Certificate Policy Engine
Enforce certificate standards across groups, tags and metadata with the SSLNexus policy engine.
Add Or Request A Certificate
From Certificates, add an existing certificate for management or create a new request using a configured certificate authority. Supply the common name, SANs and any provider-specific information requested by the selected connector.
Choose Deployment Targets
Associate the certificate with one or more registered deployment targets. SSLNexus uses the target application and operating system to select the appropriate deployment path.
Renewal
The dashboard highlights certificates approaching expiry. Certificates configured for automated renewal are renewed according to the policy shown in the interface and then deployed to their assigned targets.
Verify Deployment
After deployment, review the result in SSLNexus. Failed jobs remain visible for review rather than being silently ignored. Correct the target or connectivity problem and retry the deployment.
Manual Control
You can run issuance, renewal or deployment on demand when maintenance or change windows require direct operator control.
Deployment Ownership
Each managed certificate records who is responsible for completing its deployment. This is operational responsibility; it does not change certificate ownership or the issuing certificate authority.
SSLNexus Automation
SSLNexus deploys the certificate through a registered target.
Internal Staff
Your team completes deployment outside the automated target workflow.
External Vendor
Deployment is handed to an assigned vendor and can be followed through the Vendor Portal lifecycle.
Custom Flow
A custom integration is responsible for deployment.
SSLNexus infers a default when the certificate is added. Administrators and Operators can change it from Certificates. The Operational overview shows the current estate split by deployment owner, and changes are recorded in Activity & audit.
Revoke A Certificate
When the configured certificate authority supports revocation, SSLNexus exposes a Revoke action for the managed certificate. Select a reason, confirm the permanent operation, and SSLNexus sends the revocation through the CA connector.
After successful revocation, the certificate is marked revoked, its automatic renewal schedule is disabled, and the operation is recorded in Activity & audit. Sectigo, DigiCert and Let’s Encrypt have native revocation support in this release.
Post-Deployment Live Verification
After SSLNexus deploys a certificate through a registered target, it connects to the certificate common name on TCP 443 and performs a TLS handshake. The live leaf certificate fingerprint must match the newly issued certificate before the operation is considered fully verified.
The Certificates page records the verification state, timestamp and result message. A mismatch or unreachable endpoint is reported as verification_failed so a successful file copy cannot be mistaken for a successful live deployment.
Renewal Policies
Renewal policy is configured per certificate. Set the renewal window, choose automatic renewal or require operator approval, configure retry attempts and delay, and optionally restrict execution to a UTC maintenance window.
Approval-required renewals remain pending until an Operator or Administrator approves them. Retryable failures are re-queued according to policy, while maintenance-window renewals wait for the next permitted window instead of running outside it.
Groups, Tags And Metadata
Use classification to keep large certificate estates navigable and ready for policy automation.
Groups
Operational collections such as Production, Customer portals or Lagos DC. Groups are intended to become policy and bulk-action targets.
Tags
Lightweight searchable labels such as internet-facing, pci or vendor-managed.
Metadata
Structured key/value context such as team=Infrastructure, region=NG and criticality=high.
The Certificates page searches across certificate identity, CA, target, groups, tags and metadata, and can filter directly by group or tag. Classification changes are recorded in Activity & audit and travel with normal backup/restore state.
Policy-Aware Bulk Changes
Bulk operations use the same policy evaluator. See Bulk operations and CA migration.

