Sign in

CertKit SSL Certificate Automation

@certkit.io
27 followers 27 following 92 posts

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates. Learn more at www.certkit.io

PostsRepliesMedia
CertKit SSL Certificate Automation @certkit.io · 7h
"Where is the SSL certificate for examplecom?" is now one search across every client you manage. New in CertKit: cross-collection search, a dashboard with a 90-day renewal timeline, and a read-only API for dashboards and invoices. www.certkit.io/blog/certkit...
certkit.io
CertKit for MSPs: a new dashboard, search everywhere, and the API
Every collection and client on one page, a search that finds any certificate, host, or agent, a new dashboard, and a read-only API for the rest.
000
CertKit SSL Certificate Automation @certkit.io · 29/09/2026
SSTP, DirectAccess, RD Gateway, IIS, Exchange, ADFS. None run an ACME client, and every renewal touches a binding, a restart, or a reboot. Oct 6, Richard Hicks and I automate all of it. Bring the appliance nobody has given you a straight answer on: events.teams.microsoft.com/event/894fa7...
events.teams.microsoft.com
Microsoft Virtual Events Powered by Teams
Microsoft Virtual Events Powered by Teams
000
CertKit SSL Certificate Automation @certkit.io · 28/09/2026
The certificate Common Name was deprecated in 2000. We checked 3 billion certs in CT logs and 96% still have one. Browsers ignore it. GlobalProtect, Cisco Umbrella, NetScaler, and Exchange don't. www.certkit.io/blog/does-a-... #PKI #SSL
certkit.io
Does a TLS Certificate Need a Common Name?
The certificate Common Name has been deprecated for decades, but your load balancer and Exchange connectors might not have gotten the memo.
000
CertKit SSL Certificate Automation @certkit.io · 25/09/2026
Apple's draft policy for Merkle Tree Certificates caps validity at 7 days. Not a shorter X.509. A new post-quantum cert type, validated from periodic out-of-band client updates, so it only has to outlive the update cycle. 7 days costs nothing when nothing human renews it. #PKI
020
CertKit SSL Certificate Automation @certkit.io · 23/09/2026
Some jerk got an SSL certificate for a subdomain we had forgotten about, and Google told us before our own CT log tool did. Now CertKit watches the log. You get an email when a certificate shows up for a name it has never seen on your domain. www.certkit.io/blog/ct-alerts
certkit.io
CT alerts: know when someone gets a certificate for your domains
CertKit now watches certificate transparency logs for your domains and emails you when a certificate appears that you have never seen before.
111
CertKit SSL Certificate Automation @certkit.io · 22/09/2026
Your once-a-year SSL renewal becomes a five-times-a-year renewal on March 15, when public cert lifetimes drop from 200 days to 100. At 47 days, twelve. Oct 6, live with Richard Hicks on automating renewal for Windows servers, VPN, and appliances. Free: events.teams.microsoft.com/event/894fa7...
events.teams.microsoft.com
Microsoft Virtual Events Powered by Teams
Microsoft Virtual Events Powered by Teams
000
CertKit SSL Certificate Automation @certkit.io · 21/09/2026
We're in the Japanese celebrity gossip site business now. A DNS record we forgot for ten years pointed at an IP we gave up. Some jerk got the IP, a Let's Encrypt cert, and a spam site The cert sat in our own CT tool the whole time. www.certkit.io/blog/danglin...
certkit.io
How a ten-year-old dangling DNS record handed one of our subdomains to spammers
We forgot a DNS record for ten years. Someone else got the IP, a certificate, and our subdomain. How dangling DNS becomes a subdomain takeover.
010
CertKit SSL Certificate Automation @certkit.io · 03/09/2026
Cloud SSL certificate monitoring only sees what the internet sees. Your intranet pages expire too, but they don't warn anyone first. CertKit agents now monitor SSL certificates inside your network, and judge trust from the host's own trust store. www.certkit.io/blog/certifi... #PKI #sysadmin
certkit.io
Certificate monitoring for your intranet hosts
CertKit agents now monitor TLS endpoints inside your network, judge trust from the host's trust store, and re-check hosts the moment a certificate deploys.
000
CertKit SSL Certificate Automation @certkit.io · 24/08/2026
I searched our own domain in the public certificate transparency logs. Three dev servers and four vendors, named. Nobody scanned us. We published it ourselves by getting SSL certificates. www.certkit.io/blog/somebod... #PKI
certkit.io
Somebody's been keeping a list of your certificates
There is a permanent public record of every certificate ever issued for your domain. You never agreed to it and you can't opt out. I read ours, and it names our dev servers and most of our vendors.
000
CertKit SSL Certificate Automation @certkit.io · 18/08/2026
You didn't turn on the TLS key exchanges the IETF just banned. They shipped that way. nginx, Apache and Windows Server enable RSA key exchange by default. RFC 10015 says MUST NOT. www.certkit.io/blog/tls-1-2... #TLS
certkit.io
TLS 1.2 isn't end of life, but it will be soon
Two RFCs in July took away three of TLS 1.2's key exchange methods and its entire future. The banned ones ship enabled by default in nginx, Apache, and Windows Server, which means you are probably sti...
000
CertKit SSL Certificate Automation @certkit.io · 30/07/2026
I spent months telling people not to run their own certificate authority. Today CertKit ships Private PKI. Running a CA is a job, so we took the job. Internal SSL certs that issue, renew, and get trusted automatically. www.certkit.io/blog/certkit... #PKI
certkit.io
CertKit Private PKI: A private certificate authority without running one yourself
I spent months telling you not to run your own certificate authority. Today CertKit ships Private PKI. Both things are true, because the job was the problem, and we took the job.
000
CertKit SSL Certificate Automation @certkit.io · 27/07/2026
Let's Encrypt issued its last client auth cert on July 8. They're 90-day certs, so the last expire in early October with no renewal behind them. If you run mTLS on public certs, that's the window. www.certkit.io/blog/public-...
certkit.io
Public mTLS client-auth certificates stop renewing in October
Chrome's root program is pulling mTLS client authentication out of the public web PKI. Let's Encrypt got there first, and the last client certificates they issued expire in early October.
000
CertKit SSL Certificate Automation @certkit.io · 14/07/2026
A 47-day SSL certificate is not a shorter version of the same job. It is a different job. Once a year, a person can renew it. Eight times a year, they cannot. Issuance was solved. Distribution is the hard part. runasradio.com/Shows/Show/1... #SSL #SysAdmin
runasradio.com
47 Day Certificates with Todd Gardner
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last o...
000
CertKit SSL Certificate Automation @certkit.io · 13/07/2026
If you learned the TLS handshake from a textbook, half the steps no longer happen. No ClientKeyExchange. No 37 cipher suites. No secret on the wire. Attacks removed them one by one. www.certkit.io/blog/tls-han... #TLS #SysAdmin
certkit.io
How the TLS handshake works, and why half of it is gone
Every HTTPS connection starts with a TLS handshake. Most explanations walk the steps without telling you why they exist, or why half the steps you learned no longer happen. The modern handshake is sho...
000
CertKit SSL Certificate Automation @certkit.io · 08/07/2026
CertKit now deploys SSL certificates to Microsoft Exchange, SQL Server, SSRS, and Citrix NetScaler. Exchange is auto-detected. Pick a template, pick a certificate, done. www.certkit.io/blog/easy-mo... #SSL #sysadmin
certkit.io
Certificate deployments just got an easy mode
The old deployment flow expected you to know certificate formats, store locations, and your way around a script editor. The new one asks for a template, a name, and a certificate. That's it.
000
CertKit SSL Certificate Automation @certkit.io · 07/07/2026
Why are SSL certificates dropping to 47 days? Because revocation is broken. OCSP fails open. Revocation lists go stale. A stolen certificate stays trusted too long. Short lifespans are the industry's workaround. runasradio.com/Shows/Show/1... #SSL #InfoSec
runasradio.com
47 Day Certificates with Todd Gardner
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last o...
000
CertKit SSL Certificate Automation @certkit.io · 06/07/2026
One SSL cert, three servers. Which one generates the private key? Generate-where-used breaks once a cert is shared. The key moves anyway. Design that, or it becomes scp in a cron job. www.certkit.io/blog/ssl-cer... #SSL #PKI
certkit.io
One SSL certificate on multiple servers
Generating the private key on the server it protects is the textbook answer. Then someone asks for a wildcard, or a second server, and the textbook doesn't have a chapter for that.
000
CertKit SSL Certificate Automation @certkit.io · 01/07/2026
One SonicWall. The SSL certificate import API is barely documented and shifts between SonicOS versions. Now repeat for every appliance you run, up to 12x a year. Build it yourself and you maintain it forever. www.certkit.io/blog/automat... #SSL
certkit.io
Automating SonicWall Certificate Deployment with the SonicOS API
Certificate lifetimes are shrinking to 47 days. Manually updating SSL certificates through the SonicWall Administration UI is no longer an option. We automate the process, but SonicOS doesn't make it ...
000
CertKit SSL Certificate Automation @certkit.io · 30/06/2026
The longest SSL certificate you can buy today is 200 days. By 2029 it will be 47. Revocation never worked, so the industry is killing long lifespans instead. @toddhgardner.com broke down the why on RunAs Radio. runasradio.com/Shows/Show/1... #SSL #PKI
runasradio.com
47 Day Certificates with Todd Gardner
The 47-day certificate is coming! While at NDC in Toronto, Richard received an update from Todd Gardner about his show last year: certificate authorities are moving toward SSL certificates that last o...
000
CertKit SSL Certificate Automation @certkit.io · 29/06/2026
Let's Encrypt is going post-quantum. I'm not worried about quantum computers. The real story in Merkle Tree Certificates: smaller handshakes, transparency built in, and even shorter cert lifetimes. www.certkit.io/blog/quantum... #SSL #PKI
certkit.io
Quantum is the least interesting part of quantum certificates
Let's Encrypt just committed to Merkle Tree Certificates for a post-quantum web. I don't think quantum computers are close. The plan is still worth your attention, just not for the reason the headline...
000
Reposted by CertKit SSL Certificate Automation
Richard Campbell @richcampbell.bsky.social · 22/06/2026
The problem with SSL certificates is revocation mechanisms - they just don't work. So the industry has responded by shortening lifespans, ultimately to only 47 days. @ToddHGardner.com talks on RunAs Radio at runasradio.com/Shows/Show/1... about automating routine renewal of certificates!
031
CertKit SSL Certificate Automation @certkit.io · 11/06/2026
Live SSL certificate deployment next week. Real setup, not a polished demo. If something breaks, we fix it on air. June 16, 11am Central. With Richard Hicks. us02web.zoom.us/webinar/regi... #CertificateManagement #WindowsIT
us02web.zoom.us
Welcome! You are invited to join a webinar: Certificate Automation in Practice: A Technical Deep Dive for Windows IT. After registering, you will receive a confirmation email about joining the webinar...
with Richard Hicks and Todd Gardner June 16 | 11:00am Central | 60 minutes | Free The first question most Windows IT teams have after deciding to automate certificate management isn't "should we do t...
010
CertKit SSL Certificate Automation @certkit.io · 08/06/2026
PKI has a term for the leaf-to-root trust chain. It has no term for the series of certs you've been renewing for years. Certbot calls it a lineage. Nobody else picked it up. At 47-day lifetimes, naming this correctly starts to matter. www.certkit.io/blog/certifi... #PKI #TLS
certkit.io
Certificate lineage: the concept your tools already use but nobody named
PKI has precise terminology for almost everything. The one thing it never named is the series of certificates you've been renewing for years. Here's what it is, why it matters now, and why your tools ...
000
CertKit SSL Certificate Automation @certkit.io · 04/06/2026
Let's Encrypt drops cert lifetimes to 45 days by Feb 2028, a year early. CertKit now supports their TLS Server profile, so you can issue 45-day certs today and test your automation before the deadline. www.certkit.io/blog/managed... #LetsEncrypt #SSL
certkit.io
Managed accounts for MSPs, plus 45-day certificates you can use today
MSPs can now stand up fully-managed CertKit accounts for their clients, deploy certificates and agents, then hand over the keys. We also added support for Let's Encrypt's TLS Server profile, so you ca...
030
CertKit SSL Certificate Automation @certkit.io · 03/06/2026
Managing SSL certs for clients? New: managed accounts. An MSP sets up the client's CertKit account, deploys certs and agents, then hands it over. Client owns it. You keep audited support access. www.certkit.io/blog/managed... #MSP #SSL
certkit.io
Managed accounts for MSPs, plus 45-day certificates you can use today
MSPs can now stand up fully-managed CertKit accounts for their clients, deploy certificates and agents, then hand over the keys. We also added support for Let's Encrypt's TLS Server profile, so you ca...
