Administration
Administration is performed from the SSLNexus web interface after initial administrator setup. Use named administrator accounts for normal access rather than the installation token.
Administrator Access
The first administrator is created from the short-lived setup URL. After setup, sign in with that named account. Keep administrator access limited to staff responsible for certificate operations, integrations and product configuration.
Organisation Settings
Set the organisation identity and managed parent domains that SSLNexus is expected to manage. Each parent domain receives a DNS TXT ownership challenge. Passive parent-domain discovery remains disabled until that challenge is verified, then administrators can explicitly enumerate names and observe the certificates currently presented over HTTPS before deciding which deployments to adopt.
Team Access And Roles
Use named accounts and assign the least privilege needed for each team member.
Full product administration, including organisation settings, licensing, identity providers, CA configuration, plugins and team access.
Certificate and deployment operations, including issuing and renewing certificates, managing deployment targets and approving renewal work where policy requires approval. Operators cannot change licensing, identity, organisation, plugin or team-access configuration.
Read/write access to network-appliance targets and their certificates only. Network Operators can enter and rotate encrypted appliance API credentials, run Test connection and Test CA independently, and operate network-bound certificate jobs without access to Linux/Windows targets or broader platform administration. This is designed for network teams that share the same SSL Nexus gateway with infrastructure/security teams and should not require duplicate installations. LDAP/OIDC groups can be mapped directly to this role. See Network Operator role.
Operational visibility without permission to create, renew, approve or change configuration.
Vendor identities remain separate and use the Vendor Portal rather than the internal administration interface. Identity providers can use Microsoft Entra ID, Okta, Google Workspace or Generic OIDC, with LDAP / Active Directory retained for directory-backed staff authentication. Staff and vendor SSO can be enabled independently on the same connection.
Connections
CA credentials, Windows credentials and other integration secrets are entered through the relevant configuration screen. Test each connection before relying on it for renewal or deployment. Certificate destinations are configured separately from CA adapters and deployment targets so managed certificates can also publish to HashiCorp Vault KV v2, AWS Secrets Manager or Azure Key Vault.
Administrative Recovery
Supported recovery actions are available from the server console through ssl-nexus-admin recover. Use them instead of editing state files directly.
recover doctor validates configuration, application state, Administrator availability, protected secret files, the target encryption key, registered target credential decryption and local service health. recover admin resets an existing local Administrator and revokes its existing sessions. recover licence performs an immediate licensing-authority check.
/etc/ssl-nexus/secrets/targets.key when encrypted deployment targets exist. Restore that key from a backup; replacing it would make the stored credentials unreadable.Notifications
Administrators can configure Smart Mail alerts through Google Workspace, Microsoft 365 or SMTP from Notifications. Alerts cover certificate expiry, certificate-operation failures, target-health failures, vendor certificate failures and licence health. Delivery is de-duplicated so the same event does not generate repeated email every scheduler cycle. See Email notifications.
Updates
Apply SSLNexus updates using the package format used for the original installation. Before replacement, SSLNexus creates a pre-upgrade recovery snapshot and validates the new service after installation. If the new service fails its health or version check, the previous state and runtime are restored automatically when a valid snapshot is available. Existing administrators, vendors, targets, licence identity and certificate state are retained.

