Features

Own The Certificate Lifecycle Without Forcing Everything Into One Vendor.

SSLNexus keeps issuance, renewal, deployment, verification and delegated supplier work in one self-hosted control plane while preserving the differences between certificate authorities and target platforms.

Why SSLNexus

Certificate Automation Should Follow Your Estate - Not Force Your Estate To Follow It.

Most organisations do not run one operating system, one application stack or one certificate authority. SSLNexus gives those differences one place to operate without hiding the workflows each platform actually needs.

Discovery &Amp; Adoption

Discover Certificate Ownership Before Taking Lifecycle Ownership.

Verified parent domains become the discovery boundary. SSLNexus can enumerate names passively, observe the live certificate presented by each HTTPS endpoint, and keep discovery independent of CA selection until an administrator chooses to adopt a deployment.

01

Ownership-Gated Discovery

A DNS TXT challenge proves control of the parent domain before passive enumeration is allowed, preventing the discovery feature from becoming an unrestricted scanning tool.

02

Adopt Without Changing Provider

Revalidate the discovered fingerprint on the real target, copy the existing certificate/key into protected SSLNexus management storage, and select any enabled CA adapter only when lifecycle management begins.

03

Recover Instead Of Reissuing

Use the retained artifact and deployment binding to recover a rebuilt target with the same still-valid certificate where a new issuance is unnecessary.

SSLNexus
LinuxNginx · Apache
WindowsIIS · PaperCut · SAP BI Launch Pad · IWMC
CROSS-PLATFORM AUTOMATION

Automate Windows And Linux Certificate Renewals From One Dashboard

Automate SSL certificate renewal and deployment across Windows, Linux, IIS, Nginx, Apache and application targets such as PaperCut, SAP BI Launch Pad and IWMC from a single dashboard. SSLNexus keeps the platform-specific connection method behind the target while giving administrators one place to see what is managed, what is expiring and what needs attention.

One dashboardAutomatic renewalsTarget-aware deploymentCentral status
YOUR ORGANISATIONCertificate IssuedLifecycle stays under your control
EXTERNAL VENDORSecure Hand-OffNo SSLNexus admin access required
Tracked centrally
VENDOR OPERATIONS

Manage Certificates For Externally Hosted Services

Keep ownership of certificate issuance even when the application or website is operated by a third party. The dedicated Vendor Portal separates vendor work from administration, does not retain vendor private keys after one-time delivery, can restrict access by source network, and hard-limits requests to certificate names your organisation has delegated.

Private-key non-retentionSource-network limitsDelegated-name scopeCentral visibility
Agentless target model
1Central SSLNexus engineLifecycle, policy and deployment orchestration
2Existing management channelsSSH, WinRM and supported appliance APIs
3Nginx · IIS · PaperCut · Launch PadNo persistent SSLNexus agent required
LIGHTWEIGHT TARGETS

Keep Managed Servers Free From Another Permanent Agent

SSLNexus uses an agentless certificate automation model. There is no persistent SSLNexus daemon to install on every Nginx, Apache, IIS, PaperCut or SAP BI Launch Pad server, no extra background process consuming resources while idle, and no separate agent fleet to patch every time the central engine changes.

Deployment work uses the management channels already supported by the target platform, so managed systems do not need a permanent SSLNexus agent.

No resident agentNo fleet-wide agent upgradesLinux and WindowsSupported network appliancesSmaller software footprint
Custom deployment flow
1Receive certificateUse the same managed lifecycle
2Run your logicInstall, convert, copy or call your application
3Activate & verifyKeep the result in the control plane
EXTENSIBLE AUTOMATION

Test Custom Deployment Logic Before Using IT In Production

Build versioned deployment adapters for internal platforms, bespoke applications and products outside the standard integration catalogue. Validate a custom integration against a registered Windows or Linux target before assigning production certificates, with controlled execution and recovery safeguards.

Pre-deployment target testingVersioned adaptersVerificationRollback controls
Version-controlled Deployment Plugins
1GitHub · Bitbucket · GitLabOrganisation-controlled repository boundary
2Individual administrator identityNo shared personal source-control token
3Pull · Test · PublishSame validated SSLNexus execution pipeline
TEAM AUTOMATION

Version Custom Certificate Integrations With The Rest Of Your Infrastructure Code

Connect Deployment Plugins to GitHub, Bitbucket Cloud or GitLab. Teams can review and retain integration history in their normal source-control workflow while SSLNexus remains the execution and secret boundary. The organisation selects the source-control account; each administrator connects their own identity so repository actions stay attributable.

