Built for WatchGuard Beta
Pre-built templates for the Web Server, Mobile VPN with IKEv2, and the inbound HTTPS proxy ship in your CertKit account, currently in beta.
A Firebox keeps separate certificates for its Web Server (the Web UI, portals, and Mobile VPN with SSL), for Mobile VPN with IKEv2, and for inbound HTTPS proxy inspection. A renewed certificate does nothing until someone imports it and selects it for each one. Every 47 days.
CertKit issues and renews the certificate centrally, then the CertKit Agent imports it over the Fireware SSH CLI and selects it where it belongs.
Pre-built templates for the Web Server, Mobile VPN with IKEv2, and the inbound HTTPS proxy ship in your CertKit account, currently in beta.
On every renewal, the agent connects to the Fireware CLI, imports the chain and then the certificate with its key, finds the new certificate by fingerprint, and selects it. It reads the setting back and only reports success when the Firebox shows the new certificate.
For the inbound proxy, the import replaces the default Proxy Server certificate in place, so every HTTPS rule that uses the default serves the new one.
The manual process, if you want to do it yourself:
Every one of these steps is manual, and Fireware won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every Firebox. Miss one and remote users can't reach the SSL VPN, or IKEv2 clients refuse to connect.
At 47 days, automation is the only sustainable way to run WatchGuard certificates. Here's how CertKit does it.
Your network CertKit ACME CA ┌───────────────────┐ ┌──────────────────┐ ┌─────────────┐ │ ┌─────────────┐ │ │ │ │ │ │ │Deploy Agent │◄─┼─────┤ Issue & Renew │◄──►│ │ │ └──┬────┬─────┘ │ │ Certificates │ │ │ │ │ │SSH │ │ ┌───┐ └─────────────┘ │ │ │ :4118 │ └───────────┬────│DNS│ │ ▼ ▼ │ │ └───┘ │ ┌──────────────┐ │ │ │ │ Firebox │ │ │ │ │ [x] Imported │ │ │ │ │ [x] Selected │ │ ◄───────────────┘ │ │ [x] Read back│ │ Verify │ └──────────────┘ │ └───────────────────┘
CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.
The deploy agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then signs in to the Firebox over SSH. The Firebox never talks to CertKit, never runs ACME, and never holds DNS credentials.
Ever since the news of the Certificate expiration dates being compressed down to 47 days we have been looking for an MSP friendly solution, CertKit were the clear winners as their platform is easy to use, MSP friendly & cost effective. We’ve been really impressed with the team from a technical support perspective as they’re super quick to respond and we’ve never had a certificate we couldn’t provision!
Andrew Charlesworth, Technical Director, NCS
Fireware can refuse to import a renewal while the old certificate with the same subject is still installed. WatchGuard's answer is to delete the old one first, which leaves the service on the default certificate until the new one is selected.
CertKit imports the new certificate before touching the old one and selects it by fingerprint. If Fireware refuses the import, the agent stops and tells you, instead of deleting a certificate that's still in use.
Most networks have more than one place where TLS certificates live: other firewalls like SonicWall, FortiGate, and Palo Alto, and VPN gateways like Ivanti Connect Secure. CertKit automates all of it from one account.
Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.