Certificates on Windows servers
renewed automatically — without gaps.
TLS/SSL certificates for IIS, RDS, Exchange, LDAPS and more: fully automatic discovery, renewal, deployment and monitoring. ACME-native. Governance-secured. BAIT- and DORA-compliant.
How CertOps works — at a glance
Four components, one closed loop. No manual intervention in normal operation.
Three reasons certificate automation is no longer optional
No more blind spots
73% of all Windows certificates expire unplanned — because they're not centrally tracked anywhere. CertOps automatically builds a complete cert CMDB: every FQDN, every SAN, every expiry date, every service binding — always current.
Fully automated — no manual work
30 days before expiry, CertOps triggers the renewal, deploys the new certificate and binds it to all affected Windows services. The operator approves via HITL gate — and that's it. No ticket escalation, no late-night emergency work.
Audit-ready at the push of a button
Every issuance, every rebind, every HITL approval automatically generates a machine-readable evidence record. BAIT, DORA, BSI and ISO 27001 reports are generated from existing data — no manual documentation.
The CA/Browser Forum roadmap — automation is mandatory
The industry is consistently shortening certificate lifetimes. Anyone who doesn't automate will soon face impossible tasks.
Still possible manually — but already labour-intensive.
Manually borderline. Automation strongly recommended.
No longer manually viable. Automation mandatory.
Manually virtually impossible. Full automation is the only option.
Four steps — fully automated
Every step has a governance checkpoint. Nothing runs blindly.
Discovery
A blackbox exporter scans all endpoints daily. Cert CMDB automatically captures FQDN, SANs, issuer, expiry date and service binding.
Renewal (ACME)
30 days before expiry, the orchestrator automatically triggers a renewal — via ACME against Let's Encrypt, ZeroSSL, Sectigo/DigiCert or an internal step-ca.
Windows binding (HITL)
The PowerShell agent binds the new certificate to IIS, RDS, Exchange, LDAPS etc. For production systems: approval via HITL gate required.
Monitor & alert
Prometheus checks the new expiry date after binding. Tiered alerts at 30/14/7/3 days. Automatic incident on renewal failure.
What CertOps delivers
Discovery & inventory
Automatic TLS probing of all configured endpoints. Complete cert CMDB: FQDN, SANs, issuer, expiry date, service binding — always current.
Automatic renewal
ACME-native: Let's Encrypt/ZeroSSL for public hosts, step-ca for internal servers, Sectigo/DigiCert ACME for OV/EV. Renewal 30 days before expiry.
Windows deployment
PowerShell agent automatically binds the new cert to IIS, RDS/RD Gateway, Exchange, LDAPS, WinRM, SQL Server, NPS. Service-specific hooks per service.
Governance & audit trail
Every issuance and every bind generates a machine-readable evidence record. Production rebind only after explicit HITL-gate approval.
Monitoring & alerts
Blackbox exporter + Prometheus: tiered alerts at 30/14/7/3 days before expiry. Grafana dashboard. Automatic incident on renewal failure.
Compliance reports
Quarterly compliance reports for BAIT, DORA, BSI IT-Grundschutz and ISO 27001 — automatically generated from existing cert data. No manual compiling.
RDP publisher signing Beta
Signs .rdp connection files with a code-signing certificate (rdpsign.exe) and maintains the GPO trusted-publisher list — the mstsc "Unknown publisher" warning disappears. Issuance always HITL-approved.
Regulatory requirements — met automatically
CertOps supplies the audit trail automatically. Every issuance, every rebind — machine-readable, verifiable, report-ready.
Banking supervisory IT requirements: cert-lifecycle documentation and automated renewal as a control against cert outages. An expired certificate = an availability incident.
Digital Operational Resilience Act: ICT security (Art. 9) makes key and certificate management mandatory. Business continuity (Art. 10): cert outages are in scope for the BCP.
Patch and change management: certificates as cryptographic patches. Web-server security (APP.3.2): TLS currency as a baseline-protection control — demonstrably met.
ISO/IEC 27001:2022: automated key and certificate lifecycle as a requirement. CertOps delivers the technical implementation and the documented proof.
Supported Windows services
Eight service-specific PowerShell hooks — each using the native Windows binding API.
| Service | Binding method | Restart |
|---|---|---|
| IIS (Web, OWA, SharePoint) | WebAdministration PowerShell | Optional / IISReset |
| RDS / RD-Gateway | WMI TermServices + netsh | TermService restart |
| LDAPS (Domain Controller) | NTDS\Personal Store | NTDS service restart (~10 s) |
| Exchange (IIS+SMTP+IMAP+POP) | Enable-ExchangeCertificate (EMS) | IISReset |
| WinRM HTTPS | WSMan-Listener + netsh | WinRM Restart |
| SQL Server | WMI / Registry | SQL service restart |
| NPS | netsh nps | No restart |
| RDP-Publisher-Signing (RD-Web/RemoteApp) Beta | rdpsign.exe + GPO-Thumbprint-Liste | No restart |
Reseller & MSP model
IT systems houses and MSPs deploy CertOps and resell it white-label to their customers — savings banks, municipalities, SMEs. The controller runs on-premise at the reseller (full data sovereignty). Intelego supplies software, updates and governance.
