Bulk Operations And CA Migration
Use one controlled workflow to act on a certificate collection selected by explicit IDs, groups, tags or structured metadata.
Preview Before Execution
Every bulk action begins with Preview. SSLNexus resolves the selector, evaluates policy and lifecycle eligibility for every matching certificate, and shows each item as Ready or Blocked with the reason. Execution uses the same evaluation path.
Supported Operations
- Renew - queue normal renewal jobs for eligible managed certificates.
- Migrate / reissue - request replacement certificates from another configured CA without changing the recorded CA until the new issue/deploy/verify workflow succeeds.
- Revoke - revoke supported certificates using a selected revocation reason.
- Replace classification - apply groups, tags and metadata to the selected certificates subject to policy checks.
Safe CA Migration
A migration keeps the certificate identity, target, deployment owner, renewal policy and classification. The destination CA is used only for the migration job. If issuance or deployment fails, the original CA remains recorded. The provider changes only after the normal deployment and live-certificate verification path succeeds.
Selection And Policy
Selectors use the same organisation model as the policy engine. Group, tag and metadata conditions are combined, and explicit certificate IDs can narrow the operation further. Matching policies are evaluated before execution, so a bulk operation cannot bypass standards that would block the equivalent single-certificate change.
Audit And Results
The Bulk operations page returns per-certificate results. Renewals and migrations create normal jobs and remain visible in Jobs and Activity & audit. Revocation and classification actions are also audited.

