Product
Automatic SSL certificate renewal for MSPs
The KairosLink certificates module covers the three things an MSP needs to do with its customers' certificates: know which certificates exist and when they expire, watch the SSL of public domains, and renew SSL certificates without paying or touching the server every year. All from the same console where you already do monitoring for the computers.
Certificate inventory on every computer
The agent scans the certificate stores of each Windows computer (LocalMachine, including the Personal, WebHosting and Remote Desktop stores) and pulls each certificate's subject, issuer, expiration date, whether it has the private key attached and whether it is self-signed. The global view lists every certificate sorted by nearest expiration, with a traffic light based on the warning and critical thresholds, and a search box by subject, issuer or friendly name. The scan runs automatically once a day on online computers and can also be requested on demand for a specific computer.
Which of your domains' SSL certificates are about to expire?
Besides the certificates installed on computers, KairosLink checks the certificate served by any public domain through a real TLS handshake from the panel, with no agent needed on that server. For each domain it records the issuer, the subject and the expiration, and detects connection errors with a readable message: name that does not resolve in DNS, timeout, connection refused or failed TLS handshake. The check runs when the domain is added, once a day automatically, and whenever you ask.
Email alerts use a warning threshold at 30 days before expiration and a critical one at 7 days, both editable per organization. Each domain has a single open alert: it escalates from warning to critical as expiration approaches and resolves itself when the certificate is renewed or becomes valid again, so nobody gets the same reminder twenty times.
Automatic SSL certificate renewal
KairosLink issues and renews SSL certificates with Let's Encrypt's ACME protocol and DNS-01 validation. It supports single-domain, multi-domain (several names on one certificate, SAN) and wildcard certificates (*.domain.com). Issuance follows an automatic flow: the agent generates the key pair and the CSR on the server, KairosLink publishes the validation TXT record in DNS, waits for propagation, validates against Let's Encrypt, downloads the certificate and installs it on the computer.
The private key is generated on and stays on the customer's server. It is never transmitted to or stored in the platform: only the CSR and the issued certificate, which are public material, travel between the agent and KairosLink. Installation is automatic on IIS, where it creates the HTTPS binding on port 443, and on Exchange, where it assigns the certificate to the IIS and SMTP services. Each renewal fires 30 days before expiration with nobody involved, and if a renewal fails twice in a row an alert opens so the technician can review it.
Because validation is done over DNS and not through an inbound connection to the server, it also works for internal servers that are not exposed to the internet. Every issuance leaves a step-by-step trail in an event log: CSR requested, CSR received, order created, TXT record published, challenge validated, certificate issued, installed and service activated, with the date of each stage.
The savings: renewal with no per-certificate cost
Commercial wildcard and multi-domain certificates cost hundreds of dollars a year, and renewals are usually pricier than the first year. The certificates KairosLink issues via ACME have no per-certificate cost and renew themselves, wildcard and multi-domain included. The MSP stops paying for each certificate and stops losing time renewing by hand, and with the reports it can show each customer which certificates it manages for them.
Frequently asked questions
What is automatic SSL certificate renewal?
How do I renew an SSL certificate without paying every year?
What happens when an SSL certificate expires?
Does it work for Exchange Server?
Does it work for internal servers with no internet access?
Where does the private key live?
What do I need to use it?
Does it cover wildcard and multi-domain certificates?
All modules included. No credit card.