Certificate automation
Set it up once. Never chase a renewal again.
Certificate automation issues, renews, deploys, and verifies your SSL certificates without
manual steps, so a certificate never expires because someone forgot. You point one DNS
record at CertKit, and the whole cycle runs on its own from then on.
Start free trial
See how it works
The manual way doesn't scale
Managing certificates by hand is a standing chore: a spreadsheet of expiry dates, calendar
reminders, an OpenSSL command you look up every time, and a renewal job on each server that
someone has to babysit. It works until it doesn't, usually at 2am, usually while the person
who set it up is on vacation.
It gets harder every year. The 200-day maximum is already in effect, and 47-day
certificates are coming by 2029. A renewal that used to happen once a year will happen
roughly twelve times a year, on every certificate, on every server. At that cadence, manual
renewal stops being a process and becomes a liability.
Read about the certificate lifetime mandate.
How certificate automation works
CertKit acts as a central ACME
client for all your domains. You add your domains and point one
delegated DNS CNAME record at CertKit. After
that, CertKit requests and renews every certificate on its own, and the CertKit Agent
deploys each one to your servers and appliances and confirms it is being served.
That one record is everything required to automate SSL certificate renewal across your fleet.
┌───────┐ ┌────────┐ ┌─────────┐ ┌───────┐
│ Issue │──►│ Deploy │──►│ Monitor │──►│ Renew │──┐
└───┬───┘ └────────┘ └─────────┘ └───────┘ │
▲ │
└──────────── repeats, unattended ────────────┘
Set it up once. CertKit issues, deploys, monitors, and renews on schedule, with nobody in the loop.
No scripts. No cron jobs. No ACME client to install on each box. No 2am alerts when
something expires.
Certificate renewal automation, end to end
Renewal is where manual processes break down, because it never stops. CertKit tracks the
expiration date of every certificate and renews each one well before its deadline. There is
no renewal job to schedule and no reminder to snooze. The renewed certificate is deployed
to every server and appliance that uses it, and the old one ages out on its own.
A renewed certificate that never gets deployed is just a file on the wrong server. That gap
is why teams with renewal scripts still get expiry outages. When you automate SSL
certificate renewal with CertKit, renewal, deployment, and verification run as one motion,
so the certificate your users see is always the current one.
Issuance automation is not certificate automation
Plenty of tools automate part of the job. The gap is what happens after a certificate is
issued.
Issuance automation
Tools like Certbot automate getting a certificate on the one box they run on. You still
wire up the renewal job, the deployment, and the service restart on every server
yourself, and nothing reaches the appliances that can't run ACME.
Certificate automation
CertKit automates the whole cycle from one account: issue, renew, deploy to every server
and appliance, and verify. There is no per-server script to maintain, and no step left
waiting on someone.
Issuance was the easy part all along. Deployment is where certificates actually break, and
distribution is the last mile.
Verification is the success signal
Most automation stops at "renewal succeeded." The CA said ok, the client exited 0, a file
got written. None of that proves your site is serving the new certificate.
CertKit verifies every deployment from the outside: a real TLS handshake against the public
hostname, checking the expiry date, the names on the certificate, and the full chain. Not
"the file exists," but "real clients see the new certificate." Every hostname, after every
renewal. How to verify a certificate
renewal.
Why CertKit's automation is different
- No DNS API required. One-time CNAME setup, and your DNS credentials stay with you.
- No ACME on every server. CertKit issues centrally, so there is nothing to install or maintain per box.
- No open ports. The CertKit Agent makes outbound connections only, so it works behind firewalls.
- Wildcards and multi-domain certificates are handled out of the box.
- Any certificate authority. Let's Encrypt or any ACME-compatible CA, with no lock-in.
SSL automation for more than web servers
Certificates live everywhere TLS terminates: load balancers, firewalls, mail servers, VPN
appliances, and the legacy box nobody wants to touch. Most of those can't run an ACME
client at all. SSL certificate automation only counts when it reaches every one of them.
The CertKit Agent deploys renewed certificates to Windows and Linux servers directly and
pushes them to appliances like FortiGate, F5, and Palo Alto through
pre-built integrations, in the format each one expects. One
automation pipeline for the whole fleet, not one script per box.
Works with your certificate authority
CertKit automates issuance and renewal from the public CAs teams use most. Move to a free CA
like Let's Encrypt or Google Trust Services once renewal is automated, or stay with the
commercial CA you already have. You are never locked in.
When no public CA can issue what you need, for an internal hostname, an IP address, or an mTLS
client certificate, CertKit can be the certificate authority.
Managed PKI issues from a private CA and automates it the same way.
Automation is one stage of the lifecycle
Certificate renewal automation is the stage that removes the most work, but it is one part of
certificate lifecycle management. CertKit
also discovers the certificates you forgot about and
monitors every one, so nothing slips through, and
it deploys to your servers and appliances automatically.
Start free trial
See how it works
CertKit has been a fantastic solution for automating our environment’s SSL/TLS certificates. With a single pane of glass for centralized management, visibility, and monitoring and the highly customizable interface for granular control over individual systems, we have found great value in reducing the time and complexity of managing an ad-hoc ACME solution for individual certificate automation.
Seth Allums, Lead Systems and Information Security Engineer, Clackamas Community College
Frequently asked questions
Do I have to run an ACME client or script on each server?
No. CertKit issues and renews every certificate centrally. The CertKit Agent then deploys
each one to your servers and appliances, so there is no ACME client, renewal script, or
cron job to maintain on each box.
Why servers shouldn't need ACME
Can I automate the certificates I already have?
Yes. You reissue them through CertKit for the same domains. That is free and does not
invalidate your current certificates, so they keep working until you switch over. From
then on, CertKit renews and deploys them automatically.
What happens if an automated renewal fails?
CertKit monitors every certificate and alerts you before an expiry becomes an outage, so a
failed renewal is something you hear about early, not after a site goes down.
About certificate monitoring
Do I have to switch certificate authorities?
No. CertKit works with Let's Encrypt, your current CA, or any ACME-compatible authority.
Most teams move to free Let's Encrypt certificates once renewal is automated, but you
don't have to.
How do I get started?
Start a 90-day free trial, no credit card required. Add your domains, point one CNAME, and
CertKit begins issuing and renewing automatically. Our engineering team helps you set up.
See pricing
Automate your certificates and forget about them
Free 90-day trial. No credit card required.
Direct access to our engineering team to get you set up.
Start free trial
See pricing