CA/Browser Forum: from March 2026, max. 200-day certificate lifetime

Certificates on Windows servers
renewed automatically — without gaps.

TLS/SSL certificates for IIS, RDS, Exchange, LDAPS and more: fully automatic discovery, renewal, deployment and monitoring. ACME-native. Governance-secured. BAIT- and DORA-compliant.

73 % of all Windows certificates expire unplanned
€ 50 k+ in damages per 15 min of unplanned TLS outage
DORA Art. 9 requires seamless certificate evidence
Architecture

How CertOps works — at a glance

Four components, one closed loop. No manual intervention in normal operation.

Windows-Server IIS · RDS · Exchange LDAPS · WinRM · SQL CertOps Orchestrator Cert-CMDB · ACME-Client · HITL CA / ACME Let's Encrypt · ZeroSSL step-ca · Sectigo/DigiCert Monitoring Prometheus · Grafana Alertmanager · Reports PowerShell-Agent Cert-Bind · HITL-Gate Evidence-Record scan / report ACME renew new certificate deploy (HITL gate) bind metrics / events alert Automatic flow Return channel
Why CertOps

Three reasons certificate automation is no longer optional

Operator approves an automatic certificate renewal — HITL gate in action

No more blind spots

73% of all Windows certificates expire unplanned — because they're not centrally tracked anywhere. CertOps automatically builds a complete cert CMDB: every FQDN, every SAN, every expiry date, every service binding — always current.

Blackbox exporter scans all endpoints daily

Fully automated — no manual work

30 days before expiry, CertOps triggers the renewal, deploys the new certificate and binds it to all affected Windows services. The operator approves via HITL gate — and that's it. No ticket escalation, no late-night emergency work.

ACME-native: Let's Encrypt, step-ca, Sectigo/DigiCert

Audit-ready at the push of a button

Every issuance, every rebind, every HITL approval automatically generates a machine-readable evidence record. BAIT, DORA, BSI and ISO 27001 reports are generated from existing data — no manual documentation.

Quarterly compliance reports generated automatically
Urgency

The CA/Browser Forum roadmap — automation is mandatory

The industry is consistently shortening certificate lifetimes. Anyone who doesn't automate will soon face impossible tasks.

Phase 1
until 15.03.2026
398 d
DCV reuse 398 d

Still possible manually — but already labour-intensive.

Today
Phase 2
from 15.03.2026
200 d
DCV reuse 200 d

Manually borderline. Automation strongly recommended.

Coming soon
Phase 3
from 15.03.2027
100 d
DCV reuse 100 d

No longer manually viable. Automation mandatory.

Still — days
Phase 4
from 15.03.2029
47 d
DCV reuse only 10 d

Manually virtually impossible. Full automation is the only option.

End of the line
How it works

Four steps — fully automated

Every step has a governance checkpoint. Nothing runs blindly.

1

Discovery

A blackbox exporter scans all endpoints daily. Cert CMDB automatically captures FQDN, SANs, issuer, expiry date and service binding.

2

Renewal (ACME)

30 days before expiry, the orchestrator automatically triggers a renewal — via ACME against Let's Encrypt, ZeroSSL, Sectigo/DigiCert or an internal step-ca.

3

Windows binding (HITL)

The PowerShell agent binds the new certificate to IIS, RDS, Exchange, LDAPS etc. For production systems: approval via HITL gate required.

4

Monitor & alert

Prometheus checks the new expiry date after binding. Tiered alerts at 30/14/7/3 days. Automatic incident on renewal failure.

Feature set

What CertOps delivers

Discovery & inventory

Automatic TLS probing of all configured endpoints. Complete cert CMDB: FQDN, SANs, issuer, expiry date, service binding — always current.

All certificates at a glance

Automatic renewal

ACME-native: Let's Encrypt/ZeroSSL for public hosts, step-ca for internal servers, Sectigo/DigiCert ACME for OV/EV. Renewal 30 days before expiry.

