Dependency & Impact
Dependency & Impact turns known SSLNexus inventory relationships into a focused graph so operators can understand certificate, CA and trust-anchor dependencies before making changes.
What The Graph Answers
The graph is intentionally focused on one selected certificate, CA or trust anchor and its nearby relationships instead of attempting to draw the entire estate at once.
- For a certificate: What depends on this certificate? and What known services could be affected if it is revoked or removed?
- For a CA: Where is this CA currently in use? and which targets are configured to use it for future issuance/renewal?
- For a trust anchor: Which bundles, targets and hosts trust this root/intermediate?
How To Use It
- Open Dependency & Impact in the Client Server, or use the global search with terms such as impact, blast radius, CA usage or what breaks.
- Choose a certificate, certificate authority or trust anchor.
- Review the focused graph and the impact summary beside it.
- Follow mapped targets, hosts, applications, CMDB/service identifiers, certificate destinations and trust-bundle relationships before approving the change.
Relationships SSLNexus Can Show
| Relationship | Meaning |
|---|---|
| CA → Certificate | The certificate is currently associated with/issued through that CA. |
| CA → Deployment target | The target is configured to use that CA for a future issuance or renewal. |
| Certificate → Target / Host / Application | The managed certificate is deployed or mapped to that infrastructure/service. |
| Certificate → Destination | The certificate is published to a configured destination such as a supported secret store. |
| CMDB / Service → Certificate | Existing business/service metadata links the certificate to that service context. |
| Trust anchor → Bundle → Target → Host | The public root/intermediate is required by an assigned trust policy. |
CA Changes And Renewal
The graph therefore distinguishes current certificate association from the CA configured on a target for its next renewal. Use that distinction when planning gradual CA migrations.
Trust-Anchor Impact
After configuring Trust Store Management, select a root or intermediate in Dependency & Impact to see the bundles and known managed systems that depend on it before excluding or removing the anchor.
Scope And Access
Impact results follow existing organisation and role boundaries. Network Operators only receive relationships for the network targets that their role is allowed to access.