GitHub AppBitbucket CloudGitLab / self-managedIndividual attributionNo secret-value export

See The Workflow →

CA A
CA B
CA C
SSLNexus
Your infrastructure
VENDOR-NEUTRAL BY DESIGN

Stay Independent Of Your Certificate Authority

Use multi-CA certificate management and vendor-neutral certificate automation while preserving the deployment model your teams already operate. SSLNexus separates certificate lifecycle automation from the CA itself. Use supported provider connectors or build a custom provider workflow for another authority while keeping the same deployment model across your estate. Changing CA does not have to mean rebuilding certificate operations from scratch.

Multiple CAsCustom provider workflowsConsistent deploymentNo CA lock-in
Sectigo SCMLast request 2 min ago · credentials verified
HEALTHY
DigiCert ACMEDirectory reachable · EAB configured
HEALTHY
Internal CALast test failed · authentication rejected
FAILED
CONNECTOR HEALTH

Know Whether Your Certificate Authority Connection Is Ready Before Renewal Time

Test configured CA connectors without issuing a certificate, see the last successful request and recent failures, and disable an individual connector without deleting its credentials or taking other certificate authorities offline.

Non-mutating connection testsLast successful requestFailure visibilityPer-connector enable / disable
× REVOCATION

Revoke Certificates From The Same Lifecycle That Issued Them

Where the certificate authority supports it, revoke a managed certificate directly from SSLNexus with a recorded reason. The CA must confirm the operation before SSLNexus marks the certificate revoked, disables renewal and records the action in Activity & audit.

SectigoDigiCertLet’s EncryptPermanent audit trail
portal.example.comManaged certificate
REVOCATION REQUEST
Certificate AuthorityProvider confirms revocation
REVOKED · AUDITED
30 daysRenewal opens
ApprovalChange control
DeployMaintenance window
AutomaticApproval requiredRetry ×302:00–04:00 UTC
RENEWAL POLICY

Control How Each Certificate Renews

Use automatic renewal for unattended services, require approval for change-controlled applications, configure retry behaviour, and restrict execution to an approved UTC maintenance window.

Per-certificate windowsApproval gatingRetry policyMaintenance windows
GROUPProduction / Customer Portals
internet-facingpcivendor-managed
team
Infrastructure
region
NG
criticality
high
service
payments
# ESTATE ORGANISATION

Keep Hundreds Or Thousands Of Certificates Organised For Policy And Automation

Group certificates into operational collections, add searchable tags, and attach structured metadata such as team, region or criticality. Search and filter the estate directly from Certificates, with the same classification ready for policy and bulk-operation targeting.

GroupsTagsStructured metadataSearch & filters
The Result

Renew Automatically. Deploy Consistently. Extend When You Need To.

Issue, renew, inspect, verify and deploy from one operational plane - with certificates, failures, renewals and activity visible in the same control centre.

Explore Integrations →
web-linux-01SSH · 38 ms · checked now
HEALTHY
iis-prod-02WinRM · 71 ms · checked now
HEALTHY
legacy-app-01WinRM · timeout · 4 min ago
FAILED
TARGET HEALTH

Know When A Deployment Target Becomes Unreachable

SSLNexus checks Linux targets over SSH and Windows targets over WinRM using the same credentials and management channel used for deployment. See the latest health result, check time and latency, run a check on demand, and receive an alert when a target changes to failed.

SSH healthWinRM healthManual testFailure alerts
ADMINISTRATIVE SECURITY

Protect Administrator And Vendor Access With Local Controls, LDAP And Enterprise SSO

Local staff accounts can use OTP, review active sessions and revoke access immediately. Microsoft Entra ID, Okta, Google Workspace and Generic OIDC can provide signed-token SSO, while LDAP / Active Directory remains available for directory-backed staff access. Staff and Vendor Portal authorisation stay separate so external identities cannot become administrators by accident.

OTP & sessionsEntra / Okta / Google OIDCLDAP / Active DirectoryRole & MFA policy
OTP
Current sessionChrome · Lagos · now
ACTIVE
Operations workstationEdge · 2 hours ago
REVOKE
Old sessionLast used 3 days ago
REVOKE
Certificate Authorities

Native Let’s Encrypt Automation

Use SSLNexus as the ACME client for Let’s Encrypt instead of maintaining a separate Certbot renewal path. The same adapter can issue application certificates and the certificate protecting the SSLNexus administration UI.

