Customer Authority Federation
Nexus-to-Nexus and Customer Relay let an MSP manage certificate lifecycle for customers that retain their own DNS and CA authority. A customer with SSLNexus uses its existing Client Server. A customer without SSLNexus can use the smaller Linux or Windows Relay.
One Outbound Customer Channel
- The MSP selects a customer estate and creates a single-use pairing invitation valid for 24 hours. Use Copy Pairing Invitation to share the full JSON securely.
- The customer pairs from its Client Server's External MSPs area, or from Relay's Vendor Channels. The customer initiates enrollment and subsequent polling connections to the MSP listener.
- The customer configures a vendor-specific authority profile and explicitly activates the channel. Pairing alone does not permit issuance.
- The MSP submits normal certificate work. The customer validates the CSR against local policy, obtains any required approval and calls its local CA.
- The certificate and chain return over an outbound request. The requesting Client Server resumes deployment, verification and renewal scheduling.
Private keys do not travel through federation. Keep workload keys with the owning target or requester inside the agreed infrastructure boundary. Customer-side machine and ACME account keys remain local. CA validation is still required: keep the necessary DNS API access or challenge handling inside the customer's environment.
MSP Setup
Enable and save the dedicated MSP federation listener in MSP HUB, restart, then select an active customer estate and generate its invitation. Advertise the listener's reachable HTTPS hostname and actual port. A normal dashboard web proxy that terminates TLS cannot preserve the pinned machine identity and later mutual TLS session. Use direct TLS or approved TCP passthrough.
After customer activation, refresh that estate's channels and profiles. Configure the estate's deployment target with Customer SSLNexus Relay as its CA route and the supplied channel/profile IDs. This CA-route label uses the shared federation protocol for both customer Client Server and Relay. MSP entitlement and estate activity are checked during authorisation.
Customer With SSLNexus: Nexus-To-Nexus
- Sign in as the customer organisation administrator. Open External MSPs from the left menu, or use the External MSP Connections shortcut in About.
- Paste the MSP invitation and select Pair MSP. Verify the supplied identity and endpoint through your trusted MSP contact.
- Create a customer authority profile. Select the existing customer-local CA configuration from Deployment Targets, permitted domains, SAN/validity limits, wildcard policy and approved CA trust. Using that configuration for federation does not deploy the MSP request to that local target.
- Keep approval required when your change process demands it. Enable certificate revocation only when explicitly permitted. Activate the channel after reviewing its profile.
- Review requests and approvals in External MSPs. Suspend or offboard vendors independently. CA configuration is snapshotted locally so later target edits cannot redirect an outstanding CA operation.
The customer does not need MSP HUB entitlement merely to act as the customer authority. Its existing local licence must permit the selected CA operation. The requesting MSP needs valid MSP entitlement. Local credentials and customer account access are not shared with the MSP.
Customer Without SSLNexus: Relay
Install the supplied binary Relay package on customer Linux or Windows infrastructure. Create its named administrator, pair the invitation, configure the local CA connector and vendor profile, then activate. See the Customer Relay guide for installation, accounts and policy configuration.
Renewal, Revocation And Recovery
Renewals use the same channel and are rechecked against customer policy and approval requirements on every renewal. Migration into federation issues a replacement under the destination customer policy. It does not transfer CA orders or automatically revoke the old certificate.
Revocation requires a supporting adapter and explicit customer profile permission. The original customer channel, profile, connector and CA order are retained. The requesting Client marks the certificate revoked and stops future renewal only after confirmation.
Uncertain CA operations remain stopped. Check the original operation with the CA, then reconcile its existing order or confirmed outcome in the customer request history. Do not submit a second order to resolve an unknown outcome. Channel identity renewal keeps the enrolled key and cannot reactivate a stopped vendor.
Connectivity And Pairing Errors
Both customer options need outbound HTTPS to the MSP listener and the configured CA. The MSP needs inbound access to its advertised federation port. Management and CA validation have separate requirements; public HTTP-01 validation still needs an appropriate public challenge route.
Invitations expire after 24 hours and are single-use. Obtain a new invitation after expiry or identity changes. A connection failure means the customer did not receive an MSP bootstrap response. Check the listener bind address, advertised port, firewall, DNS and direct TLS path. A connection closed or reset during TLS needs the MSP listener logs and any network inspection checked.
Customer-Local Deployment Without An Inbound MSP Path
Use Nexus-to-Nexus when a customer needs issuance, deployment and verification inside its own environment. Its licensed Client Server polls outbound for approved work and executes the supported target workflow locally. This does not require the MSP to reach customer management ports directly. Customer policy, approval, licence and target permissions still apply.
Relay-only customers can request and return certificates but cannot use Relay to deploy to internal targets or enroll through AD CS. For an MSP-hosted application, the MSP may deploy the returned certificate to its own authorised target. For a customer-hosted application, arrange customer deployment or use an appropriately licensed customer Client Server.

