End-To-End Operator Guide
This guide follows the normal administrator/operator workflow from host preparation through certificate renewal and delegated network-appliance operations.
1. Prepare The Host
Start with System requirements. Use a dedicated Linux server/VM for production where practical, create the control-plane DNS hostname and confirm required network paths.
2. Install And Bootstrap
Install the native DEB/RPM. First installation requires the SSL Nexus DNS hostname. If HTTPS is not ready yet, use the installer-provided SSH tunnel and short-lived setup URL to create the first Administrator.
3. Licence
Operate on the permanent Free tier, start the optional seven-day Trial, or activate the organisation's paid licence. Paid entitlements that expire or lose authority connectivity beyond grace become read-only without removing deployed certificates.
4. Add Deployment Targets And Their CAs
Deployment targets now carry their own certificate-authority profile. Add the target, configure its management channel, choose the CA adapter and save the target. Linux uses SSH, Windows uses WinRM/NTLM, and supported appliances use native HTTPS APIs.
The current first-party catalogue is Nginx, Apache, IIS, PaperCut, SAP BI Launch Pad, IWMC, Palo Alto Networks PAN-OS/Panorama, F5 BIG-IP and VMware vCenter. Run both Test connection and Test CA before assigning production certificate work.
5. Delegate Network Operations Where Appropriate
For organisations with a separate network engineering team, assign the Network Operator role. It gives that team read/write access to network targets and network-bound certificates, including encrypted appliance credentials and connection testing, without exposing Linux/Windows targets or broad SSL Nexus administration.
6. Manage Certificates
Request new certificates, adopt supported existing certificates, assign deployment ownership and review issuance, deployment and live-verification results. A certificate matching the configured SSL Nexus hostname follows the local control-plane path.
7. Validate Network Appliance Automation
Use the product-specific guides for Palo Alto Networks, F5 BIG-IP and VMware vCenter. New F5 and vCenter targets should be exercised against representative lab systems before automatic renewal is enabled.
8. Delegate Vendor Work
Enterprise customers can publish a dedicated Vendor Portal hostname. SSL Nexus validates DNS and manages that public certificate with Let's Encrypt while the vendor application backend remains on loopback.
9. Manage Renewals
Each certificate has a renewal lead time. Administrators also select the global Daily renewal check (UTC). Eligible automatic renewals are normally queued at that checkpoint; manual/retry work can run independently.
10. Maintain The Platform
Keep operating-system packages current, run ssl-nexus-admin preflight after upgrades, maintain backups, review audit/reporting, rotate integration credentials and keep target routes/management identities current.
Notifications
Configure Google Workspace, Microsoft 365 or SMTP notifications for expiry deadlines, certificate-operation failures, target failures, Vendor Portal/support events and licence health. Use the built-in test email after configuration.