020
CertKit SSL Certificate Automation @certkit.io · 01/06/2026
Apple's 398-day limit exempts private CAs. Most people stopped reading there. There's a second Apple requirement: all TLS certs, 825 days max. Safari silently rejects anything longer. No bypass, no details. www.certkit.io/blog/apple-d... #PrivatePKI #PKI
certkit.io
Apple doesn't care who signed your certificate
Running a private CA to escape the public cert treadmill makes sense. Apple still enforces an 825-day validity limit in Safari on every TLS certificate, no matter who issued it.
020
CertKit SSL Certificate Automation @certkit.io · 26/05/2026
PSA: You don't need a private CA for internal SSL certificates. DNS-01 ACME challenges let you issue publicly trusted certs for servers that never touch the internet. No root cert distribution. No click-through warnings. www.certkit.io/blog/private... #PKI #SSL
certkit.io
You probably don't need private PKI for internal infrastructure
Most teams assume internal infrastructure needs a private CA. It doesn't - and skipping it saves you from a maintenance burden that never fully works anyway.
000
CertKit SSL Certificate Automation @certkit.io · 20/05/2026
When your auditor asks what happened to your certificates last Tuesday, you need an answer. CertKit now logs every action in your certificate lifecycle: issuances, renewals, revocations, deployments, agent approvals. With importance flags so you can find what matters. #CertificateManagement #PKI
000
CertKit SSL Certificate Automation @certkit.io · 08/05/2026
F5 LTM. Palo Alto. Azure Key Vault. Exchange. We shipped a deployment scripting template library for all of them. Pick your target, configure your variables, and CertKit pushes the certificate to your infrastructure. www.certkit.io/blog/deploym... #CertificateManagement #PKI
certkit.io
Remote deployment scripting
CertKit now ships centrally managed deployment scripts that push certificates directly to appliances, cloud platforms, and custom infrastructure, with a template library and encrypted variable storage...
010
CertKit SSL Certificate Automation @certkit.io · 05/05/2026
50 SSL certificates managed manually today means roughly 50 renewals a year. Same team, same certs, in 2029: 400. The CA/Browser Forum's new lifetime schedule doesn't just change how often you renew. It changes the job. www.certkit.io/blog/shrinki... #PKI #SSL
certkit.io
Certificate lifetimes are shrinking.
Certificate validity is dropping from 398 days to 47 days by 2029. Here is the canonical schedule, what's driving it, and what it does to your renewal workload.
010
CertKit SSL Certificate Automation @certkit.io · 29/04/2026
Your VPN, RRAS, and IIS all need certificates. None of them can run ACME. Most teams patch this with scripts and hope. May 26, Richard Hicks and I are doing 30 minutes on what actually works. www.certkit.io/blog/webinar... #WindowsServer #SSL
certkit.io
Live Webinar: certificate automation for Windows infrastructure
On May 26, I'm doing a 30-minute live session with Richard Hicks on what actually works for SSL certificate automation in Windows environments. VPNs, IIS, RRAS, vendor appliances, the endpoints that c...
000
CertKit SSL Certificate Automation @certkit.io · 27/04/2026
Philip Greenspun's Tenth Rule: any complicated C program contains a bad implementation of half of Lisp. Certificate automation has the same problem. Todd named it. www.certkit.io/blog/todds-t... #CertificateManagement #SysAdmin
certkit.io
Todd's Tenth Rule of certificate automation
Any sufficiently complicated SSL certificate renewal system contains an ad hoc, informally-specified, bug-ridden, slow implementation of half a certificate lifecycle manager. I'm taking credit for thi...
010
CertKit SSL Certificate Automation @certkit.io · 22/04/2026
Managing SSL certs across dozens of servers? You shouldn't have to configure each one by hand. New in CertKit: copy and link agent configs across your fleet, search and filter your monitors, plus our first GDPR Data Processing Agreement. www.certkit.io/blog/shared-... #CertificateManagement #SSL
certkit.io
Shared agent configs, monitor search, and a GDPR policy
Copy and share agent configurations across your fleet, search and sort your monitored domains, and our first official Data Processing Agreement for GDPR compliance.
