ACME Certificate Auto-Renewal for PRTG Web Server
As an IT Infrastructure Manager, I want PRTG to automatically renew its web server SSL certificates using ACME protocols so that I can ensure continuous secure access to the monitoring system without manual intervention or risk of service disruption from expired certificates.
With the upcoming SSL certificate lifecycle changes requiring certificates with 47-day lifespans by March 2029, manual certificate renewal for the PRTG webserver will become impractical and operationally burdensome. The user needs an automated solution using ACME (Automatic Certificate Management Environment) to handle certificate renewals without manual intervention, ensuring continuous secure access to the PRTG web interface.
-
Denis Bisaro
commented
Critical here too, we have several PRTG servers, and doing this manually each 47 days will hardly be doable or very prone to errors
-
Larissa Hakes
commented
Also adding that this is critical for us. Even if we are able to change the certificate outside of the certificate importer would be an improvement so we could script the certificate change. Manual renewals are going to be difficult with the drop to 99 days in March 2027 and impossible to keep up with when they drop to 47 days in 2029. We need ACME integration or the ability to change the certificate like a normal Apache webserver.
-
Emmery Cheung
commented
Please set this as a priority
-
Rob Wheeler
commented
yes, this is important to me as well. Please update your software to allow the ACME (automatic certificate management environment) to handle this in future as it will not be possible to do this manually with such frequent renewals.
-
AH
commented
hi, is there any update on this?
-
Les Dotson
commented
This is CRITICAL
Just renewed the cert for the PRTG server and will have to do so again in October. -
LD
commented
Certificate Automation will be absolutely critical for us. As of March 15th, the cert lifetime has already dropped to 200 days and from next year on it will be 100 days. No way are we going to manually manage certificates then.
-
Johua Ganger
commented
This is important for us as well. We don't use Let's Encrypt but do use ACME with a different CA for the majority of our environment. It might be possible to rig something up with certbot, the prtg cert import tool, and scheduled tasks, but it'd be preferable for it to be a native capability.
-
Thomas Puschacher commented
When will this automatic cert renewal be in place? Certificate validation time will be reduced to 47 days in the next years step by step starting in march 2026.
https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days
So an automatic renewal process is crucial in the future -
AH
commented
Been awhile since last response, @Jonah Kowall is there any progress?
-
AH
commented
can we please have an update
-
AH
commented
This should be done as soon as possible so we can prepare and configure this beforehand.
(Edited by admin) -
AH
commented
Yeah it's going to be necessary, otherwise renewing the certificate will be very impractical going forward as SSL expiry times will continue to shrink
-
Michael Finney 1
commented
In a year or two we probably won't be able to get 1 year certificates. Certificate renewals need to be automatically done going forward. Please add Let's Encrypt or other CA support.
-
Temple Murphy commented
The ability to use Let's Encrypt would make things a lot easier with the coming cert changes - +1 for this one.
-
AH
commented
Hi Jonah, I am referring to the certificate for the PRTG web server.
Currently https://www.paessler.com/tools/certificateimporter is used to renew the certificate for the webserver. But as I say manual renewal will be difficult in future.