Getting started
From download to automatic renewals. Detailed help for every screen is built into the app (Help in the menu).
Requirements
- A Windows Server 2016 or later machine (a VM is fine) for the console and the service.
- SQL Server, or let the installer set up SQL Express on the same machine.
- Outbound HTTPS from that server to Let's Encrypt, your DNS provider's API and our license server.
- An account with API access at your DNS provider (Cloudflare, GoDaddy), or a Windows DNS or BIND server you control.
Install
- Sign in to your account and download the installer.
- Run it as an administrator. It installs the web console (its own HTTPS listener, no IIS needed), the background service, the .NET runtime and, if you want, SQL Express.
- Open the console address it shows at the end and create the first administrator.
Enter your license
Go to Settings > License, paste the key from your email and click Activate. The server confirms it with our license server, which takes a second. Line breaks copied from an email don't matter.
Your first certificate
- Credentials: add your DNS provider's API token (stored encrypted).
- Certificates > Add: enter the main name (for example
*.example.com), any extra names, and choose the DNS provider. - Click Issue now. The service creates the DNS record, waits until it's visible, and gets the certificate.
Deploying
Under Hosts, add where the certificate goes:
- Windows servers (domain or workgroup): pushed over WMI, IIS bindings updated by site and port.
- Pull agents: install the agent from the host's page with its one-line command. It fetches the certificate over HTTPS, so nothing needs to reach into that server. Linux agents handle Apache, HAProxy SNI folders, or run your own script.
- OPNsense HAProxy and Veeam Cloud Connect have their own host types.
Renewals and alerts
Once a day (02:00 by default) the service renews anything inside the renewal window (30 days by default) and redeploys it. Set the mail server and who to alert under Settings; you hear about failures, not successes.
How licensing works
- A license is for one server installation. Your plan sets how many certificates and hosts you can add.
- The server checks in with our license server once a day, sending only the key, an installation ID, the server name, the app version and the counts of certificates and hosts. It keeps working for 14 days without a connection.
- If a subscription ends, the console stops accepting changes, but automatic renewals keep running for 30 more days, and certificates already issued keep working until they expire.
- Going over a limit after a downgrade doesn't break anything; you just can't add more until you're under it again.
Moving to a new server
On the old server, Settings > License > Remove from this server frees the license. If the old server is gone, release it from your account (or it frees itself after 30 days without a check-in). Then activate on the new server.