Windows and Active Directory estates

Every TLS certificate in your estate, found and watched.

CertCommand inventories certificates across your Windows hosts and network endpoints, records every place each one is bound, and tells the right people before anything expires. One Windows Server, no agents on your hosts, no internet access required.

Agentless over WinRM Runs as a gMSA Read-only JEA endpoint

01

Nothing is probed until you accept it

Discovery fills a review queue. Contacting a host is a decision somebody makes on the Discovery page, not a default. Accept the entries you want and CertCommand creates the asset and probes it.

02

Read-only by construction

Windows collection runs through a JEA endpoint that exposes three read-only functions in a NoLanguage session. Certificates come back as public DER. Private key material never leaves the host.

03

One server, no agents

A single Windows service on Kestrel, running as a gMSA. No IIS, no database server, and nothing installed on the hosts you inventory. Licensing never touches the network. The daily update check is the one outbound call, and you own the switch.

Why this got worse

Renewals used to be a yearly chore.

Public TLS certificates were capped at 398 days in 2020, and the CA/Browser Forum has since voted to bring that ceiling down in stages toward 47 days. A job you did once a year turns into a job you do every few weeks, and every extra renewal is another chance to miss one.

The harder half is the certificates nobody issued on purpose. AD CS hands out certificates that never reach a spreadsheet. RDP generates its own. SQL Server, WinRM, HTTP.sys reservations, and a rack of appliances each hold something with an expiry date on it. The outage rarely comes from the certificate you renewed. It comes from the one you did not know was there.

The loop

Discover, monitor, alert, deploy.

Four jobs the product does today, and a fifth that retires the nag: renewal automation, over ACME under Pro and against AD CS under Enterprise.

01Discover

Find what you own

Four independent sources feed one review queue. If a source fails, the others still run.

  • Active Directory computer accounts
  • AD CS issued certificates
  • Certificate Transparency logs
  • Opt-in subnet sweep

02Monitor

See where it is used

Two collection paths, one inventory. Assets and certificates are separate records joined by bindings.

  • Direct TLS handshake with full chain
  • Batched WinRM collection per cycle
  • Stores, IIS, SQL Server, RDP, WinRM, HTTP.sys
  • Push collector for off-domain hosts

03Alert

Tell the right person

Rules scoped globally, to a tag, or to one asset, with day thresholds you set.

  • Email digests and a webhook
  • Escalation recipients on the last threshold
  • Chain problems flagged
  • Fires once, re-arms on renewal

04Deploy

Roll it to the fleet

One command on a domain controller stages the files and builds the GPO that does the rest.

  • GPO plus scheduled task, no reboots
  • MSI or script install for the console
  • Preview every change with WhatIf
  • Rollout status visible per host
Plain numbers

What the product does, counted.

6

binding types inventoried per Windows host

4

discovery sources feeding the review queue

1

GPO command to roll the collector role to an OU

14

day evaluation, unlimited targets, one click

50

endpoints on the free edition, with no time limit

0

network calls made to verify your license

Who it is for

Small teams who own the whole estate.

Built for the people who inherited a domain, keep servers running past their warranty, and cannot justify a certificate platform priced per seat.

  • County and city government
  • Courts
  • School districts
  • Hospitals and clinics
  • Credit unions
  • Municipal utilities
Read next

Before you install anything.

Product

How collection works

The discovery sources, both probe paths, the JEA role, and what the alert rules actually do.

Resources

System requirements

What the app server needs, which PowerShell versions the targets need, and the quickstart in five steps.

Pricing

Editions and licensing

Three editions with the prices on the page, offline license files, and what happens to monitoring when one expires.

Get started

Run it against your own estate for 14 days.

The evaluation is one click in the console, covers unlimited targets, and needs no key from us. Binaries are not on public download yet, so email us and we will send the build.