Getting started

From download to automatic renewals. Detailed help for every screen is built into the app (Help in the menu).

Requirements

  • A Windows Server 2016 or later machine (a VM is fine) for the console and the service.
  • SQL Server, or let the installer set up SQL Express on the same machine.
  • Outbound HTTPS from that server to Let's Encrypt, your DNS provider's API and our license server.
  • An account with API access at your DNS provider (Cloudflare, GoDaddy), or a Windows DNS or BIND server you control.

Install

  1. Sign in to your account and download the installer.
  2. Run it as an administrator. It installs the web console (its own HTTPS listener, no IIS needed), the background service, the .NET runtime and, if you want, SQL Express.
  3. Open the console address it shows at the end and create the first administrator.

Enter your license

Go to Settings > License, paste the key from your email and click Activate. The server confirms it with our license server, which takes a second. Line breaks copied from an email don't matter.

Your first certificate

  1. Credentials: add your DNS provider's API token (stored encrypted).
  2. Certificates > Add: enter the main name (for example *.example.com), any extra names, and choose the DNS provider.
  3. Click Issue now. The service creates the DNS record, waits until it's visible, and gets the certificate.

Deploying

Under Hosts, add where the certificate goes:

  • Windows servers (domain or workgroup): pushed over WMI, IIS bindings updated by site and port.
  • Pull agents: install the agent from the host's page with its one-line command. It fetches the certificate over HTTPS, so nothing needs to reach into that server. Linux agents handle Apache, HAProxy SNI folders, or run your own script.
  • OPNsense HAProxy and Veeam Cloud Connect have their own host types.

Renewals and alerts

Once a day (02:00 by default) the service renews anything inside the renewal window (30 days by default) and redeploys it. Set the mail server and who to alert under Settings; you hear about failures, not successes.

How licensing works

  • A license is for one server installation. Your plan sets how many certificates and hosts you can add.
  • The server checks in with our license server once a day, sending only the key, an installation ID, the server name, the app version and the counts of certificates and hosts. It keeps working for 14 days without a connection.
  • If a subscription ends, the console stops accepting changes, but automatic renewals keep running for 30 more days, and certificates already issued keep working until they expire.
  • Going over a limit after a downgrade doesn't break anything; you just can't add more until you're under it again.

Moving to a new server

On the old server, Settings > License > Remove from this server frees the license. If the old server is gone, release it from your account (or it frees itself after 30 days without a check-in). Then activate on the new server.