← Integrations

Automated SSL certificate renewal for WatchGuard Firebox

Fireware won't select a renewed certificate on its own. CertKit will.

A Firebox keeps separate certificates for its Web Server (the Web UI, portals, and Mobile VPN with SSL), for Mobile VPN with IKEv2, and for inbound HTTPS proxy inspection. A renewed certificate does nothing until someone imports it and selects it for each one. Every 47 days.

CertKit issues and renews the certificate centrally, then the CertKit Agent imports it over the Fireware SSH CLI and selects it where it belongs.

Start free trial Watch demo

Built for WatchGuard Beta

Pre-built templates for the Web Server, Mobile VPN with IKEv2, and the inbound HTTPS proxy ship in your CertKit account, currently in beta.

On every renewal, the agent connects to the Fireware CLI, imports the chain and then the certificate with its key, finds the new certificate by fingerprint, and selects it. It reads the setting back and only reports success when the Firebox shows the new certificate.

For the inbound proxy, the import replaces the default Proxy Server certificate in place, so every HTTPS rule that uses the default serves the new one.

How to install an SSL certificate on a WatchGuard Firebox

The manual process, if you want to do it yourself:

  1. Get the certificate with its chain. For IKEv2, it must cover the VPN address clients connect to.
  2. Import it. In Fireware Web UI, open System → Certificates and import it as General Use for the Web Server and IKEv2, or as Proxy Server for inbound inspection. Import the intermediates too.
  3. Select it. Choose it under Authentication → Web Server Certificate, and in the Mobile VPN with IKEv2 settings.
  4. Handle same-subject renewals. WatchGuard's own renewal procedure has you switch to the default certificate, delete the old one, import the renewal, and select it again.
  5. Save and repeat. Save the configuration, then repeat on every Firebox you manage.

Every one of these steps is manual, and Fireware won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every Firebox. Miss one and remote users can't reach the SSL VPN, or IKEv2 clients refuse to connect.

At 47 days, automation is the only sustainable way to run WatchGuard certificates. Here's how CertKit does it.

How it works

 Your network            CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│  ┌─────────────┐  │     │                  │    │             │
│  │Deploy Agent │◄─┼─────┤  Issue & Renew   │◄──►│             │
│  └──┬────┬─────┘  │     │   Certificates   │    │             │
│     │    │SSH     │     │                ┌───┐  └─────────────┘
│     │    │ :4118  │     └───────────┬────│DNS│
│     ▼    ▼        │                 │    └───┘
│ ┌──────────────┐  │                 │
│ │ Firebox      │  │                 │
│ │ [x] Imported │  │                 │
│ │ [x] Selected │  │ ◄───────────────┘
│ │ [x] Read back│  │       Verify
│ └──────────────┘  │
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The deploy agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then signs in to the Firebox over SSH. The Firebox never talks to CertKit, never runs ACME, and never holds DNS credentials.

Ever since the news of the Certificate expiration dates being compressed down to 47 days we have been looking for an MSP friendly solution, CertKit were the clear winners as their platform is easy to use, MSP friendly & cost effective. We’ve been really impressed with the team from a technical support perspective as they’re super quick to respond and we’ve never had a certificate we couldn’t provision!

Andrew Charlesworth, Technical Director, NCS

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Prepare the Firebox. A locally managed Firebox with SSH management on port 4118 and a read/write Device Administrator. Cloud-managed and fully WSM-managed Fireboxes aren't supported yet.
  3. Install the CertKit Agent. One command on a Windows host that can reach the Firebox over SSH, plus the Posh-SSH module for all users.
  4. Add the WatchGuard deployment script. Choose the Web Server, IKEv2, or inbound proxy template, then enter the Firebox address and credentials.

See the full architecture →

Questions about the beta? Talk to the engineering team →

Why renewals get stuck on a Firebox

Fireware can refuse to import a renewal while the old certificate with the same subject is still installed. WatchGuard's answer is to delete the old one first, which leaves the service on the default certificate until the new one is selected.

CertKit imports the new certificate before touching the old one and selects it by fingerprint. If Fireware refuses the import, the agent stops and tells you, instead of deleting a certificate that's still in use.

WatchGuard is just one part of your network edge

Most networks have more than one place where TLS certificates live: other firewalls like SonicWall, FortiGate, and Palo Alto, and VPN gateways like Ivanti Connect Secure. CertKit automates all of it from one account.

See all integrations

Start automating WatchGuard certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing