All features

Deployment agents

More than 30 signed agents install certificates on Windows, Linux, network appliances, and cloud platforms. Push or pull, your choice.

  • IIS, Exchange, SQL Server, ADFS, and more Windows roles
  • Nginx, Apache, HAProxy, Tomcat, Postfix, and PostgreSQL over SSH
  • NetScaler, Kemp, pfSense, Synology, NetApp, and VMware
  • AWS ACM, Azure Key Vault, and Google Cloud Certificate Manager

The certificate has to land on the server

Issuing a certificate is the easy part. The hard part is installing it correctly on an Exchange server, binding it in IIS, reloading HAProxy, or updating a NetScaler without downtime. sslbrain agents own exactly that step: each agent knows its platform and performs installation, binding, and reload with validation and rollback.

Push or pull

Push agents run from the appliance over SSH for Linux, WinRM for Windows, or REST APIs for appliances and cloud services. The pull model uses the Windows Service Agent, an MSI package you can roll out via GPO, SCCM, or Intune. It fetches tasks from sslbrain over outbound HTTPS, so there are no firewall openings and no WinRM to enable.

Signed code, your policy

Every agent package is signed with ECDSA P-384, and every server carries a ScriptPolicy deciding what it accepts: FairSSL-signed agents only, verified community agents, or your own custom agents. Browse the full catalog on the features page and the principles under policy management.

Ready to automate your certificates?

Get started in under 5 minutes with the Free plan.