← Integrations

Automated SSL certificate renewal for Ivanti Connect Secure

Connect Secure won't use a renewed certificate on its own. CertKit will.

Ivanti Connect Secure, formerly Pulse Secure, presents a device certificate on each port: the external port VPN users connect to, the internal and management ports, and any virtual ports. A renewed certificate does nothing until someone imports it and moves every port off the old one. Every 47 days.

CertKit issues and renews the certificate centrally, then the CertKit Agent imports it through the REST API and reassigns your ports. Users who are already connected stay connected.

Start free trial Watch demo

Built for Ivanti Connect Secure

The pre-built Connect Secure template ships in your CertKit account. No scripting required.

On every renewal, the agent imports the certificate with its intermediate chain, assigns it to the ports you list, and deletes the old certificate once no port uses it. If the gateway rejects a port change, CertKit puts the ports back the way they were.

New connections get the renewed certificate right away. In a cluster, point CertKit at the node you manage and the change copies to the rest.

How to install an SSL certificate on Ivanti Connect Secure

The manual process, if you want to do it yourself:

  1. Get the certificate with its chain. A PFX or a certificate and key, including wildcard certificates.
  2. Import it. Under System → Configuration → Certificates → Device Certificates, choose Import Certificate & Key.
  3. Check the intermediates. Add any missing intermediate to Intermediate Device CAs on the same page, or clients report an invalid server certificate.
  4. Assign the ports. Open the new certificate and move each port from the old one: External, Internal, Management, and any virtual ports.
  5. Clean up. Delete the old certificate once no port uses it, then repeat on each standalone gateway.

Every one of these steps is manual, and Connect Secure won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every gateway. Miss one and remote users get an invalid server certificate error instead of a VPN connection.

At 47 days, automation is the only sustainable way to run Ivanti Connect Secure certificates. Here's how CertKit does it.

How it works

 Your network            CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│  ┌─────────────┐  │     │                  │    │             │
│  │Deploy Agent │◄─┼─────┤  Issue & Renew   │◄──►│             │
│  └──┬────┬─────┘  │     │   Certificates   │    │             │
│     │    │REST    │     │                ┌───┐  └─────────────┘
│     │    │API     │     └───────────┬────│DNS│
│     ▼    ▼        │                 │    └───┘
│ ┌──────────────┐  │                 │
│ │ Ivanti ICS   │  │                 │
│ │ [x] Imported │  │                 │
│ │ [x] Assigned │  │ ◄───────────────┘
│ │ [x] Cleaned  │  │       Verify
│ └──────────────┘  │
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The deploy agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then calls the gateway's REST API on your admin network. The gateway never talks to CertKit, never runs ACME, and never holds DNS credentials.

CertKit makes what many companies struggle with much easier to manage while at the same time providing great value compared to the traditional vendors in the space.

Ben Story, Managed Services Director, RedEye Network Solutions

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Allow REST API access. Connect Secure 9.1R14 or later. Turn on Allow access to REST APIs for an admin account without MFA, with a role that can change device certificates.
  3. Install the CertKit Agent. One command on a Windows host that can reach the admin interface over HTTPS.
  4. Add the Connect Secure deployment script. Enter the gateway address, credentials, admin realm, and the ports to assign.

See the full architecture →

Ivanti Connect Secure deployment requirements and troubleshooting →

Why importing the certificate isn't enough

Importing a certificate on Connect Secure changes nothing until ports move to it. The usual miss is a certificate that served two ports: the external port gets moved, the internal or management port doesn't, and the old certificate keeps serving there until it expires.

CertKit assigns every port you list in one step and only removes the old certificate when nothing uses it.

Connect Secure is just one part of your network edge

Most networks have more than one place where TLS certificates live: firewalls like Palo Alto, SonicWall, and Cisco Firepower, and remote access servers like Absolute Secure Access. CertKit automates all of it from one account.

See all integrations

Start automating Ivanti Connect Secure certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing