Operations

Dependency & Impact

Certificates · CAs · Trust · Blast Radius

Dependency & Impact turns known SSLNexus inventory relationships into a focused graph so operators can understand certificate, CA and trust-anchor dependencies before making changes.

What The Graph Answers

The graph is intentionally focused on one selected certificate, CA or trust anchor and its nearby relationships instead of attempting to draw the entire estate at once.

How To Use It

  1. Open Dependency & Impact in the Client Server, or use the global search with terms such as impact, blast radius, CA usage or what breaks.
  2. Choose a certificate, certificate authority or trust anchor.
  3. Review the focused graph and the impact summary beside it.
  4. Follow mapped targets, hosts, applications, CMDB/service identifiers, certificate destinations and trust-bundle relationships before approving the change.
Known dependencies: The graph only claims relationships that SSLNexus knows from managed inventory, discovery and configured mappings. Undiscovered infrastructure can still exist.

Relationships SSLNexus Can Show

RelationshipMeaning
CA → CertificateThe certificate is currently associated with/issued through that CA.
CA → Deployment targetThe target is configured to use that CA for a future issuance or renewal.
Certificate → Target / Host / ApplicationThe managed certificate is deployed or mapped to that infrastructure/service.
Certificate → DestinationThe certificate is published to a configured destination such as a supported secret store.
CMDB / Service → CertificateExisting business/service metadata links the certificate to that service context.
Trust anchor → Bundle → Target → HostThe public root/intermediate is required by an assigned trust policy.

CA Changes And Renewal

Changing a CA adapter does not revoke or replace the current certificate. Existing certificates remain valid until normal expiry or explicit revocation. A target CA change controls the CA used for future issuance/renewal.

The graph therefore distinguishes current certificate association from the CA configured on a target for its next renewal. Use that distinction when planning gradual CA migrations.

Trust-Anchor Impact

After configuring Trust Store Management, select a root or intermediate in Dependency & Impact to see the bundles and known managed systems that depend on it before excluding or removing the anchor.

Scope And Access

Impact results follow existing organisation and role boundaries. Network Operators only receive relationships for the network targets that their role is allowed to access.