Skip to content

Product

TLSPilot: Certificate Lifecycle Management

TLSPilot is professional certificate management software for reliable, automated certificate lifecycle management. Set up an issuer, define deployment targets and select a renewal schedule. TLSPilot handles certificate issuance, distribution and monitoring while providing timely notifications if an operation requires attention.

Automated certificate management

Short certificate lifetimes and expanding IT environments demand consistent processes. TLSPilot provides automated certificate deployment and certificate renewal automation for public and internal certificates. This makes it easier to renew TLS certificates, reduce manual effort and prevent service interruptions caused by expired certificates.

Why that matters: .

Flexible certificate issuers

Whether the certificates should be internal or public, and whether they come through ACME or from an internal Enterprise CA: TLSPilot is flexible enough to work with a wide range of issuers.

ACME

TLSPilot obtains certificates automatically through ACMEv2. Providers such as Let’s Encrypt and ZeroSSL are supported. Additional providers can be integrated through JSON definitions, making TLSPilot effective for ACME certificate management.

Enterprise CA

Existing AD CS environments can be connected to TLSPilot. Rights can be assigned to specific certificate templates so that internal certificates are issued and distributed according to established enterprise policies. This creates controlled enterprise certificate management across the organization.

Private CA

Where no public certificate or Enterprise CA is required, TLSPilot can issue certificates through its private CA capabilities and distribute them to the designated systems. CRL and OCSP are supported for dependable trust management.

Deployment across your IT environment

TLSPilot does more than obtain and store certificates. It distributes them agentlessly to systems with a suitable API or interface, manages the credentials involved, and runs health checks after deployment. Deployment Helpers help configure the required permissions on the target so rollouts stay consistent and dependable.

Deployment targets

TLSPilot does not only obtain certificates and store them. They can also be distributed to any deployment targets, as long as those targets expose some kind of interface. This works without installing agents, using the built-in means of the API or interface.

Deployment Helpers

It can sometimes be difficult to equip the deployment target with the required permissions. The deployment helpers in TLSPilot help set the correct permissions everywhere so the deployment itself then simply works.

Credentials and certificate store

Secrets for authorizing against an issuer or a deployment target are stored securely in the Windows Credential Store. You can also use gMSA/dMSA or external credential stores - including ones that handle automatic password rotation (such as CyberArk or BeyondTrust).

Health checks and several targets

The health of deployment targets stays under TLSPilot control even after a successful deployment. TLSPilot regularly checks whether the deployment still sits correctly and reports actively when something no longer fits. Re-deployments also run regularly when an irregularity is detected.

Renewal in the lifecycle

When a certificate needs renewing—on schedule or forced—TLSPilot obtains the new one in time and immediately redistributes it to every configured target, so the lifecycle doesn’t stall after issuance.

Renew in time

TLSPilot keeps track of certificate remaining lifetimes and also knows their renewal window. As soon as that window begins, the certificate is renewed automatically and then updated on all deployment targets. Of course a roll-back is possible at any time.

Distribute again at once

After a certificate renewal it is distributed immediately to all deployment targets and rebound. TLSPilot then also checks whether the new certificate sits correctly. A renewal can also be forced outside the renewal window if you want.

Managing these parts

Operate the full certificate lifecycle from the desktop Management Tool or the matching Web UI, control who can do what with RBAC (Entra ID / AD), and automate again via the Management API or the PowerShell module.

Management Tool

All administration can be done through the Management Tool on the installation server. Despite the complex topic it is very simple and user-friendly - almost self-explanatory.

WebUI

Besides the Management Tool there is also a web interface. It looks exactly the same and lets you manage the full certificate lifecycle entirely in the browser. Through RBAC and an integration with Entra ID or Active Directory you decide who gets access to what.

RBAC

With TLSPilot's sophisticated RBAC (Role Based Access Control), Entra ID / Active Directory users or groups can be authorized for specific actions - for all certificates, deployments and credentials, or for individual elements of them, or for tenants (groupings of certificates by customer/team).

Management API & PowerShell

TLSPilot also offers access to every function via API or its own PowerShell module. That way even the automation of the certificate lifecycle can be automated again.

Further functions

Beyond the core loop, TLSPilot groups certificates by tenant, keeps auto backups, alerts you when something needs attention, and records actions in logging and auditing.

Tenants

Tenants are simply groupings of certificates and credentials so they can be divided by customer or by team/responsibility. RBAC authorization within individual tenants is also possible.

Auto Backup

The entire TLSPilot configuration can be backed up and restored at any time - including granularly. That applies not only to certificates but also to their deployment targets, individual configuration options, and more. With the migration backup, TLSPilot can also be moved from server to server without fuss.

Alerts

Whether something went well or not, TLSPilot alerts keep you up to date. They can trigger mail, Teams/Slack messages, Syslog or even webhooks - whatever you want. Want the coffee machine to brew a coffee first when a deployment is not healthy? All doable.

Logging & Auditing

Every action carried out automatically or manually in TLSPilot is also recorded in logs. Those logs are in the Windows Event Logs and/or as files. You decide how deep logging goes. If you want, every action is logged - even simply opening a dialog. So you always know who did what, and when.

Installation scenarios

TLSPilot stays useful without on-prem — cloud-only works. What matters is credentials plus reachability of deployment targets, issuers, and alert channels — not where the management host sits.

System requirements

Minimum requirements

Host
Windows Server x64 (management host; Windows Client also possible)
Runtime
.NET 8 ships self-contained in Setup — no separate runtime install
Minimum
2 vCPU, 4 GB RAM
Storage
SSD recommended; about 5 GB free for TLSPilot plus several GB free for data, logs, and backups.
Recommended
At least 4 vCPU and 8 GB RAM

Learn more: pick an edition

TLSPilot comes in 6 editions in total - depending on how large your certificate or deployment need is and which features you require. Get to know our editions next.

To the editions

Why that matters

Two forces push at the same time.

Shorter certificate lifetimes

Since 15 March 2026, public TLS certificates may be valid for at most 200 days. On 15 March 2027 that drops to 100 days — and on 15 March 2029 the target maximum of 47 days takes effect. That is barely manageable by hand.

More and more systems need a certificate

In the past, mainly online shops and similar sites needed a certificate for HTTPS. Authentication and encryption are now increasingly important for applications, services, VPN connections, and more — and so are the certificates behind them.

Tenants

Tenants let you group certificates and credentials. That keeps things tidy when you split by team or customer — and lets you limit issuers to certain tenants or apply permissions/roles only to specific tenants:

Enterprise CA

If an Enterprise CA (AD Certificate Services) is already available in the domain, TLSPilot detects it automatically. All templates the management service can access that allow server authentication certificates can then be used directly in TLSPilot — issued and deployed to your targets:

Private CA

TLSPilot Private CA is ideal for certificates that do not need redundancy for CRL checking — for example Entra app registration authentication. TLSPilot Private CA offers various key algorithms (including ECC) and also allows CRL checking via OCSP:

ACME

Anything that follows the ACMEv2 standard can be entered in TLSPilot as a public cert source. From free public cert providers such as Let's Encrypt, ZeroSSL, etc., through to commercial CAs that support ACMEv2. Integration in TLSPilot is modular via JSON definition files that you can also write yourself. Many providers are already included — and only need configuration.

Domain validation uses DNS-01, HTTP-01, or TLS-ALPN-01. Many DNS providers are already included — plus manual DNS configuration and any that work per RFC2136. HTTP-01 can even be terminated on the management host itself with its own listener:

Deployment targets

The catalog of direct deployment targets is huge, and many deployments can also be driven with a file path for certificate and key plus a configurable service restart / PowerShell code block (if the edition includes "Custom Deployments").

Many applications run under Nginx, Apache, IIS, etc. and can already be fully covered by those individual deployment targets. Custom Deployments also allow PowerShell for your own deployments. As long as the target system exposes an interface/API, a deployment with TLSPilot is possible.

Supported deployment targets

Windows
  • Certificate store
  • IIS
  • File Path (WinRM)
  • UNC
  • RDS
  • Exchange
  • AD FS
  • SQL Server
  • NPS (RADIUS)
Linux
  • Nginx
  • Apache
  • HAProxy
  • Tomcat
  • PostgreSQL
  • MySQL/MariaDB
  • File Path (SSH)
Application Delivery (ADC)
  • NetScaler
  • F5 BIG-IP
Omnissa
  • UAG (Omnissa)
Firewall / VPN
  • Palo Alto
Google Cloud
  • Certificate Manager
Amazon Web Services
  • Certificate Manager
Azure
  • Azure Key Vault
  • Azure App Service
  • Azure Front Door
  • Azure Application Gateway
  • Azure API Management
Entra
  • Entra Application Proxy App
  • Entra App Certificate
Custom
  • Custom script

Deployment Helpers

Example of a deployment helper that configures RBAC with Entra ID as the identity provider or an Azure Application Gateway to obtain the permissions needed for future deployments. Everything follows best practice and the least-privilege principle:

WebUI

So TLSPilot can be managed from wherever you need it, there is also a WebUI reachable in the browser — with authentication via an identity provider (AD or Entra ID). It does not only look like the Management Tool: it behaves the same way:

RBAC

Role-based access control lets you define precisely and granularly which person or group (including nested groups) gets which access rights. On each certificate or credential, inheritance can also be broken and replaced with explicit permissions:

Auto Backup

TLSPilot includes its own backup format, which can also be created automatically every 24 hours. Restoring individual components that have changed is then straightforward. With a migration backup you can also move the install quickly to another server:

Distribute again at once

Whether a normal renew in the renewal window, a forced renew, or a revoke with a replacement certificate: deployments are started again right after, and the deployment target’s health is checked — manually or in the background on the regular 24-hour cycle. Versioning stays clear, with roll-back, and every action is listed in history as well as in the log:

Management Tool

Simple, clear, and uncluttered — that was our credo building TLSPilot. Everyone should find their way around as quickly as possible, and find things where they expect them:

Renew in time

TLSPilot knows exactly when the renewal window for each individual certificate begins and when it should attempt to renew it — including different sources with different lifetimes, and even when those lifetimes keep getting shorter:

Health checks and several targets

Each deployment target is checked regularly — configurable — for correctness. If something no longer matches, this can also trigger an alert on request. Multiple deployment targets per certificate are possible, each of which can be enabled or paused individually:

Credentials and certificate store

Secrets are stored securely in the Windows Credential Store (Local Machine) or can come from other sources — from Azure Key Vault through Delinea, CyberArk, BeyondTrust and other supported password safes. gMSA/dMSA with rotating passwords or certificates as secrets are also supported:

See certificate inventory health, license edition, and issuer tiles at a glance on the management host
Pick an issuer: ACME family, Enterprise CA, Private CA
Continue the catalogue - Entra (application proxy / app registration), Google Cloud Certificate Manager, and AWS Certificate Manager are first-class deploy targets
Open Channel configuration from Settings → Alerts - named instances for Mail, Webhook, Microsoft Teams, Slack, and Syslog (CEF)
WebUI sign-in with Microsoft Entra ID
RBAC manager: Reader, Manager, Owner, Deployer roles
Add Deployment: Linked service dropdown (Windows/Linux and more; Certificate store only selected)
Add Deployment: File path on Windows host with PFX/PEM, reload PowerShell and Windows service restart
Entra ID RBAC Helper: sign-in and steps after Start
Add Deployment Helper: Azure Application Gateway, Required Permissions and What the helper writes (least privilege)
Credentials Manager: types, display names, sources (TLSPilot Store, CyberArk CCP, gMSA/dMSA)
Modify Deployment: Health Healthy / Check Now
Certificate Deployments: multiple targets with health and enable toggles
Modify Certificate Settings: renewal window slider and Private CA leaf
Private CA: Running, renew/export, CDP/OCSP
ACME: public CA providers
ACME: DigiCert / commercial CA
New Certificate wizard Settings: Enterprise CA enrollment, template, renewal window
TLSPilot Management Console: dashboard, certificate list, Enterprise, Health OK
TLSPilot WebUI in the browser: dashboard like the Management Tool
RBAC: roles and permissions in the manager
RBAC: break inheritance and set explicit permissions
TLSPilot PowerShell module: cmdlets for certificates and deployments
Settings tenants: tenant list and configuration
Tenant dropdown on certificates and credentials
RBAC: scope permissions to tenants
Settings Alerts: channels mail, Teams, Slack, webhook, syslog
Alert profile: configure events and channels
Settings Logging: Event Logs and log files
Settings Backup: automatic backup and migration
Restore: restore individual components from backup
ACME HTTP-01: listener on the management host (port 80)
ACME DNS-01: DNS provider list (ClouDNS and others)

Alerts

With alerts, specific events can trigger messages on different channels. Both the alert channel and the events can be configured in detail:

Logging & Auditing

Whether Windows Event Logs, classic log files, or both — besides alerts, every operational action, audits of manual steps, and debug information can be recorded clearly and looked up at any time:

Management API & PowerShell

Want even more automation? No problem: besides the Management Tool and WebUI, TLSPilot also offers a full API and a PowerShell module so you can call every function directly:

On-premises Windows host

Management on a Windows Server in your network. Host location does not limit targets: deploy to on-prem and cloud services whenever credentials and reachability allow.

LAN TLSPilot host On-prem Windows On-prem target Cloud targets Issuers Credentials Alerts

Azure VM / cloud-only

Run the management host in Azure (or similar) — no on-prem host required. Cloud targets sit with the host in the cloud; on-prem targets remain possible when reachable (hybrid). Credentials and reachability decide.

Cloud TLSPilot host Azure VM · no on-prem host Cloud target LAN / hybrid On-prem targets Issuers Credentials Alerts

Web UI from anywhere

Enterprise+ with WebUI & RBAC — operate from a browser wherever the Web UI is reachable. With Entra ID RBAC, access can be hardened with Conditional Access (CAP). No RDP required. Desktop console and Management service remain on the host. Deployments still reach on-prem and cloud targets when credentials and reachability allow.

Issuers Credentials Alerts Browser Entra ID / CAP Web UI TLSPilot host Desktop console Management service On-prem targets if reachable Cloud targets if reachable