Automatically renewed — 30 days before expiry

Windows deployment

PowerShell agent automatically binds the new cert to IIS, RDS/RD Gateway, Exchange, LDAPS, WinRM, SQL Server, NPS. Service-specific hooks per service.

IIS, RDS, LDAPS, Exchange — no downtime

Governance & audit trail

Every issuance and every bind generates a machine-readable evidence record. Production rebind only after explicit HITL-gate approval.

Seamless proof — every action documented

Monitoring & alerts

Blackbox exporter + Prometheus: tiered alerts at 30/14/7/3 days before expiry. Grafana dashboard. Automatic incident on renewal failure.

Expiry forecast, MTTR, compliance score

Compliance reports

Quarterly compliance reports for BAIT, DORA, BSI IT-Grundschutz and ISO 27001 — automatically generated from existing cert data. No manual compiling.

BAIT-/DORA-compliant reports on request

RDP publisher signing Beta

Signs .rdp connection files with a code-signing certificate (rdpsign.exe) and maintains the GPO trusted-publisher list — the mstsc "Unknown publisher" warning disappears. Issuance always HITL-approved.

No more publisher warning on RD Web/RemoteApp
Regulatory

Regulatory requirements — met automatically

CertOps supplies the audit trail automatically. Every issuance, every rebind — machine-readable, verifiable, report-ready.

BAIT
AT 4.3 · KRITIS availability

Banking supervisory IT requirements: cert-lifecycle documentation and automated renewal as a control against cert outages. An expired certificate = an availability incident.

DORA
Art. 9 + Art. 10

Digital Operational Resilience Act: ICT security (Art. 9) makes key and certificate management mandatory. Business continuity (Art. 10): cert outages are in scope for the BCP.

BSI IT-Grundschutz
OPS.1.1.7 · APP.3.2

Patch and change management: certificates as cryptographic patches. Web-server security (APP.3.2): TLS currency as a baseline-protection control — demonstrably met.

ISO 27001
A.8.24 — Use of Cryptography

ISO/IEC 27001:2022: automated key and certificate lifecycle as a requirement. CertOps delivers the technical implementation and the documented proof.

Compatibility

Supported Windows services

Eight service-specific PowerShell hooks — each using the native Windows binding API.

Service Binding method Restart
IIS (Web, OWA, SharePoint) WebAdministration PowerShell Optional / IISReset
RDS / RD-Gateway WMI TermServices + netsh TermService restart
LDAPS (Domain Controller) NTDS\Personal Store NTDS service restart (~10 s)
Exchange (IIS+SMTP+IMAP+POP) Enable-ExchangeCertificate (EMS) IISReset
WinRM HTTPS WSMan-Listener + netsh WinRM Restart
SQL Server WMI / Registry SQL service restart
NPS netsh nps No restart
RDP-Publisher-Signing (RD-Web/RemoteApp) Beta rdpsign.exe + GPO-Thumbprint-Liste No restart
Partner model

Reseller & MSP model

IT systems houses and MSPs deploy CertOps and resell it white-label to their customers — savings banks, municipalities, SMEs. The controller runs on-premise at the reseller (full data sovereignty). Intelego supplies software, updates and governance.

CertOps MSP model: one systems house operates CertOps for many end customers
200
end-customer sub-scopes per licence
4.9×
customer ROI (customer value / licence price)
€ 0
infrastructure cost at Intelego

On-prem white-label

Controller in the reseller's infrastructure. Data never leaves the premises. Ideal for BAIT and savings-bank requirements with strict data sovereignty.

  • Unlimited endpoints
  • Up to 200 end-customer sub-scopes
  • Your own branding

Your margin, your customers

Resellers bill end customers themselves — on their own terms. Intelego supplies software, updates, support and compliance documentation in the background.

  • Isolated inventory DBs per customer
  • Isolated cert stores
  • Your own pricing

Intelego in the background

Software updates, security patches, new service hooks and compliance-report templates are maintained and delivered by Intelego. No in-house dev team required.

