Your certificates, renewed and ready to use
The CertIntel Agent runs on the machine that needs the certificate: an embedded ACME client requests certificates from a public CA and handles renewal and installation locally. The same agent reports certificate inventory back to CertIntel.
Windows x64 with a desktop app · Linux x86-64/ARM64 with systemd and a CLI
Certificates, renewals and installation — in one place.
Configure discovery monitors on this agent. Internal TLS Probe - Cloud assignments appear separately in Overview.
Configure host names and ports to inspect certificates presented over TLS. These probes run on this agent.
| Host | Port | Notes | Enabled |
|---|---|---|---|
| portal.example.com | 443 | Internal portal | ☑ |
| vault.example.com | 8200 | Secrets service | ☑ |
Monitor PEM, CRT, CER, DER, PKCS#7, PKCS#12, and Java JKS files.
| Path | Format | Notes | Enabled |
|---|---|---|---|
| C:\certs\portal.pem | PEM | Portal certificate | ☑ |
CurrentUser refers to the service identity. Filters match CN or DNS SAN; each * matches one nonempty label.
| Location | Store | Names | Notes | Enabled |
|---|---|---|---|---|
| LocalMachine | My | portal.example.com | Portal | ☑ |
Set it up once. Keep renewals moving.
Choose a public ACME CA, domains and installation steps, then enable automatic renewal. The agent handles the work and reports the results.
Automatic ACME renewals
Request free, publicly trusted certificates from Let's Encrypt, or use another compatible public ACME CA. Renew and install them within your chosen weekly maintenance windows.
Installs for your applications
Configure file or Java keystore outputs and installation steps for NGINX, Apache or Tomcat. Windows also supports certificate stores and IIS bindings.
Certificate keys stay local
The agent generates and keeps certificate private keys on your machine. Only certificate details and status reports go to CertIntel.
Monitors internal services too
Check the internal services and certificate files you choose, plus Windows certificate stores. See the results alongside your public websites.
What happens at renewal time?
The agent requests a replacement, verifies your domain through CertIntel's delegated DNS and installs the new certificate using your saved settings.
- 01
Request
The agent requests a certificate from Let’s Encrypt or another compatible public ACME CA.
- 02
Validate
CertIntel hosts the DNS proof that you control the domain.
- 03
Install
The agent saves the certificate and runs your configured installation steps.
- 04
Renew
With auto-renew enabled, the agent repeats the process when renewal is due.
Follow issuance and installation status in the agent, and renewal results in CertIntel. If installation fails after issuance, retry installation with the certificate already issued. There is no need to request another one.
Start with your first certificate.
Create a free account and add a public site or connect an agent.