Integration guidance

Integration Support And Qualification

Choose a supported workflow and check its scope before extending automation to another environment. A connector being available does not mean every account, product version or configuration has been live-qualified.

What The Status Means

Operationally qualified records the established deployments confirmed for the product. Automated coverage means repeatable fixture or regression checks, rather than a claim of live access to your CA or appliance. Lab identifies a workflow with explicit production qualification limits.

IntegrationStatusSupported scope
Sectigo REST Enrollment + OAuthOperationally qualifiedExisting tenant Enrollment workflow. New Admin v2 authentication modes are separately fixture-tested, not included in this qualification.
Generic ACME and Let’s EncryptOperationally qualifiedEstablished ACME workflow. New provider accounts and EAB/challenge configurations need their own configuration check.
SAP BI Launch PadOperationally qualifiedExisting Windows application keystore and deployment workflow; not a promise for all SAP products.
Canon iW Management Console (iWMC)Operationally qualifiedExisting Canon iW Management Console (iWMC) Windows service/certificate workflow; version and installation layout still matter.
PaperCut, Nginx/Apache and IISImplemented; qualification record to confirmBuilt-in workflows exist. Do not infer a new live qualification result from automated test coverage.
DigiCert, GoDaddy, Google Trust Services and Vault PKIImplemented with automated coverageAccount policies, products and deployment environments require live qualification for the intended setup.
The SSL Store and custom REST CAImplemented; endpoint-specific qualificationUse a supported account/API contract. Generic REST does not automatically support every REST certificate API.
Microsoft AD CSImplemented with automated coverageTemplate policy and pending request recovery supported in Client Server. Requires customer-specific Windows/CA qualification; not a Relay provisioning feature.
Tomcat, Exchange, FortiGate, NetScaler, F5, Palo Alto and vCenterImplemented; environment qualificationBuilt-in adapters exist. Check the intended application/appliance version, binding, activation, verification and recovery path.
Kubernetes TLS Secret deploymentImplemented with automated coverageCreates/updates the configured TLS Secret and reads it back. Does not imply a Kubernetes issuer controller or pod/application reload management.
ServiceNow CMDBImplemented with automated coverageConfigured CMDB lookup/ownership workflow. Does not imply a complete ServiceNow change-request/approval integration.
Discovery, trust stores, audit, MSP tenancy and certificate destinationsImplemented with automated coverageCheck estate-specific reachability, policies and destination permissions. Discovery sources may return partial results.
Kemp LoadMasterLabCertificate upload is implemented; production binding, HA and rollback remain qualification gates.
Customer RelayRequest-only boundaryLocal CA/DNS access over outbound pairing. No deployment engine, WinRM/Ansible execution or customer-hosted AD CS deployment lifecycle.
Nexus-to-NexusImplemented with automated coverageLicensed customer Nexus executes its authorised local lifecycle over outbound federation. Confirm entitlements, estate policy and target access.

Check Your Intended Rollout

For each selected target, confirm certificate acquisition, pending approval where applicable, retrieval and chain, application activation, verification, renewal and recovery after restart. Start with one authorised target and retain the result in your change record.

Customer Infrastructure Boundaries

Private keys and target access remain in customer-controlled infrastructure. Relay requests certificates but cannot provision them to customer-hosted applications. Use a licensed customer Nexus when the customer needs local deployment coordinated by an external MSP.

CA connector guidance · Deployment targets · Backup recovery