Integrations
Microsoft Exchange Certificate Automation
First-Party Windows Target
SSLNexus uses the existing WinRM/PowerShell provisioner and Exchange certificate cmdlets. Exchange generates and retains its private key; SSLNexus retrieves the CSR and returns the signed certificate.
Workflow
- Register the Exchange server as a Windows target.
- Select the Exchange services SSLNexus may bind: IIS, SMTP, POP and/or IMAP.
- SSLNexus runs
New-ExchangeCertificate -GenerateRequestwith a non-exportable private key. - The target-bound CA signs the CSR.
- SSLNexus runs
Import-ExchangeCertificate, followed byEnable-ExchangeCertificatefor the explicitly selected services. Get-ExchangeCertificateverifies the resulting certificate state.
Key custody: the private key remains in the Exchange certificate store.

