Useful From The First Connected Systems
SSLNexus is a central, self-hosted service rather than a new daemon for every endpoint. Connect supported CAs and representative targets first, prove the workflow, then expand coverage at your own pace.
SSLNexus keeps issuance, renewal, deployment, verification and delegated supplier work in one self-hosted control plane while preserving the differences between certificate authorities and target platforms.
Most organisations do not run one operating system, one application stack or one certificate authority. SSLNexus gives those differences one place to operate without hiding the workflows each platform actually needs.
Verified parent domains become the discovery boundary. SSLNexus can enumerate names passively, observe the live certificate presented by each HTTPS endpoint, and keep discovery independent of CA selection until an administrator chooses to adopt a deployment.
A DNS TXT challenge proves control of the parent domain before passive enumeration is allowed, preventing the discovery feature from becoming an unrestricted scanning tool.
Revalidate the discovered fingerprint on the real target, copy the existing certificate/key into protected SSLNexus management storage, and select any enabled CA adapter only when lifecycle management begins.
Use the retained artifact and deployment binding to recover a rebuilt target with the same still-valid certificate where a new issuance is unnecessary.
Automate SSL certificate renewal and deployment across Windows, Linux, IIS, Nginx, Apache and application targets such as PaperCut, SAP BI Launch Pad and IWMC from a single dashboard. SSLNexus keeps the platform-specific connection method behind the target while giving administrators one place to see what is managed, what is expiring and what needs attention.
Keep ownership of certificate issuance even when the application or website is operated by a third party. The dedicated Vendor Portal separates vendor work from administration, does not retain vendor private keys after one-time delivery, can restrict access by source network, and hard-limits requests to certificate names your organisation has delegated.
SSLNexus uses an agentless certificate automation model. There is no persistent SSLNexus daemon to install on every Nginx, Apache, IIS, PaperCut or SAP BI Launch Pad server, no extra background process consuming resources while idle, and no separate agent fleet to patch every time the central engine changes.
Deployment work uses the management channels already supported by the target platform, so managed systems do not need a permanent SSLNexus agent.
Build versioned deployment adapters for internal platforms, bespoke applications and products outside the standard integration catalogue. Validate a custom integration against a registered Windows or Linux target before assigning production certificates, with controlled execution and recovery safeguards.
Connect Deployment Plugins to GitHub, Bitbucket Cloud or GitLab. Teams can review and retain integration history in their normal source-control workflow while SSLNexus remains the execution and secret boundary. The organisation selects the source-control account; each administrator connects their own identity so repository actions stay attributable.
Use multi-CA certificate management and vendor-neutral certificate automation while preserving the deployment model your teams already operate. SSLNexus separates certificate lifecycle automation from the CA itself. Use supported provider connectors or build a custom provider workflow for another authority while keeping the same deployment model across your estate. Changing CA does not have to mean rebuilding certificate operations from scratch.
Test configured CA connectors without issuing a certificate, see the last successful request and recent failures, and disable an individual connector without deleting its credentials or taking other certificate authorities offline.
Where the certificate authority supports it, revoke a managed certificate directly from SSLNexus with a recorded reason. The CA must confirm the operation before SSLNexus marks the certificate revoked, disables renewal and records the action in Activity & audit.
Use automatic renewal for unattended services, require approval for change-controlled applications, configure retry behaviour, and restrict execution to an approved UTC maintenance window.
Group certificates into operational collections, add searchable tags, and attach structured metadata such as team, region or criticality. Search and filter the estate directly from Certificates, with the same classification ready for policy and bulk-operation targeting.
Issue, renew, inspect, verify and deploy from one operational plane - with certificates, failures, renewals and activity visible in the same control centre.
SSLNexus checks Linux targets over SSH and Windows targets over WinRM using the same credentials and management channel used for deployment. See the latest health result, check time and latency, run a check on demand, and receive an alert when a target changes to failed.
Local staff accounts can use OTP, review active sessions and revoke access immediately. Microsoft Entra ID, Okta, Google Workspace and Generic OIDC can provide signed-token SSO, while LDAP / Active Directory remains available for directory-backed staff access. Staff and Vendor Portal authorisation stay separate so external identities cannot become administrators by accident.