000
CertKit SSL Certificate Automation @certkit.io · 17/04/2026
CertKit 1.9: push agent updates from the dashboard, no more logging into every server. Plus Google Trust Store as a second ACME issuer alongside Let's Encrypt. www.certkit.io/blog/agent-1.9 #CertificateManagement #SSL
certkit.io
Remote Agent Updates and Google Trust Store
Agent 1.9 adds remote push updates so you can upgrade your entire fleet from the dashboard, plus first-class support for Google Trust Store as an ACME certificate issuer alongside Let's Encrypt.
000
CertKit SSL Certificate Automation @certkit.io · 13/04/2026
One certificate management vendor used the word "trust" 17 times on their homepage. I still couldn't tell what they sell or what it costs. Apparently that's what the sales call is for. www.certkit.io/blog/perform... #PKI #cybersecurity
certkit.io
Performative Trust Maximalism
Certificate management vendors use the word "trust" so often it stops meaning anything. They also won't tell you what the product does, or what it costs, without a sales call first. These are, I shoul...
010
CertKit SSL Certificate Automation @certkit.io · 08/04/2026
CertKit is out of beta. 600 signups. Certificates issuing, deploying, renewing in production. Features we never planned, built because users needed them. www.certkit.io/blog/out-of-... #PKI #CertificateManagement
certkit.io
CertKit is out of beta
We launched the beta in July 2025. Over 600 users later, the beta is over. Here's what we built, what we learned, and a thank you to the early adopters who helped make it real.
000
Reposted by CertKit SSL Certificate Automation
Bryan Hogan @bryanjhogan.bsky.social · 02/04/2026
Podcast with @toddhgardner.com about how web certificates work. In the next episode we'll talk about Certkit, a solution for SSL Certificate Lifecycle Management. nodogmapodcast.bryanhogan.net/180-todd-gar...
042
Reposted by CertKit SSL Certificate Automation
Richard Campbell @richcampbell.bsky.social · 01/04/2026
Are you ready to take a look at Richard's home lab? Living in a remote location with intermittent power and internet makes for a challenging lab environment! Check out the details on RunAs Radio at runasradio.com/Shows/Show/1...
041
CertKit SSL Certificate Automation @certkit.io · 01/04/2026
Yes, we shipped a retro MS-DOS modal today. No, it's not an April Fools joke. Agent 1.8 also adds Windows Certificate Store support, Java Keystore format, and RDP auto-detection. www.certkit.io/blog/agent-1.8 #CertificateManagement #Windows
010
CertKit SSL Certificate Automation @certkit.io · 30/03/2026
Let's Encrypt ran a mass revocation drill on 3 million production certificates in March 2026. They shortened ARI windows to simulate an emergency and watched who responded. Most ACME clients never noticed. www.certkit.io/blog/lets-en... #PKI #ACME
certkit.io
Let's Encrypt simulated revoking 3 million certificates. Most ACME clients didn't notice.
Let's Encrypt ran their first annual mass revocation drill, shortening ARI renewal windows across 3 million production certificates. Here's what happened.
020
CertKit SSL Certificate Automation @certkit.io · 26/03/2026
Oh look, a CA is "breaking the model" by offering unlimited managed certificates for ONLY $99,000. Meanwhile, you can do it for $99 with CertKit. www.prnewswire.com/news-release...
prnewswire.com
OmniTrust Breaks the Certificate Lifecycle Management Model with $99,000 PKI and Unlimited Certificates
/PRNewswire/ -- OmniTrust today announced a new offering that challenges the cybersecurity industry's reliance on certificate-counting models, delivering...
000
CertKit SSL Certificate Automation @certkit.io · 25/03/2026
Your security policy says private keys can't leave the network. Certificate automation says they have to. We just fixed that. www.certkit.io/blog/certkit-keystore #PKI #CertificateManagement
certkit.io
CertKit Keystore: Private keys that never leave your infrastructure
CertKit manages your certificates from issuance through deployment. For most organizations, that includes holding your private keys. For some, that's a hard no. The Local Keystore is for them.
