real TLS handshake against the public hostname, checking the expiry date, the names on the certificate, and the full chain. Not "the file exists," but "real clients see the new certificate." Every hostname, after every renewal. How to verify a certificate renewal.

Why CertKit's automation is different

SSL automation for more than web servers

Certificates live everywhere TLS terminates: load balancers, firewalls, mail servers, VPN appliances, and the legacy box nobody wants to touch. Most of those can't run an ACME client at all. SSL certificate automation only counts when it reaches every one of them.

The CertKit Agent deploys renewed certificates to Windows and Linux servers directly and pushes them to appliances like FortiGate, F5, and Palo Alto through pre-built integrations, in the format each one expects. One automation pipeline for the whole fleet, not one script per box.

Works with your certificate authority

CertKit automates issuance and renewal from the public CAs teams use most. Move to a free CA like Let's Encrypt or Google Trust Services once renewal is automated, or stay with the commercial CA you already have. You are never locked in.

When no public CA can issue what you need, for an internal hostname, an IP address, or an mTLS client certificate, CertKit can be the certificate authority. Managed PKI issues from a private CA and automates it the same way.

Automation is one stage of the lifecycle

Certificate renewal automation is the stage that removes the most work, but it is one part of certificate lifecycle management. CertKit also discovers the certificates you forgot about and monitors every one, so nothing slips through, and it deploys to your servers and appliances automatically.

Start free trial See how it works

CertKit has been a fantastic solution for automating our environment’s SSL/TLS certificates. With a single pane of glass for centralized management, visibility, and monitoring and the highly customizable interface for granular control over individual systems, we have found great value in reducing the time and complexity of managing an ad-hoc ACME solution for individual certificate automation.

Seth Allums, Lead Systems and Information Security Engineer, Clackamas Community College

Frequently asked questions

Do I have to run an ACME client or script on each server?

No. CertKit issues and renews every certificate centrally. The CertKit Agent then deploys each one to your servers and appliances, so there is no ACME client, renewal script, or cron job to maintain on each box.

Why servers shouldn't need ACME

Can I automate the certificates I already have?

Yes. You reissue them through CertKit for the same domains. That is free and does not invalidate your current certificates, so they keep working until you switch over. From then on, CertKit renews and deploys them automatically.

What happens if an automated renewal fails?

CertKit monitors every certificate and alerts you before an expiry becomes an outage, so a failed renewal is something you hear about early, not after a site goes down.

About certificate monitoring

Do I have to switch certificate authorities?

No. CertKit works with Let's Encrypt, your current CA, or any ACME-compatible authority. Most teams move to free Let's Encrypt certificates once renewal is automated, but you don't have to.

How do I get started?

Start a 90-day free trial, no credit card required. Add your domains, point one CNAME, and CertKit begins issuing and renewing automatically. Our engineering team helps you set up.

See pricing

Automate your certificates and forget about them

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing