Product
TLSPilot: Certificate Lifecycle Management
TLSPilot is professional certificate management software for reliable, automated certificate lifecycle management. Set up an issuer, define deployment targets and select a renewal schedule. TLSPilot handles certificate issuance, distribution and monitoring while providing timely notifications if an operation requires attention.
Automated certificate management
Short certificate lifetimes and expanding IT environments demand consistent processes. TLSPilot provides automated certificate deployment and certificate renewal automation for public and internal certificates. This makes it easier to renew TLS certificates, reduce manual effort and prevent service interruptions caused by expired certificates.
Why that matters: .
Flexible certificate issuers
Whether the certificates should be internal or public, and whether they come through ACME or from an internal Enterprise CA: TLSPilot is flexible enough to work with a wide range of issuers.
ACME
TLSPilot obtains certificates automatically through ACMEv2. Providers such as Let’s Encrypt and ZeroSSL are supported. Additional providers can be integrated through JSON definitions, making TLSPilot effective for ACME certificate management.
Enterprise CA
Existing AD CS environments can be connected to TLSPilot. Rights can be assigned to specific certificate templates so that internal certificates are issued and distributed according to established enterprise policies. This creates controlled enterprise certificate management across the organization.
Private CA
Where no public certificate or Enterprise CA is required, TLSPilot can issue certificates through its private CA capabilities and distribute them to the designated systems. CRL and OCSP are supported for dependable trust management.
Deployment across your IT environment
TLSPilot does more than obtain and store certificates. It distributes them agentlessly to systems with a suitable API or interface, manages the credentials involved, and runs health checks after deployment. Deployment Helpers help configure the required permissions on the target so rollouts stay consistent and dependable.
Deployment targets
TLSPilot does not only obtain certificates and store them. They can also be distributed to any deployment targets, as long as those targets expose some kind of interface. This works without installing agents, using the built-in means of the API or interface.
Deployment Helpers
It can sometimes be difficult to equip the deployment target with the required permissions. The deployment helpers in TLSPilot help set the correct permissions everywhere so the deployment itself then simply works.
Credentials and certificate store
Secrets for authorizing against an issuer or a deployment target are stored securely in the Windows Credential Store. You can also use gMSA/dMSA or external credential stores - including ones that handle automatic password rotation (such as CyberArk or BeyondTrust).
Health checks and several targets
The health of deployment targets stays under TLSPilot control even after a successful deployment. TLSPilot regularly checks whether the deployment still sits correctly and reports actively when something no longer fits. Re-deployments also run regularly when an irregularity is detected.
Renewal in the lifecycle
When a certificate needs renewing—on schedule or forced—TLSPilot obtains the new one in time and immediately redistributes it to every configured target, so the lifecycle doesn’t stall after issuance.
Renew in time
TLSPilot keeps track of certificate remaining lifetimes and also knows their renewal window. As soon as that window begins, the certificate is renewed automatically and then updated on all deployment targets. Of course a roll-back is possible at any time.
Distribute again at once
After a certificate renewal it is distributed immediately to all deployment targets and rebound. TLSPilot then also checks whether the new certificate sits correctly. A renewal can also be forced outside the renewal window if you want.
Managing these parts
Operate the full certificate lifecycle from the desktop Management Tool or the matching Web UI, control who can do what with RBAC (Entra ID / AD), and automate again via the Management API or the PowerShell module.
Management Tool
All administration can be done through the Management Tool on the installation server. Despite the complex topic it is very simple and user-friendly - almost self-explanatory.
WebUI
Besides the Management Tool there is also a web interface. It looks exactly the same and lets you manage the full certificate lifecycle entirely in the browser. Through RBAC and an integration with Entra ID or Active Directory you decide who gets access to what.
RBAC
With TLSPilot's sophisticated RBAC (Role Based Access Control), Entra ID / Active Directory users or groups can be authorized for specific actions - for all certificates, deployments and credentials, or for individual elements of them, or for tenants (groupings of certificates by customer/team).
Management API & PowerShell
TLSPilot also offers access to every function via API or its own PowerShell module. That way even the automation of the certificate lifecycle can be automated again.
Further functions
Beyond the core loop, TLSPilot groups certificates by tenant, keeps auto backups, alerts you when something needs attention, and records actions in logging and auditing.
Tenants
Tenants are simply groupings of certificates and credentials so they can be divided by customer or by team/responsibility. RBAC authorization within individual tenants is also possible.
Auto Backup
The entire TLSPilot configuration can be backed up and restored at any time - including granularly. That applies not only to certificates but also to their deployment targets, individual configuration options, and more. With the migration backup, TLSPilot can also be moved from server to server without fuss.
Alerts
Whether something went well or not, TLSPilot alerts keep you up to date. They can trigger mail, Teams/Slack messages, Syslog or even webhooks - whatever you want. Want the coffee machine to brew a coffee first when a deployment is not healthy? All doable.
Logging & Auditing
Every action carried out automatically or manually in TLSPilot is also recorded in logs. Those logs are in the Windows Event Logs and/or as files. You decide how deep logging goes. If you want, every action is logged - even simply opening a dialog. So you always know who did what, and when.
Installation scenarios
TLSPilot stays useful without on-prem — cloud-only works. What matters is credentials plus reachability of deployment targets, issuers, and alert channels — not where the management host sits.
System requirements
Minimum requirements
- Host
- Windows Server x64 (management host; Windows Client also possible)
- Runtime
- .NET 8 ships self-contained in Setup — no separate runtime install
- Minimum
- 2 vCPU, 4 GB RAM
- Storage
- SSD recommended; about 5 GB free for TLSPilot plus several GB free for data, logs, and backups.
- Recommended
- At least 4 vCPU and 8 GB RAM
Learn more: pick an edition
TLSPilot comes in 6 editions in total - depending on how large your certificate or deployment need is and which features you require. Get to know our editions next.