Operations

Certificate Policy Engine

Certificate Lifecycle

Enforce certificate standards across groups, tags and metadata with the SSLNexus policy engine.

Add Or Request A Certificate

From Certificates, add an existing certificate for management or create a new request using a configured certificate authority. Supply the common name, SANs and any provider-specific information requested by the selected connector.

Choose Deployment Targets

Associate the certificate with one or more registered deployment targets. SSLNexus uses the target application and operating system to select the appropriate deployment path.

Renewal

The dashboard highlights certificates approaching expiry. Certificates configured for automated renewal are renewed according to the policy shown in the interface and then deployed to their assigned targets.

Verify Deployment

After deployment, review the result in SSLNexus. Failed jobs remain visible for review rather than being silently ignored. Correct the target or connectivity problem and retry the deployment.

Manual Control

You can run issuance, renewal or deployment on demand when maintenance or change windows require direct operator control.

Deployment Ownership

Each managed certificate records who is responsible for completing its deployment. This is operational responsibility; it does not change certificate ownership or the issuing certificate authority.

SSLNexus Automation

SSLNexus deploys the certificate through a registered target.

Internal Staff

Your team completes deployment outside the automated target workflow.

External Vendor

Deployment is handed to an assigned vendor and can be followed through the Vendor Portal lifecycle.

Custom Flow

A custom integration is responsible for deployment.

SSLNexus infers a default when the certificate is added. Administrators and Operators can change it from Certificates. The Operational overview shows the current estate split by deployment owner, and changes are recorded in Activity & audit.

Revoke A Certificate

When the configured certificate authority supports revocation, SSLNexus exposes a Revoke action for the managed certificate. Select a reason, confirm the permanent operation, and SSLNexus sends the revocation through the CA connector.

Revocation is permanent. SSLNexus only changes the local certificate state after the certificate authority confirms the request.

After successful revocation, the certificate is marked revoked, its automatic renewal schedule is disabled, and the operation is recorded in Activity & audit. Sectigo, DigiCert and Let’s Encrypt have native revocation support in this release.

Post-Deployment Live Verification

After SSLNexus deploys a certificate through a registered target, it connects to the certificate common name on TCP 443 and performs a TLS handshake. The live leaf certificate fingerprint must match the newly issued certificate before the operation is considered fully verified.

The Certificates page records the verification state, timestamp and result message. A mismatch or unreachable endpoint is reported as verification_failed so a successful file copy cannot be mistaken for a successful live deployment.

Renewal Policies

Renewal policy is configured per certificate. Set the renewal window, choose automatic renewal or require operator approval, configure retry attempts and delay, and optionally restrict execution to a UTC maintenance window.

Approval-required renewals remain pending until an Operator or Administrator approves them. Retryable failures are re-queued according to policy, while maintenance-window renewals wait for the next permitted window instead of running outside it.

Groups, Tags And Metadata

Use classification to keep large certificate estates navigable and ready for policy automation.

Groups

Operational collections such as Production, Customer portals or Lagos DC. Groups are intended to become policy and bulk-action targets.

Tags

Lightweight searchable labels such as internet-facing, pci or vendor-managed.

Metadata

Structured key/value context such as team=Infrastructure, region=NG and criticality=high.

The Certificates page searches across certificate identity, CA, target, groups, tags and metadata, and can filter directly by group or tag. Classification changes are recorded in Activity & audit and travel with normal backup/restore state.

Policy-Aware Bulk Changes

Bulk operations use the same policy evaluator. See Bulk operations and CA migration.

Policy Engine

Turn Certificate Classification Into Enforceable Controls

Policies target certificates by group, tag and structured metadata. Matching selectors are combined as AND conditions, and an empty selector can apply a baseline across the whole estate.

01

Approved Certificate Authorities

Restrict a collection to the CA adapters approved for that environment or business unit.

02

Deployment Responsibility

Require approved deployment owners and, where appropriate, a registered managed deployment target.

03

Renewal Controls

Require automatic renewal and a minimum renewal lead time for certificates that must not depend on manual action.

04

Prevent Drift And Expose Existing Gaps

Changes that would violate an enabled policy are rejected. Existing certificates that do not comply remain visible with the exact policy violation so teams can remediate them safely.