010
CertKit SSL Certificate Automation @certkit.io · 23/03/2026
Epic Games had a wildcard cert expire in 2021. Monitoring caught it in 12 minutes. Recovery took 5.5 hours and 25 people. The cert renewed fine. Distribution is where it fell apart. www.certkit.io/blog/certifi... #PKI #TLS
certkit.io
Certificate distribution is the last mile nobody solved
Certbot solved certificate issuance. It's great at that. The hard part is everything that happens after: getting the certificate file to every server that needs it, in the right format, with the right...
010
CertKit SSL Certificate Automation @certkit.io · 16/03/2026
Mass certificate revocation isn’t a fire drill. It’s a 24-hour clock with thousands of certs on the line. ARI (RFC 9773) was built to handle exactly this. But it only works if your ACME client is actually listening. www.certkit.io/blog/ari-sol... #PKI #TLS
certkit.io
ACME Renewal Information (ARI) solves mass certificate revocation
When a CA has to revoke hundreds of thousands of certificates on a short deadline, email notifications aren't enough. ARI is the protocol that lets the CA tell your client directly: renew now. Here's ...
011
CertKit SSL Certificate Automation @certkit.io · 11/03/2026
CertKit now supports ACME ARI and 6-day certificates. ARI means the CA tells us when to renew. We check it multiple times a day. The next mass revocation event will be boring for you. www.certkit.io/blog/acme-ar... #PKI #TLS
certkit.io
ACME ARI support and 6-day certificates
CertKit now polls Let's Encrypt multiple times a day to check when each certificate should renew. That means mass revocations happen automatically, without you doing anything. We also added support fo...
010
CertKit SSL Certificate Automation @certkit.io · 09/03/2026
Your certificate renewed. The old one is still serving. Certbot solves "I forgot to renew." It doesn't tell you whether the new cert actually made it to your server. LinkedIn learned this the hard way in 2019. www.certkit.io/blog/how-to-... #PKI #TLS
certkit.io
How to verify certificate renewal actually worked
Certbot ran. The logs show success. Exit code 0. LinkedIn found out the hard way that renewed and deployed are not the same thing. The verify step is the part of certificate automation nobody builds u...
010
CertKit SSL Certificate Automation @certkit.io · 04/03/2026
Certificate management has always been a one-person job. Until something breaks, everyone ignores it. Until that one person leaves. CertKit now supports team access: roles, SAML SSO, MFA, and a weekly email digest. www.certkit.io/blog/user-ma... #CertKit #PKI
certkit.io
User management, MFA, SSO, and weekly summaries are live
CertKit now supports team accounts with role-based access, multi-factor authentication, SAML single sign-on, and a weekly email digest. Here's what shipped and why it matters.
010
CertKit SSL Certificate Automation @certkit.io · 02/03/2026
How does CertKit work? www.certkit.io/how-it-works
certkit.io
How CertKit Works - Automated SSL Certificate Management
CertKit automates your entire certificate lifecycle. Issue certificates via ACME, deploy them with the CertKit Agent, and verify everything with real TLS checks. No open ports, no ACME on your servers...
010
CertKit SSL Certificate Automation @certkit.io · 02/03/2026
March 15 is the last day to issue a certificate with ~1 year of validity. After that, 200-day max. Then 100 in 2027. Then 47 in 2029. Renew now and you set your own automation schedule. Wait, and the CA/B Forum sets it for you. www.certkit.io/blog/last-ca... #PKI #CertificateManagement
certkit.io
Last call on 398-day certificates
The bar closes March 15. After that, no CA can serve you a 398-day certificate. If you're still managing commercial SSL certs manually, you have two weeks to grab one last round of full-year runway be...
010
CertKit SSL Certificate Automation @certkit.io · 25/02/2026
CertKit Agent 1.6 is out: Microsoft RRAS support, deploy windows, and agent locking. Shorter cert lifetimes mean certificate automation has to act like real releases: issue, deploy, verify (and do it on your schedule). www.certkit.io/blog/agent-1.6 #CertificateAutomation #SysAdmin
certkit.io
CertKit Agent update: RRAS support, deploy windows, and agent locking
The CertKit Agent now supports Microsoft RRAS for VPN certificate management. We also added deploy windows so you can control when certificate updates happen, and agent locking to protect your infrast...
010