Built for Absolute Secure Access
The pre-built Absolute Secure Access template ships in your CertKit account. No scripting required.
Absolute Secure Access, formerly NetMotion Mobility, serves its management console and web services API from a Java keystore in the server's install folder. A renewed certificate does nothing until someone replaces it and restarts the Secure Access Web Server service. Every 47 days.
CertKit issues and renews the certificate centrally, then the CertKit Agent on the Secure Access server updates the keystore and restarts the web server. VPN connections are not affected.
The pre-built Absolute Secure Access template ships in your CertKit account. No scripting required.
On every renewal, the agent finds the web server's keystore, reads its password from the
configuration, backs it up, and replaces the certificate. Then it restarts
NmWebServer and checks that the console serves the new certificate.
If the update, restart, or check fails, the agent puts the old keystore back. Console users reconnect after the restart. Mobile devices keep their tunnels.
The manual process, if you want to do it yourself:
NmWebServer) so the console loads the new certificate.
Every one of these steps is manual, and Secure Access won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every Secure Access server. Miss one and the console and its API start failing TLS checks.
At 47 days, automation is the only sustainable way to run Absolute Secure Access certificates. Here's how CertKit does it.
Secure Access server CertKit ACME CA ┌───────────────────┐ ┌──────────────────┐ ┌─────────────┐ │ │ │ │ │ │ │ ┌───────────────┐ │ Issue & Renew │◄──►│ │ │ │ CertKit Agent │◄──┤ Certificates │ │ │ │ └─────────┬─┬───┘ │ ┌───┐ └─────────────┘ │ │ │ │ └───────────┬────│DNS│ │ Keystore ◄─┘ │ │ │ └───┘ │ [x] Updated │ │ │ │ │ │ │ │ NmWebServer ◄─┘ │ ◄───────────────┘ │ [x] Restarted │ Verify └───────────────────┘
CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.
The agent pulls each renewal over outbound HTTPS and works locally with the Java
keytool that ships with Secure Access. The server never runs ACME and never
holds DNS credentials.
Ever since the news of the Certificate expiration dates being compressed down to 47 days we have been looking for an MSP friendly solution, CertKit were the clear winners as their platform is easy to use, MSP friendly & cost effective. We’ve been really impressed with the team from a technical support perspective as they’re super quick to respond and we’ve never had a certificate we couldn’t provision!
Andrew Charlesworth, Technical Director, NCS
NmWebServer restarts and VPN tunnels stay up. If the certificate is already installed, nothing restarts.
auto. CertKit handles every renewal.
Absolute Secure Access deployment requirements and troubleshooting →
VPN tunnels keep working when the console certificate expires, so nobody notices. Then an administrator needs the console during an outage, or a tool that calls the web services API starts failing. Renewing it on a schedule is how you avoid finding out that way.
Remote access usually runs on more than one system: Microsoft's own Always On VPN and DirectAccess, and VPN gateways like Ivanti Connect Secure and SonicWall. CertKit automates all of it from one account.
Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.