Administration

MSP HUB Administration

Use one SSLNexus Enterprise control plane for the MSP's own infrastructure and the isolated certificate estates it operates for customers.

Licence requirement: MSP HUB is an Enterprise add-on. If it is not enabled on the current licence, the MSP customer-management controls are not available.

Operating Model

An MSP-enabled installation has two working contexts:

The estate selector in the dashboard shows the MSP HUB and the active customer estates available to the signed-in staff member.

Create A Client Estate

Start From MSP HUB

Sign in as an Organisation Administrator and make sure the current estate is MSP HUB.

Open MSP Clients

Select MSP clients and choose Add client estate.

Describe The Customer

Enter the customer name and, where useful, the account/contract reference and tags your service team uses to organise the portfolio.

Create The Estate

Select Create isolated estate. The new customer is then available in the MSP portfolio and estate selector.

Assign Engineers To Customers

Organisation Administrators can oversee the managed portfolio. Operational staff should be given only the customer access they require.

  1. From MSP clients, open the customer's Access controls.
  2. Select the enabled MSP staff who should be allowed to work with that customer.
  3. Save the assignment.

Use per-customer assignment for Operators, Network Operators and Read-only staff so customer visibility follows support responsibility.

Enter And Leave A Customer Estate

Use the dashboard estate selector, or choose Open estate from the MSP client portfolio. The dashboard clearly identifies the active customer context.

When customer work is complete, select MSP HUB to return to the MSP's own infrastructure and shared administration.

What You Operate Inside A Client Estate

Use the normal SSL Nexus workflow inside the selected customer: manage certificates, deployment targets, vendors, policies, reports and audit activity that belong to that estate.

Keep the boundary clear: create customer targets and certificate workflows while that customer's estate is selected. Keep the MSP's own infrastructure in MSP HUB.

Where maintenance/blackout windows are used, configure them with the customer whose change-control schedule they represent.

Controls That Stay In MSP HUB

Some settings affect the SSL Nexus appliance as a whole rather than one customer. Return to MSP HUB for product licensing, backups/restores and other shared platform administration. This prevents ordinary customer operations from changing appliance-wide configuration.

Suspend Or Reactivate A Customer

From MSP clients, an Organisation Administrator can suspend a customer estate when service is paused or a customer is being off-boarded.

Suspension preserves the customer's certificate records, targets, jobs, policies and audit history. Reactivate the estate when service resumes rather than recreating the customer from scratch.

Client-Estate Capacity

The MSP licence includes a managed client-estate allowance chosen for the size of the portfolio. When that allowance is reached, existing customers continue to operate but another client estate cannot be created until capacity is increased.

Check Settings → Product licence for the current licence state or contact your SSL Nexus account team when additional client capacity is required.

Backups And Disaster Recovery

Backups are managed from MSP HUB because they protect the SSL Nexus appliance and its managed estates together. Treat backup media as MSP-confidential and restrict restore operations to authorised Hub administrators.

If The MSP Add-On Is Removed

Removing the MSP entitlement does not delete the customer portfolio. Client estates and their retained data stay in place, while MSP customer operations remain unavailable until the add-on is restored.

If the organisation no longer requires MSP service delivery, this preservation model allows licensing changes without turning a commercial change into destructive data loss.

Recommended MSP Workflow