Skip to content

Support

Support

Short tutorials for TLSPilot: from the installer and setup wizard through certificates, ACME, deployments, daily operations, and backup.

Getting started

Setup

Learn how to install TLSPilot from the downloaded installer: accept the license, choose the installation folder, and complete setup. Data lands under ProgramData, event logs are created, and a dedicated certificate store folder is prepared for private keys.

Subtitles

Community Edition Walkthrough

Walk through TLS Pilot Community Edition after install: confirm the free license in the Initial Setup Wizard, configure Let's Encrypt (staging or production), set the renewal cycle, then issue your first ACME certificate with DNS-01, add an IIS deployment with WinRM credentials, and see automatic renewal via the management service.

Subtitles

Initial Setup Wizard

Walk through the Initial Setup Wizard after installation: migration restore option, Community versus paid license, certificate issuers (ACME, Enterprise CA, Private CA), Web UI and identity provider, renewal cycle, and Entra ID app registration helper.

Subtitles

Certificates

Private CA certificate

Issue your first certificate from the built-in Private CA. Enter Common Name and SANs, set validity and key algorithm, document purpose and owners, then issue immediately and review certificate details and PDF documentation.

Subtitles

Enterprise CA certificate

Request a certificate from an Active Directory Enterprise CA: pick the issuing CA and template, set the renewal window, issue immediately, and use type filters (EC, PC, AC) and search in the certificate list.

Subtitles

ACME certificate

Issue a public ACME certificate via Let's Encrypt: staging versus production, leaf key algorithm, DNS-01 validation with integrated DNS providers, store API credentials, and request the certificate with automatic TXT validation.

Subtitles

ACME & challenges

ACME Settings

Add and configure ACME providers under Settings: built-in directories, JSON import for ACME v2, directory URL checks, EAB credentials, default key algorithms, account reset, enable for New Certificate, and DNS-01 propagation wait.

Subtitles

Additional Challenge Types

Explore ACME challenge types beyond DNS-01: HTTP-01 via listener, local webroot, or remote WinRM/SSH deployment of the validation file, and TLS-ALPN-01 on port 443 with its practical limitations versus DNS-01 for wildcards.

Subtitles

Certificate Export Options

Export certificates from TLSPilot in the formats your targets need: PFX/PKCS#12 with chain and private key, encrypted PEM, separate CRT and key ZIP, PKCS#8 PEM, and PKCS#1 for older RSA-only applications.

Subtitles

Deployments

Local Store

Configure automatic deployment to a Windows certificate store (local or remote): browse AD computer accounts, add WinRM credentials including gMSA/dMSA, reload commands and service restarts, dry-run validation, helpers, and post-deploy health checks with drift redeploy.

Subtitles

IIS

Deploy a certificate to a remote IIS site: select the host and credentials, bind site name and HTTPS port (default 443), use dry run and helper guidance, deploy immediately, and verify the HTTPS binding on the target.

Subtitles

Nginx

Deploy certificates to Linux targets such as nginx over SSH: add Linux Secure Shell credentials (password or PEM key), set cert and key paths, optional owner/group and service restart, dry run, then deploy with health verification.

Subtitles

App Registration

Replace client secrets with certificate auth for Entra ID app registrations. Issue a Private CA auth certificate, deploy to an existing app with the least-privilege helper, also create a new app registration, and deploy the cert to scripting hosts that authenticate to the app.

Subtitles

Azure Key Vault

Push certificates into Azure Key Vault using a dedicated App Registration: create a Private CA service-account certificate, provision the app with the helper, grant Key Vault Certificates Officer via the vault helper, dry-run, deploy, and rely on renewal and health-driven redeploy.

Subtitles

Custom Deployment

Use Enterprise Edition custom deployments with PowerShell for targets that are not built in (example: Caddy). Add SSH credentials, write deployment and health-check scripts with $cert/$target/$cred variables, fix script errors from deploy output, redeploy, and verify the live certificate.

Subtitles

Operations

Web UI

Manage TLSPilot from a browser via the Web UI: enable under Settings, protocols, bind address, port and TLS certificate, Entra ID sign-in, almost full management parity, and the limits around starting helpers and restarting the service remotely.

Subtitles

RBAC

Configure Role-Based Access Control for the Web UI with AD or Entra ID: break-the-glass local admins, system roles (Reader, Owner, Manager, Deployment Admin, Deployer, Credential Admin), group and user grants, per-certificate overrides, and credential-scoped RBAC.

Subtitles

Tenants

Use Ultimate Edition tenants for MSPs and large teams: create tenants with allowed issuers and Enterprise CA templates, switch via the tenant picker, scope RBAC roles per tenant, and bind credentials so they are only usable inside that tenant.

Subtitles

External Credential Stores

Pull secrets from external stores such as HashiCorp Vault (also CyberArk, BeyondTrust, Azure Key Vault): configure the store under Security, resolve WinRM credentials from vault paths, and alternatively use Group or Delegated Managed Service Accounts for Windows targets.

Subtitles

Alerts & Logging

Stay informed with alert channels (email SMTP or Exchange Online OAuth, webhooks, Teams, Slack, Syslog), event triggers including service owners and tenant filters, plus audit/operational/debug logging to files and the Windows Event Viewer under iTrain TLSPilot.

Subtitles

Advanced

Certificate Options

Advanced certificate lifecycle actions: names and issuer are fixed after issue so create a replacement and Copy Deployments; delete or revoke with reason; Force Renew with ACME rate-limit awareness; and rollback to a previous non-revoked version with redeploy.

Subtitles

Backup & help

Backup & Restore

Back up TLSPilot configuration and certificates: scheduled backups and retention, same-host backups with DPAPI-protected keys, password-protected migration backups for moving to another server, and selective Restore Configuration for changed areas only.

Subtitles

Support Ticket

Open an in-product support ticket via chat with Thomas (AI first-level, typically within about thirty minutes): provide email, subject, and description in German or English, confirm the summary, reply by email, and escalate to human second-level when needed.

Subtitles