Prepare Windows Targets
Windows deployment targets use Windows Remote Management (WinRM) with NTLM authentication. Prepare Windows servers before adding them to SSLNexus so connectivity can be tested successfully from the interface.
Create Or Choose A Management Account
Use a dedicated Windows account for SSLNexus automation. The account must be able to perform the certificate and application-management actions required on the target. For managed estates, a dedicated domain service account is normally easier to govern than creating the same local account on every server.
Add the account to Administrators and Remote Management Users on the managed Windows servers, subject to your organisation's security policy.
Enable WinRM
PowerShell remoting/WinRM must be enabled on each Windows target. Configure the WinRM listener and Windows Firewall according to your organisation's management standard. SSLNexus supports the standard WinRM ports 5985 and 5986; use HTTPS/5986 where your environment is configured for it.
Gold Images And Group Policy
For virtualised or cloud estates, add the WinRM configuration and required management policy to the Windows gold image or apply it centrally with Group Policy. Do not embed the SSLNexus account password in the image. New servers should inherit the management configuration while credentials remain centrally controlled.
Network Placement
Place SSLNexus on a management or automation network with controlled routed access to the server VLANs it must manage. Permit only the configured WinRM management traffic from SSLNexus to its targets. Normal Windows deployment is initiated by SSLNexus, so ordinary application/server VLANs do not need a general management path back into the SSLNexus VLAN. This preserves segmentation while allowing certificate deployment across the estate.
Add The Target In SSLNexus
- Select a Windows application such as IIS, PaperCut or IWMC.
- SSLNexus selects Windows automatically.
- Enter the Windows management username and password.
- Select or enter the configured WinRM port.
- Run Test connection.
- Save only after the test succeeds.
Windows security policy can restrict remote administrative tokens for local accounts. If you use local rather than domain credentials, ensure your Windows security policy explicitly permits the required remote administrative access.
SAP BusinessObjects Bi Launch Pad
SSLNexus can manage the certificate used by BusinessObjects Tomcat while keeping the private key on the Windows application server.
- Register the server with WinRM/NTLM and supply the application/keystore password.
- Use the client-facing Launch Pad FQDN and required SANs when creating the certificate automation.
- Test the target after BusinessObjects, Tomcat or Java upgrades before relying on unattended renewal.
- SSLNexus protects the active application configuration with rollback handling if the service does not return successfully.
See the application guidance packaged with SSLNexus for supported versions and operational considerations.

