← Integrations

Automated SSL certificate renewal for Intermapper

Intermapper won't load a renewed certificate on its own. CertKit will.

Intermapper's web server and Intermapper Remote connections use one certificate, stored as a single PEM file, SSLCertificateFile, in Intermapper's Certificates folder. The private key comes first, then the certificate and chain. A renewed certificate does nothing until someone builds that file in the right order and restarts the server. Every 47 days.

CertKit handles it with a built-in template. The CertKit Agent writes an all-in-one PEM, key first, and restarts the Intermapper service.

Start free trial Watch demo

Built for Intermapper

No dedicated template needed. The built-in Restart a Windows service template does the job.

CertKit's all-in-one PEM format writes the private key first, then the certificate and its chain. That's the order Intermapper expects, so there's no conversion step.

Point the file at Intermapper's certificate, set the service name, and CertKit writes and restarts on every renewal. Web and Remote clients reconnect after the restart.

How to install an SSL certificate in Intermapper

The manual process, if you want to do it yourself:

  1. Create a certificate request. Open Edit → Server Settings → SSL Certificate and choose Create new CSR. Intermapper generates a 2048-bit RSA key.
  2. Get it signed. Send the CSR to a CA and collect the certificate with its intermediates.
  3. Build the PEM in order. Private key, server certificate, intermediates, then the root if you want it. The wrong order is the usual failure.
  4. Upload it. Choose Upload new Certificate in the same panel.
  5. Restart the server. Restart from Server Settings so HTTPS and Remote connections pick up the new certificate.

Every one of these steps is manual, and Intermapper won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every Intermapper server. Miss one and the maps your NOC watches open with a certificate warning.

At 47 days, automation is the only sustainable way to run Intermapper certificates. Here's how CertKit does it.

How it works

 Your Intermapper server   CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│                   │     │                  │    │             │
│     ┌───────────────┐   │  Issue & Renew   │◄──►│             │
│     │ CertKit Agent │◄──┤   Certificates   │    │             │
│     └─────────┬─┬───┘   │                ┌───┐  └─────────────┘
│               │ │ │     └───────────┬────│DNS│
│ PEM file    ◄─┘ │ │                 │    └───┘
│ [x] Written     │ │                 │
│                 │ │                 │
│ Intermapper   ◄─┘ │ ◄───────────────┘
│ [x] Restarted     │       Verify
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The agent on the Intermapper server pulls renewals over outbound HTTPS and works locally. Intermapper never runs ACME and never holds DNS credentials.

CertKit makes what many companies struggle with much easier to manage while at the same time providing great value compared to the traditional vendors in the space.

Ben Story, Managed Services Director, RedEye Network Solutions

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Install the CertKit Agent. One command on the Intermapper server.
  3. Add the Restart a Windows service template. Choose the all-in-one PEM format and set the destination to C:\ProgramData\InterMapper\InterMapper Settings\Certificates\SSLCertificateFile.
  4. Set the service name. Change the script to Restart-Service -Name "InterMapper" -Force. CertKit runs it on every renewal.

See the full architecture →

Built-in deployment templates →

Why not keep the default certificate?

Intermapper ships with a certificate that encrypts traffic but isn't trusted by browsers, so every visit starts with a warning. People learn to click through it, and a warning that means something later looks the same.

A publicly trusted certificate removes the warning, and CertKit keeps it renewed.

Intermapper is just one part of your stack

The systems Intermapper watches need certificates too: Windows servers running IIS, and firewalls like FortiGate and Palo Alto. CertKit automates all of it from one account.

See all integrations

Start automating Intermapper certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing