Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.certimate-ubuntu-24-04-aa8c8e19-5bec-4242-ac63-2f146470284d/image0_logolarge.png

Certimate on Ubuntu 24.04 LTS

by cloudimg

Certimate, self hosted SSL and TLS certificate automation, on Ubuntu 24.04 LTS by cloudimg

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

Certimate - SSL and TLS Certificate Automation by cloudimg

Deploy a private, self-hosted certificate manager on your own Azure infrastructure in minutes - no manual installation, no shared credentials. This image delivers Certimate 0.4.27 fully installed and hardened, managed entirely from a web console, so you sign in with the unique administrator password generated for your instance and start automating certificate issuance, deployment and renewal immediately after the VM boots.

Why This Image Instead of Manual Installation

Installing Certimate by hand means placing the server binary, writing a systemd unit, fronting the console with a web server, laying out the embedded database, and opening the right ports. This image eliminates that operational burden:

  • Certimate 0.4.27 installed as a single self-contained Go binary and managed by systemd
  • The web console served behind nginx on port 80, the server bound to loopback
  • Secure by default: a unique administrator password is generated per instance on first boot
  • No shared or default login ships in the image; the upstream default credential never works
  • Embedded SQLite storage, no external database to run
  • Immediate time-to-value: build an automated certificate workflow within minutes of boot
  • Ongoing expert support: 24/7 cloudimg engineers handle upgrades and configuration

Use Case: Automated Certificate Lifecycle

A team manages TLS certificates for many domains and internal services and wants issuance, deployment and renewal handled automatically instead of by hand. With this image they launch a VM, sign in with the per instance administrator password, add their ACME certificate authority and provider credentials, and build a visual workflow that issues a certificate, deploys it to their web servers, CDNs or load balancers, and renews it on a schedule - all within their own VNet.

Application Stack

Certimate is a single self-contained Go binary built on PocketBase, with the web console and embedded SQLite database included. The server binds to loopback on port 8090 and is published by nginx on port 80. It issues certificates from ACME certificate authorities including Let's Encrypt, ZeroSSL, Google Trust Services, SSL.com and Actalis, supports both DNS-01 and HTTP-01 challenges, and deploys issued certificates to a wide range of targets such as Kubernetes, CDNs, WAFs, load balancers and object storage. A visual workflow editor chains issuance, deployment, renewal and notification, with certificate expiry monitoring and multi channel notifications built in. All state lives in the embedded database on the VM.

Secure By Default

The image ships with no usable default credential. A unique administrator password is generated for each instance on first boot, written to a protected root owned file on the VM, and set before the console is reachable, so the upstream default login never works. Certimate runs as a dedicated non-root service bound to loopback and is reached only through nginx. Restrict the console port 80 to trusted networks in production, since it is the administrative interface.

Getting Started

1. Launch the image on your chosen Azure VM size 2. Read the per instance administrator password from /root/certimate-credentials.txt over SSH 3. Browse to the VM public IP on port 80 and sign in with admin@certimate.fun and that password 4. Add your ACME certificate authority and provider credentials, then build an issuance and deployment workflow

Licensing and Pricing

Certimate is licensed under the MIT License and is free; there is no per-seat fee. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance, and 24/7 expert support. The web console on port 80 is the administrative interface; restrict it to trusted networks before production.

cloudimg Support

24/7 technical support by email covers deployment, upgrades, ACME and certificate authority setup, workflow configuration, and deployment targets. Critical issues receive a one-hour average response time.

Certimate is a trademark of its respective owner. All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.certimate-ubuntu-24-04-aa8c8e19-5bec-4242-ac63-2f146470284d/image3_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.certimate-ubuntu-24-04-aa8c8e19-5bec-4242-ac63-2f146470284d/image7_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.certimate-ubuntu-24-04-aa8c8e19-5bec-4242-ac63-2f146470284d/image1_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.certimate-ubuntu-24-04-aa8c8e19-5bec-4242-ac63-2f146470284d/image2_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies