Skip to content
Windows & Linux

Your certificates, renewed and ready to use

The CertIntel Agent runs on the machine that needs the certificate: an embedded ACME client requests certificates from a public CA and handles renewal and installation locally. The same agent reports certificate inventory back to CertIntel.

Windows x64 with a desktop app · Linux x86-64/ARM64 with systemd and a CLI

Windows agent · Agent Monitors · Interface illustration with example data
How it works

Set it up once. Keep renewals moving.

Choose a public ACME CA, domains and installation steps, then enable automatic renewal. The agent handles the work and reports the results.

Automatic ACME renewals

Request free, publicly trusted certificates from Let's Encrypt, or use another compatible public ACME CA. Renew and install them within your chosen weekly maintenance windows.

Installs for your applications

Configure file or Java keystore outputs and installation steps for NGINX, Apache or Tomcat. Windows also supports certificate stores and IIS bindings.

Certificate keys stay local

The agent generates and keeps certificate private keys on your machine. Only certificate details and status reports go to CertIntel.

Monitors internal services too

Check the internal services and certificate files you choose, plus Windows certificate stores. See the results alongside your public websites.

Windows setup guide Linux setup guide

Certificate authorities

Start free with Let's Encrypt—or choose another CA

Let's Encrypt is a leading public ACME CA and issues publicly trusted TLS certificates at no cost. It is built in as the default, while custom ACME directories let you use another compatible public CA.

Let's Encrypt — production
Free, automated and publicly trusted. Let's Encrypt helped bring ACME certificate automation into the mainstream and is the default when creating a new account in the agent.
Let's Encrypt — staging (test certificates)
Test issuance, DNS validation and installation before going live. Staging certificates are not trusted by browsers.
Custom ACME directory
Use another compatible public CA by entering its ACME directory URL. The CA must support the agent's DNS-01 validation flow. Configure external account binding (EAB) if your CA requires it.

For EAB, add the CA-provided key ID and HMAC key to the agent's ACME account. To change CA for an existing certificate, create a new workflow.

Built-in ACME

What happens at renewal time?

The agent requests a replacement, verifies your domain through CertIntel's delegated DNS and installs the new certificate using your saved settings.

  1. 01

    Request

    The agent requests a certificate from Let’s Encrypt or another compatible public ACME CA.

  2. 02

    Validate

    CertIntel hosts the DNS proof that you control the domain.

  3. 03

    Install

    The agent saves the certificate and runs your configured installation steps.

  4. 04

    Renew

    With auto-renew enabled, the agent repeats the process when renewal is due.

Follow issuance and installation status in the agent, and renewal results in CertIntel. If installation fails after issuance, retry installation with the certificate already issued. There is no need to request another one.

Start with your first certificate.

Create a free account and add a public site or connect an agent.

Sign up free