Operations

Bulk Operations And CA Migration

Preview · Policy Check · Execute

Use one controlled workflow to act on a certificate collection selected by explicit IDs, groups, tags or structured metadata.

Preview Before Execution

Every bulk action begins with Preview. SSLNexus resolves the selector, evaluates policy and lifecycle eligibility for every matching certificate, and shows each item as Ready or Blocked with the reason. Execution uses the same evaluation path.

Supported Operations

  • Renew - queue normal renewal jobs for eligible managed certificates.
  • Migrate / reissue - request replacement certificates from another configured CA without changing the recorded CA until the new issue/deploy/verify workflow succeeds.
  • Revoke - revoke supported certificates using a selected revocation reason.
  • Replace classification - apply groups, tags and metadata to the selected certificates subject to policy checks.

Safe CA Migration

A migration keeps the certificate identity, target, deployment owner, renewal policy and classification. The destination CA is used only for the migration job. If issuance or deployment fails, the original CA remains recorded. The provider changes only after the normal deployment and live-certificate verification path succeeds.

Selection And Policy

Selectors use the same organisation model as the policy engine. Group, tag and metadata conditions are combined, and explicit certificate IDs can narrow the operation further. Matching policies are evaluated before execution, so a bulk operation cannot bypass standards that would block the equivalent single-certificate change.

Audit And Results

The Bulk operations page returns per-certificate results. Renewals and migrations create normal jobs and remain visible in Jobs and Activity & audit. Revocation and classification actions are also audited.

Policy Engine

Turn Certificate Classification Into Enforceable Controls

Policies target certificates by group, tag and structured metadata. Matching selectors are combined as AND conditions, and an empty selector can apply a baseline across the whole estate.

01

Approved Certificate Authorities

Restrict a collection to the CA adapters approved for that environment or business unit.

02

Deployment Responsibility

Require approved deployment owners and, where appropriate, a registered managed deployment target.

03

Renewal Controls

Require automatic renewal and a minimum renewal lead time for certificates that must not depend on manual action.

04

Prevent Drift And Expose Existing Gaps

Changes that would violate an enabled policy are rejected. Existing certificates that do not comply remain visible with the exact policy violation so teams can remediate them safely.