On-prem white-label
Controller in the reseller's infrastructure. Data never leaves the premises. Ideal for BAIT and savings-bank requirements with strict data sovereignty.
- Unlimited endpoints
- Up to 200 end-customer sub-scopes
- Your own branding
Your margin, your customers
Resellers bill end customers themselves — on their own terms. Intelego supplies software, updates, support and compliance documentation in the background.
- Isolated inventory DBs per customer
- Isolated cert stores
- Your own pricing
Intelego in the background
Software updates, security patches, new service hooks and compliance-report templates are maintained and delivered by Intelego. No in-house dev team required.
- Updates and patches included
- New service hooks at no extra cost
- Governance documentation included
Transparent. Cancellable monthly. No vendor lock-in.
- Up to 10 endpoints
- Full controller stack
- Windows agent + 1 service hook
- Intelego supports setup
- No contract, no automation
- Unlimited endpoints
- Up to 200 end-customer sub-scopes
- All 7 service hooks
- Compliance reports (BAIT/DORA/BSI/ISO)
- Software updates & security patches
- New service hooks at no extra charge
- 4h response 2nd-level support (Mon–Fri)
- Intelego-managed controller
- Monitoring dashboard (Grafana)
- Compliance report included
- All service hooks included
- Cancellable monthly
All prices net plus VAT · cancellable monthly · EU hosting · GDPR-compliant · offer exclusively for businesses, trades, public authorities and legal entities under public law (Sect. 14 BGB) — not a consumer transaction (Sect. 13 BGB)
Frequently asked questions
Does CertOps work with our existing ADCS?
Yes. CertOps supports two CA paths: if a Microsoft Active Directory Certificate Services is already in place, CertOps uses the ADCS adapter (NDES/SCEP via certreq). If no ADCS is present, the bundled step-ca takes over as a private ACME CA. Both paths can run in parallel — ADCS for AD-joined hosts, step-ca for external or non-domain hosts.
What happens if a renewal fails?
CertOps sends tiered alerts at 30 / 14 / 7 / 3 days before expiry — regardless of whether a renewal was triggered. A renewal failure automatically creates an incident in the service desk. The certificate never silently expires: either the renewal succeeds, or an alert escalates in time to the responsible operator.
Where is our certificate data — does it leave our premises?
In the standard model (on-prem white-label), the entire controller stack — orchestrator, cert inventory DB, step-ca, Prometheus/Grafana — runs on your own Linux server in the reseller's infrastructure. Private keys, FQDN inventory and compliance reports never leave the premises. Intelego supplies software and updates but has no access to the running instance.
Do we have to use Let's Encrypt or a public CA?
No. For internal Windows servers (not publicly reachable), CertOps uses the bundled step-ca as a private ACME CA — fully on-premise, with no external CA dependency. Let's Encrypt and ZeroSSL are optional for publicly reachable hosts. OV/EV certificates (e.g. for savings-bank branding) are supported via Sectigo or DigiCert ACME.
How is a production cert rebind secured?
Every production rebind passes through a HITL gate (human-in-the-loop). The Windows agent checks before binding whether the gate is approved — if not, no binding occurs. Approval comes from an authorised operator (Cockpit or Matrix chat). Every approval and every bind generates a machine-readable evidence record for the audit trail.
Which Windows services are supported for automatic binding?
CertOps supports all common Windows services with certificate-dependent configuration: IIS (incl. OWA, SharePoint), RDS / RD-Gateway, LDAPS (Domain Controller), Exchange (IIS + SMTP + IMAP + POP), WinRM HTTPS, SQL Server and NPS. Each service has its own PowerShell hook that uses the service-specific binding API.
What is RDP publisher signing — and why do I need it?
Windows shows the warning "Unknown publisher", when opening an .rdp connection file that isn't signed — typical for RD Web/RemoteApp portals that automatically generate .rdp files for end users. CertOps issues a code-signing certificate for this purpose (private CA, HITL-approved), signs the files with rdpsign.exe and maintains the GPO trusted-publisher list. After that, mstsc shows the real publisher name instead of the warning. Status: Beta — the code is implemented, rollout happens gradually per customer.
See the loop live now
We'll prove discovery → renewal → binding → monitoring
on your Windows servers — in 30 days, risk-free, no contract.