  • Updates and patches included
  • New service hooks at no extra cost
  • Governance documentation included
Pricing

Transparent. Cancellable monthly. No vendor lock-in.

PoC
€ 0 / 30 days
Prove the loop — risk-free
  • Up to 10 endpoints
  • Full controller stack
  • Windows agent + 1 service hook
  • Intelego supports setup
  • No contract, no automation
Start PoC →
Per-endpoint
For direct customers — plus €1,990 setup · minimum 10 endpoints
10–25 endpoints € 25/Ep/Mo
26–100 endpoints € 14/Ep/Mo
101–500 endpoints € 9/Ep/Mo
  • Intelego-managed controller
  • Monitoring dashboard (Grafana)
  • Compliance report included
  • All service hooks included
  • Cancellable monthly
Request →

All prices net plus VAT · cancellable monthly · EU hosting · GDPR-compliant · offer exclusively for businesses, trades, public authorities and legal entities under public law (Sect. 14 BGB) — not a consumer transaction (Sect. 13 BGB)

CertOps — a digital certificate shield protecting Windows infrastructure
Security by design

Every production rebind sits behind a HITL gate. Private keys never leave the premises. EU hosting. GDPR-compliant.

FAQ

Frequently asked questions

Does CertOps work with our existing ADCS?

Yes. CertOps supports two CA paths: if a Microsoft Active Directory Certificate Services is already in place, CertOps uses the ADCS adapter (NDES/SCEP via certreq). If no ADCS is present, the bundled step-ca takes over as a private ACME CA. Both paths can run in parallel — ADCS for AD-joined hosts, step-ca for external or non-domain hosts.

What happens if a renewal fails?

CertOps sends tiered alerts at 30 / 14 / 7 / 3 days before expiry — regardless of whether a renewal was triggered. A renewal failure automatically creates an incident in the service desk. The certificate never silently expires: either the renewal succeeds, or an alert escalates in time to the responsible operator.

Where is our certificate data — does it leave our premises?

In the standard model (on-prem white-label), the entire controller stack — orchestrator, cert inventory DB, step-ca, Prometheus/Grafana — runs on your own Linux server in the reseller's infrastructure. Private keys, FQDN inventory and compliance reports never leave the premises. Intelego supplies software and updates but has no access to the running instance.

Do we have to use Let's Encrypt or a public CA?

No. For internal Windows servers (not publicly reachable), CertOps uses the bundled step-ca as a private ACME CA — fully on-premise, with no external CA dependency. Let's Encrypt and ZeroSSL are optional for publicly reachable hosts. OV/EV certificates (e.g. for savings-bank branding) are supported via Sectigo or DigiCert ACME.

How is a production cert rebind secured?

Every production rebind passes through a HITL gate (human-in-the-loop). The Windows agent checks before binding whether the gate is approved — if not, no binding occurs. Approval comes from an authorised operator (Cockpit or Matrix chat). Every approval and every bind generates a machine-readable evidence record for the audit trail.

Which Windows services are supported for automatic binding?

CertOps supports all common Windows services with certificate-dependent configuration: IIS (incl. OWA, SharePoint), RDS / RD-Gateway, LDAPS (Domain Controller), Exchange (IIS + SMTP + IMAP + POP), WinRM HTTPS, SQL Server and NPS. Each service has its own PowerShell hook that uses the service-specific binding API.

What is RDP publisher signing — and why do I need it?

Windows shows the warning "Unknown publisher", when opening an .rdp connection file that isn't signed — typical for RD Web/RemoteApp portals that automatically generate .rdp files for end users. CertOps issues a code-signing certificate for this purpose (private CA, HITL-approved), signs the files with rdpsign.exe and maintains the GPO trusted-publisher list. After that, mstsc shows the real publisher name instead of the warning. Status: Beta — the code is implemented, rollout happens gradually per customer.

See the loop live now

We'll prove discovery → renewal → binding → monitoring
on your Windows servers — in 30 days, risk-free, no contract.

No vendor lock-in EU hosting GDPR-compliant Private keys never leave your premises