Overview

Product video
Discovery & monitoring Inventorying and monitoring of certificates Alerting for: Expiration Security issue (revocation, weak algorithm, etc) Change (e.g. the certificate is changed on a monitored service) Discovery of certificates across the organization infrastructure Network scan Certificate Authority scanning Connector-based scanning (e.g. F5 BIG-IP, Linux Servers, etc)
Lifecycle automation Automatic certificate issuance and renewal Automated deployment of the certificate Revocation Support for server and user certificates Integration with public and private CAs ACME protocol support as client Automated ACME challenge validation: http-01, dns-01 and dns-persist-01 API and agent based CA integration (e.g. Microsoft AD CS, EJBCA, etc) Integration with external secret managers for storing credentials (API tokens, password, etc) Security policies to block non-compliant certificate issuance
Platform Advanced notifications (email, JIRA, Microsoft Teams, etc) Granular RBAC permission system Flexible user authentication Local accounts Active Directory (LDAP) authentication SAML federation OIDC federation Group mapping Support for Multi-Factor Authentication (OTP) Support for Passkeys (WebAuthn) Observability SNMP Prometheus metrics endpoint OpenTelemetry API
Highlights
- Intelligent discovery Scan your network and easily import your certificates into SSLCert. Unlimited flexibility Easy integration with your existing infrastructure to suit your unique needs. Public/Private CA Integration with public and private CAs, including Microsoft CA (ADCS). ACME Protocol ACME protocol support as both client and server for integrations with different CAs.
- Centralised inventory Monitor and manage all your certificates from an intuitive dashboard. Effortless automation Automatic certificate renewal and deployment to avoid the hassle of expired certificates. Guaranteed compliance Adherence to the strictest security standards for total compliance
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
No refunds will be provided for early termination or unused subscription periods.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Highlights
Integrate advanced security scanner. AutoCert ACME dialogs now support EAB HMAC algorithm selection alongside full JOSE algorithm set for JWT signing.Features
AutoCert dialog: added EAB HMAC algorithm selector for ACME external account binding. ACME Proxy: support full JOSE algorithm set for JWT signing (HMAC-only constrained for EAB per RFC).Additional details
Usage instructions
Prerequisites: AWS account with rights to create EC2, IAM roles, Secrets Manager secrets, key pairs, and security groups. An existing VPC/subnet with internet access. Your BYOL license token (for license activation). SSLCert ships as a prebuilt AMI, so you configure a readymade appliance rather than install from scratch. Minimum footprint: 1 EC2 instance, 1 IAM role, 1 secret. Plan 45 to 60 min.
-
Create the Secrets Manager secret Must be in the same region as the instance. Secrets Manager, then Store a new secret, then Other type of secret, then the Plaintext tab, entered as JSON: { "master_key": "<random>", "db_accounts_password": "<random>", "db_sslcert_password": "<random>" }
-
Create the IAM instance role IAM, then Roles, then Create role, trusted entity AWS service, then EC2. Attach an inline JSON policy granting readonly access to the secret above: Statement 1 (scoped to the secret ARN): GetResourcePolicy, GetSecretValue, DescribeSecret, ListSecretVersionIds. Statement 2 (must stay Resource: "*"): GetRandomPassword, ListSecrets, BatchGetSecretValue, which don't support resource-level restriction.
Name it e.g. "sslcert_ec2_instance_role", Create role. (Optional: create a .pem key pair if connecting via SSH key; chmod 600 it. Skip if using SSM or EC2 Instance Connect.)
- Launch the EC2 instance from the AMI AWS Marketplace, search SSLCert, Subscribe, Configuration, Launch, then Launch through EC2.
Instance type: t3.medium (2 vCPU / 4 GiB min). Key pair: the one you created, or proceed without. Network: existing VPC plus subnet with internet access. Enable auto-assign public IP only if connecting over the internet. Security group: open port 22 (SSH), 80 (HTTP redirects to HTTPS), 443 (Web UI). Storage: 50 GiB min (100 GiB for heavy cert/log volume). Advanced details, IAM instance profile: select the role from step 2. Launch Instance.
On first boot the appliance probes IMDSv2; detecting AWS, it skips the manual network screens (the VPC already assigns an address) and pulls bootstrap secrets via the IAM role.
- SSH in and run "Setup Applications" Once Running, connect as sysadm: SSH key: ssh -i key.pem sysadm@<appliance-ip>
The welcome TUI launches automatically and detects AWS. Have ready: SMTP host/port, email sender, appliance FQDN, admin email.
Resources
Vendor resources
Support
Vendor support
Licensor provides support during regular Swiss business hours, by email at sslcert.support@e-xpertsolutions.com , phone or via a support portal. The access details to the support portal are provided by email upon the license following the payment. Support is limited to issues related to the Software and does not include: Configuration of third-party services (Cloud provider, Certificate Authorities, Reverse proxy, etc.). Custom implementations or modifications. Issues arising from misuse or misconfiguration of the Software.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.