Use SSLNexus as the ACME client for Let’s Encrypt instead of maintaining a separate Certbot renewal path. The same adapter can issue application certificates and the certificate protecting the SSLNexus administration UI.
ACME account state, issuance, renewal visibility and deployment remain inside SSLNexus alongside commercial CA connectors. For managed HTTP-01 targets, SSLNexus can generate the key and CSR and complete the ACME transaction on the remote server that actually receives the validation request.
Switch between Let’s Encrypt staging and production from the connector settings while validating DNS and HTTP-01 reachability. Once issued, SSLNexus retrieves the certificate material into the same central lifecycle used for renewal, recovery and distribution.
8F:2B:A1:77:…:C98F:2B:A1:77:…:C9SSLNexus does not stop at a successful file copy or service reload. After managed deployment it connects to the live TLS endpoint and verifies that the certificate being served matches the newly issued certificate.
Choose the Let’s Encrypt preset, DigiCert ACME with EAB credentials, or a custom ACME directory while keeping issuance and deployment inside the same SSLNexus lifecycle.
SSLNexus generates its automation key and gives operators a copy/paste setup block that creates the Linux service account, installs the public key, configures account-scoped SSH access and grants the sudo privileges Ansible needs for deployment.
Server deployment is only one destination. SSLNexus can independently publish managed certificate material into central secret stores without changing which CA issued the certificate or which application owns the live deployment.
| Destination | Behaviour |
|---|---|
| HashiCorp Vault KV v2 | Write certificate, private key and lifecycle metadata to the configured versioned secret path. |
| AWS Secrets Manager | Publish a structured certificate/key bundle and create the target secret when required. |
| Azure Key Vault | Import the managed certificate/private-key bundle as a Key Vault certificate. |
| Multiple destinations | Bind more than one destination to the same certificate and republish automatically after successful issue or renewal. |
Target groups, tags and metadata, then enforce approved CAs, deployment responsibility, managed-target requirements and renewal controls. Existing drift stays visible; new changes that break policy are blocked.
Preview the exact certificate set before execution, then renew, revoke, reclassify or migrate certificates to another CA. CA migration keeps the current provider authoritative until the new certificate is issued, deployed and verified successfully.
Build reusable inventory, expiry, compliance, target-health, vendor and audit reports using the same groups, tags and metadata that drive policy. Schedule delivery, choose executive or detailed email presentation, and export generated history as CSV or PDF.
The Network Operator role gives appliance teams read/write access to network targets and their certificate jobs while keeping Linux, Windows, licensing, backups, global identity and other administration outside their scope.
SSLNexus is a central, self-hosted service rather than a new daemon for every endpoint. Connect supported CAs and representative targets first, prove the workflow, then expand coverage at your own pace.
Use the PKI, identity, cloud services, repositories and management protocols already approved in your environment. Vendor-neutral CA connectors and separate deployment integrations let governance become consistent while infrastructure choices remain yours.
Free and Starter automate Linux with Nginx/Apache. Business adds Windows automation platform and IIS. Enterprise adds application integrations, custom plugins and Vendor Portal. Discovery, policy, audit and reporting remain part of the operational core.
Compare Entitlements →Operate SSLNexus as a private ACME CA with EAB enrollment, delegated DNS and network scope, key policy, certificate inventory, revocation and CRL publication. Internal certificates still appear in the central SSLNexus estate.
EAB credentials, source CIDRs, DNS scope, key algorithms, validity and account limits are enforced by the ACME service.
Manage ACME accounts, private certificate inventory and revocation from a dedicated Internal PKI area, with Network Operator delegation for network-scoped objects.
MSP HUB extends Enterprise for service providers that need to operate many customer environments without deploying a separate SSLNexus appliance for every contract.
Certificates, targets, policies, vendor activity and audit history remain separated by customer while the MSP keeps one operational view.
Give engineers access only to the client estates they support, reducing unnecessary visibility and operational blast radius.
Move between the MSP's own estate and assigned customers from the same signed-in dashboard instead of maintaining dozens of separate sessions.
See certificate volume, expiry risk, failed jobs and target health across the managed portfolio so teams can prioritise attention.
Suspend an off-boarded customer without deleting its operational history, then reactivate the estate when service resumes.
The Hub is still the MSP's own complete certificate estate, so internal infrastructure does not require a second installation.