← Integrations

Automated SSL certificate renewal for Absolute Secure Access

The Secure Access web server won't pick up a renewed certificate. CertKit will.

Absolute Secure Access, formerly NetMotion Mobility, serves its management console and web services API from a Java keystore in the server's install folder. A renewed certificate does nothing until someone replaces it and restarts the Secure Access Web Server service. Every 47 days.

CertKit issues and renews the certificate centrally, then the CertKit Agent on the Secure Access server updates the keystore and restarts the web server. VPN connections are not affected.

Start free trial Watch demo

Built for Absolute Secure Access

The pre-built Absolute Secure Access template ships in your CertKit account. No scripting required.

On every renewal, the agent finds the web server's keystore, reads its password from the configuration, backs it up, and replaces the certificate. Then it restarts NmWebServer and checks that the console serves the new certificate.

If the update, restart, or check fails, the agent puts the old keystore back. Console users reconnect after the restart. Mobile devices keep their tunnels.

How to install an SSL certificate on Absolute Secure Access

The manual process, if you want to do it yourself:

  1. Get a certificate for the server's name. The name administrators use to reach the console, with its intermediate chain.
  2. Open the Management Tool. Go to the Web Server tab and open Server Certificate.
  3. Import the certificate. Import the certificate with its private key, or create a request there and import the CA's response.
  4. Restart the web server. Restart the Secure Access Web Server service (NmWebServer) so the console loads the new certificate.
  5. Check the console. Load it in a browser and confirm the new expiry date, then repeat on each Secure Access server.

Every one of these steps is manual, and Secure Access won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every Secure Access server. Miss one and the console and its API start failing TLS checks.

At 47 days, automation is the only sustainable way to run Absolute Secure Access certificates. Here's how CertKit does it.

How it works

 Secure Access server      CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│                   │     │                  │    │             │
│     ┌───────────────┐   │  Issue & Renew   │◄──►│             │
│     │ CertKit Agent │◄──┤   Certificates   │    │             │
│     └─────────┬─┬───┘   │                ┌───┐  └─────────────┘
│               │ │ │     └───────────┬────│DNS│
│ Keystore    ◄─┘ │ │                 │    └───┘
│ [x] Updated     │ │                 │
│                 │ │                 │
│ NmWebServer   ◄─┘ │ ◄───────────────┘
│ [x] Restarted     │       Verify
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The agent pulls each renewal over outbound HTTPS and works locally with the Java keytool that ships with Secure Access. The server never runs ACME and never holds DNS credentials.

Ever since the news of the Certificate expiration dates being compressed down to 47 days we have been looking for an MSP friendly solution, CertKit were the clear winners as their platform is easy to use, MSP friendly & cost effective. We’ve been really impressed with the team from a technical support perspective as they’re super quick to respond and we’ve never had a certificate we couldn’t provision!

Andrew Charlesworth, Technical Director, NCS

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Install the CertKit Agent. One command on the Secure Access server, running as Local System.
  3. Create the first certificate. On a new server, create or import a server certificate once in the Management Tool. Renewals replace it after that.
  4. Add the Absolute Secure Access deployment script. Leave the install folder and alias on auto. CertKit handles every renewal.

See the full architecture →

Absolute Secure Access deployment requirements and troubleshooting →

The certificate nobody notices until it expires

VPN tunnels keep working when the console certificate expires, so nobody notices. Then an administrator needs the console during an outage, or a tool that calls the web services API starts failing. Renewing it on a schedule is how you avoid finding out that way.

Secure Access is one part of your remote access stack

Remote access usually runs on more than one system: Microsoft's own Always On VPN and DirectAccess, and VPN gateways like Ivanti Connect Secure and SonicWall. CertKit automates all of it from one account.

See all integrations

Start automating Absolute Secure Access certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing