NetBox SSL – SSL/TLS certificate management plugin for NetBox
Fills NetBox's missing cert tracking gap; auto-discovery roadmapped.

Handles Windows and JKS where Certbot fails, but it's a paid SaaS in a crowded category.
DevOps engineers managing mixed infrastructure with Windows servers and appliances
Certbot · Smallstep · Venafi
Certbot is the obvious answer but it doesn’t cover everything. It requires ACME on each server, which means each server needs to be internet-reachable or have DNS provider access. That rules out Windows servers, JKS keystores, and appliances that can’t run Certbot or speak ACME at all.
CertKit handles ACME centrally. A source-available Go agent runs on each server and handles deployment, including Windows, JKS, and appliances via custom file destinations and post-deploy commands. Validation uses a delegated CNAME so we never need your DNS provider credentials.
We just wrapped up our beta and launched today. Happy to answer any questions.
Fills NetBox's missing cert tracking gap; auto-discovery roadmapped.
Pure Go crypto means no OpenSSL dependency, but mkcert already owns this workflow.
Finally lets AI agents automate Windows-only legacy apps from Linux pipelines.
GUI for OpenSSL certs when Keychain Access and certmgr already exist.
Wraps O&O ShutUp with auto-reapply after updates, but adds minimal value.
Yet another AI agent orchestrator competing with Cursor, Continue, and dozens of others.