Integration Support And Qualification
Choose a supported workflow and check its scope before extending automation to another environment. A connector being available does not mean every account, product version or configuration has been live-qualified.
What The Status Means
Operationally qualified records the established deployments confirmed for the product. Automated coverage means repeatable fixture or regression checks, rather than a claim of live access to your CA or appliance. Lab identifies a workflow with explicit production qualification limits.
| Integration | Status | Supported scope |
|---|---|---|
| Sectigo REST Enrollment + OAuth | Operationally qualified | Existing tenant Enrollment workflow. New Admin v2 authentication modes are separately fixture-tested, not included in this qualification. |
| Generic ACME and Let’s Encrypt | Operationally qualified | Established ACME workflow. New provider accounts and EAB/challenge configurations need their own configuration check. |
| SAP BI Launch Pad | Operationally qualified | Existing Windows application keystore and deployment workflow; not a promise for all SAP products. |
| Canon iW Management Console (iWMC) | Operationally qualified | Existing Canon iW Management Console (iWMC) Windows service/certificate workflow; version and installation layout still matter. |
| PaperCut, Nginx/Apache and IIS | Implemented; qualification record to confirm | Built-in workflows exist. Do not infer a new live qualification result from automated test coverage. |
| DigiCert, GoDaddy, Google Trust Services and Vault PKI | Implemented with automated coverage | Account policies, products and deployment environments require live qualification for the intended setup. |
| The SSL Store and custom REST CA | Implemented; endpoint-specific qualification | Use a supported account/API contract. Generic REST does not automatically support every REST certificate API. |
| Microsoft AD CS | Implemented with automated coverage | Template policy and pending request recovery supported in Client Server. Requires customer-specific Windows/CA qualification; not a Relay provisioning feature. |
| Tomcat, Exchange, FortiGate, NetScaler, F5, Palo Alto and vCenter | Implemented; environment qualification | Built-in adapters exist. Check the intended application/appliance version, binding, activation, verification and recovery path. |
| Kubernetes TLS Secret deployment | Implemented with automated coverage | Creates/updates the configured TLS Secret and reads it back. Does not imply a Kubernetes issuer controller or pod/application reload management. |
| ServiceNow CMDB | Implemented with automated coverage | Configured CMDB lookup/ownership workflow. Does not imply a complete ServiceNow change-request/approval integration. |
| Discovery, trust stores, audit, MSP tenancy and certificate destinations | Implemented with automated coverage | Check estate-specific reachability, policies and destination permissions. Discovery sources may return partial results. |
| Kemp LoadMaster | Lab | Certificate upload is implemented; production binding, HA and rollback remain qualification gates. |
| Customer Relay | Request-only boundary | Local CA/DNS access over outbound pairing. No deployment engine, WinRM/Ansible execution or customer-hosted AD CS deployment lifecycle. |
| Nexus-to-Nexus | Implemented with automated coverage | Licensed customer Nexus executes its authorised local lifecycle over outbound federation. Confirm entitlements, estate policy and target access. |
Check Your Intended Rollout
For each selected target, confirm certificate acquisition, pending approval where applicable, retrieval and chain, application activation, verification, renewal and recovery after restart. Start with one authorised target and retain the result in your change record.
Customer Infrastructure Boundaries
Private keys and target access remain in customer-controlled infrastructure. Relay requests certificates but cannot provision them to customer-hosted applications. Use a licensed customer Nexus when the customer needs local deployment coordinated by an external MSP.
CA connector guidance · Deployment targets · Backup recovery

