Built for Ivanti Connect Secure
The pre-built Connect Secure template ships in your CertKit account. No scripting required.
Ivanti Connect Secure, formerly Pulse Secure, presents a device certificate on each port: the external port VPN users connect to, the internal and management ports, and any virtual ports. A renewed certificate does nothing until someone imports it and moves every port off the old one. Every 47 days.
CertKit issues and renews the certificate centrally, then the CertKit Agent imports it through the REST API and reassigns your ports. Users who are already connected stay connected.
The pre-built Connect Secure template ships in your CertKit account. No scripting required.
On every renewal, the agent imports the certificate with its intermediate chain, assigns it to the ports you list, and deletes the old certificate once no port uses it. If the gateway rejects a port change, CertKit puts the ports back the way they were.
New connections get the renewed certificate right away. In a cluster, point CertKit at the node you manage and the change copies to the rest.
The manual process, if you want to do it yourself:
Every one of these steps is manual, and Connect Secure won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every gateway. Miss one and remote users get an invalid server certificate error instead of a VPN connection.
At 47 days, automation is the only sustainable way to run Ivanti Connect Secure certificates. Here's how CertKit does it.
Your network CertKit ACME CA ┌───────────────────┐ ┌──────────────────┐ ┌─────────────┐ │ ┌─────────────┐ │ │ │ │ │ │ │Deploy Agent │◄─┼─────┤ Issue & Renew │◄──►│ │ │ └──┬────┬─────┘ │ │ Certificates │ │ │ │ │ │REST │ │ ┌───┐ └─────────────┘ │ │ │API │ └───────────┬────│DNS│ │ ▼ ▼ │ │ └───┘ │ ┌──────────────┐ │ │ │ │ Ivanti ICS │ │ │ │ │ [x] Imported │ │ │ │ │ [x] Assigned │ │ ◄───────────────┘ │ │ [x] Cleaned │ │ Verify │ └──────────────┘ │ └───────────────────┘
CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.
The deploy agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then calls the gateway's REST API on your admin network. The gateway never talks to CertKit, never runs ACME, and never holds DNS credentials.
CertKit makes what many companies struggle with much easier to manage while at the same time providing great value compared to the traditional vendors in the space.
Ben Story, Managed Services Director, RedEye Network Solutions
Ivanti Connect Secure deployment requirements and troubleshooting →
Importing a certificate on Connect Secure changes nothing until ports move to it. The usual miss is a certificate that served two ports: the external port gets moved, the internal or management port doesn't, and the old certificate keeps serving there until it expires.
CertKit assigns every port you list in one step and only removes the old certificate when nothing uses it.
Most networks have more than one place where TLS certificates live: firewalls like Palo Alto, SonicWall, and Cisco Firepower, and remote access servers like Absolute Secure Access. CertKit automates all of it from one account.
Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.