Built for real infrastructure
sslbrain manages certificates across Windows and Linux servers, supports multiple certificate authorities, and automates the entire lifecycle.
Shorter lifetimes, more renewals
Certificate lifetimes are getting shorter, and will get shorter again. The CA/Browser Forum has binding deadlines that step the maximum lifetime down in three phases through 2029.
Maximum lifetime and DCV reuse since March 2026.
Next step. Lifetime and DCV reuse are halved.
Final target. DCV reuse drops to 10 days, so domain validation runs every renewal.
With 50 servers and 47-day certificates that becomes up to 600 renewals per year if each certificate is renewed at one third of its lifetime as best practice. sslbrain uses a central scheduler that scales automatically regardless of how short lifetimes become.
Read more about the 47-day timelineSwitch CA without touching a server
sslbrain communicates with the CAs and installs the certificates on your servers through signed agents. If a CA changes its API, standards, or pricing, we update the connection and your servers notice nothing.
You can switch between Let's Encrypt, Google Trust Services, DigiCert, Sectigo and GlobalSign without changing configuration on a single server. sslbrain absorbs the complexity.
Certificate Sources
We support any ACME-based CA.
- Let's Encrypt (ACME)
- Google Trust Services (ACME)
- DigiCert
- Sectigo
- GlobalSign Atlas
- Internal CA
- Custom CA
Endpoints
Deploy certificates to any server platform.
- Microsoft IIS (Windows Server)
- Apache HTTP Server
- Nginx
- HAProxy
- Tomcat / Java Keystore
- FortiGate / FortiMail
- Citrix NetScaler
- Microsoft Exchange
- Any endpoint via custom agents
Protocol Support
Industry-standard protocols for validation and deployment.
- ACME (RFC 8555)
- DNS-01 validation (auto-DNS)
- HTTP-01 validation
- SSH-based deployment
- WinRM-based deployment (Windows)
- REST API integration
Lifecycle Management
Automate the entire certificate lifecycle.
- Automatic DNS-based validation
- Automatic certificate discovery
- Expiry monitoring & alerts
- Automated renewal
- Multi-domain (SAN) certificates
- Wildcard certificates
- Certificate revocation
Security
Enterprise-grade security built in.
- On-premises. Your data stays on your network
- Data encrypted by rotating online vault key
- Code running on your network is visible and inspectable
- Built-in and community agents security inspected and signed
- mTLS client certificates for Windows Service Agent
- Scripts executed via stdin, never written to disk
- Role-based access control
- Audit logging
Operations
Simple to deploy and operate.
- Single Docker container
- SQLite database (zero config)
- Setup wizard (3-minute onboarding)
- Web-based management UI
- Agent-based architecture
- Update agents and sslbrain via sslbrain Cloud
- Fixed IPs for firewall whitelisting
Explore the features in depth
Each core capability explained the way it works in practice.
Automatic renewal
sslbrain renews your certificates in the CA's recommended window or at 75% of lifetime and installs them where they are used. Shorter lifetimes stop being your problem.
Read moreNetwork discovery
Scan your IP ranges and find every TLS certificate in the environment, including the ones nobody documented. Visibility before automation.
Read moreDeployment agents
More than 30 signed agents install certificates on Windows, Linux, network appliances, and cloud platforms. Push or pull, your choice.
Read moreLeast privilege in practice
The pull agent on the server never receives SSH keys or sudo from the appliance. It only runs signed tasks, and you decide how much privilege it holds.
Read moreACME and Auto-DNS
sslbrain speaks ACME to the CAs and answers domain validation automatically. Your servers never run their own ACME clients.
Read moreOn-prem appliance
sslbrain runs as a Docker container inside your network. Private keys and credentials never leave your infrastructure.
Read moreSource-available code
Every line of code can be inspected, and every agent is signed with a YubiKey. Trust in a security product should be verifiable.
Read more46 agent packages
Supported platforms
sslbrain supports 46 agent packages across Windows, Linux, cloud, appliances, and custom workflows.
Windows and Microsoft
16 agent packages
- Windows IIS 8+
- IIS Web Server
- IIS Central Certificate Store
- Microsoft Exchange 2013-2019
- Microsoft Exchange
- Windows SQL Server
- Windows ADFS
- Windows Certificate Authority
- Web Application Proxy
- Windows Remote Desktop
- Windows SSL/TLS Bindings
- Windows Certificate Store
- Windows Server
- Dynamics NAV / Business Central
- Milestone XProtect
- Veeam Backup & Replication
Linux and services
8 agent packages
- Nginx
- Apache
- HAProxy
- Apache Tomcat
- Postfix
- Dovecot
- PostgreSQL
- Oracle WebLogic
Cloud certificate stores
7 agent packages
- AWS Certificate Manager
- Azure Key Vault
- Google Cloud Certificate Manager
- Cloudflare
- Akamai CPS
- Azure App Service
- AWS CloudFront
Appliances, networking, and virtualization
13 agent packages
- Citrix NetScaler / ADC
- Cisco Secure Firewall Device Manager
- Palo Alto Networks PAN-OS
- F5 BIG-IP
- Sophos Firewall
- Fortinet FortiGate
- Fortinet FortiMail
- Kemp LoadMaster
- pfSense
- Synology DSM
- NetApp ONTAP
- VMware vCenter
- VMware ESXi
Any platform can be supported via custom agents. Write your own deployment script for any platform or application.
Agent-based architecture
sslbrain uses YAML-defined agents to handle certificate deployment. Each agent is a set of platform-specific scripts that run on the endpoint. This approach means:
Windows Service Agent (.NET 9, pull-based)
No inbound ports required. Pulls signed task packages via mTLS-encrypted HTTPS. The agent enrolls with a client certificate at registration and renews it automatically.
Secure agent execution
Scripts are executed via stdin piping directly to the interpreter. No script files are written to disk. Secrets are passed via environment variables, never as command-line arguments.
Security you can verify
sslbrain is designed to be transparent. All code is visible and inspectable.
YubiKey-signed agents
Every script that runs on or against your servers is signed by us, whether it is our own script or a community version we have verified. All scripts are visible on GitHub and can be inspected.
You decide what runs
Every server has a ScriptPolicy defining what it accepts, from FairSSL-signed scripts only to community scripts or your own custom scripts. The policy can be locked via Group Policy.
Least privilege by default
The recommended pull agent never receives SSH keys or sudo from the appliance and only executes signature-verified tasks. How much privilege the service holds locally is your call: root for simplicity, or a scoped service user with access to one service's certificate files and one reload command.
Read about least privilege in practiceData stays on-premises
We cannot see your data
Stolen copy is useless
NIS2 documentation
NIS2 requires documented, monitored, and auditable security processes. A cron job is not a documented process. sslbrain provides the structure and evidence that NIS2 demands for certificate management.
Ready to automate your certificates?
Get started in under 5 minutes with the Free plan.
sslbrain is built by FairSSL A/S, a Danish company with 16 years of experience in the SSL certificate industry.