One Certificate Lifecycle

ACME account state, issuance, renewal visibility and deployment remain inside SSLNexus alongside commercial CA connectors. For managed HTTP-01 targets, SSLNexus can generate the key and CSR and complete the ACME transaction on the remote server that actually receives the validation request.

Safe Validation Testing

Switch between Let’s Encrypt staging and production from the connector settings while validating DNS and HTTP-01 reachability. Once issued, SSLNexus retrieves the certificate material into the same central lifecycle used for renewal, recovery and distribution.

DEPLOYED SHA-2568F:2B:A1:77:…:C9
=
LIVE SHA-2568F:2B:A1:77:…:C9
✓ LIVE CERTIFICATE VERIFIED
LIVE VERIFICATION

Confirm That The Application Is Actually Serving The Certificate You Deployed

SSLNexus does not stop at a successful file copy or service reload. After managed deployment it connects to the live TLS endpoint and verifies that the certificate being served matches the newly issued certificate.

Live TLS handshakeFingerprint matchVerification stateFailure visibility
SHARED ACME

Use One ACME Engine Across Let’s Encrypt, DigiCert And Compatible CAs

Choose the Let’s Encrypt preset, DigiCert ACME with EAB credentials, or a custom ACME directory while keeping issuance and deployment inside the same SSLNexus lifecycle.

Let’s EncryptDigiCert ACMECustom ACMEEAB support
LE
DIGICERT
ACME
SSLNexus
Shared engine
TARGET ONBOARDING

Prepare Linux Targets From A Generated SSH Bootstrap

SSLNexus generates its automation key and gives operators a copy/paste setup block that creates the Linux service account, installs the public key, configures account-scoped SSH access and grants the sudo privileges Ansible needs for deployment.

SSH key authDedicated userAnsible becomeVLAN-aware deployment
SSH
Linux onboarding
Generated by SSLNexus
  • Public key
  • Service account
  • SSHD drop-in
  • Sudo policy
Certificate Distribution

Publish Renewed Certificates Where Cloud-Native Workloads Already Consume Secrets.

Server deployment is only one destination. SSLNexus can independently publish managed certificate material into central secret stores without changing which CA issued the certificate or which application owns the live deployment.

DestinationBehaviour
HashiCorp Vault KV v2Write certificate, private key and lifecycle metadata to the configured versioned secret path.
AWS Secrets ManagerPublish a structured certificate/key bundle and create the target secret when required.
Azure Key VaultImport the managed certificate/private-key bundle as a Key Vault certificate.
Multiple destinationsBind more than one destination to the same certificate and republish automatically after successful issue or renewal.
POLICY ENFORCEMENT

Turn Certificate Classification Into Enforceable Operational Standards

Target groups, tags and metadata, then enforce approved CAs, deployment responsibility, managed-target requirements and renewal controls. Existing drift stays visible; new changes that break policy are blocked.

CA allowlistsDeployment controlsRenewal standardsCompliance visibility
WHENProduction + Internet-Facingcriticality = high
REQUIREApproved CA + Managed TargetAutomatic renewal · 30-day lead
392 Compliant36 NEED ATTENTION
CERTIFICATEACTIONPREVIEW
portal.example.comMigrate CAREADY
api.example.comRenewREADY
legacy.example.comRevokeBLOCKED
2 ready · 1 blocked by policy · execution has not started
BULK OPERATIONS

Change Large Certificate Collections Without Bypassing Policy

Preview the exact certificate set before execution, then renew, revoke, reclassify or migrate certificates to another CA. CA migration keeps the current provider authoritative until the new certificate is issued, deployed and verified successfully.

Preview firstPolicy awareSafe CA migrationPer-certificate results
ENTERPRISE REPORTING

Turn Operational Certificate Data Into Scheduled Reports And Audit Evidence

Build reusable inventory, expiry, compliance, target-health, vendor and audit reports using the same groups, tags and metadata that drive policy. Schedule delivery, choose executive or detailed email presentation, and export generated history as CSV or PDF.

Saved reportsScheduled emailCSV exportPDF export
Monthly Certificate PostureProduction · internet-facing
EMAILPDFCSV
APPLIANCE DELEGATION

Let Network Engineers Operate Network Certificates Without Handing Over The Whole Platform.

The Network Operator role gives appliance teams read/write access to network targets and their certificate jobs while keeping Linux, Windows, licensing, backups, global identity and other administration outside their scope.

Network-only RBACEncrypted API credentialsTest connectionTest CALDAP/OIDC group mapping
Network Operator
PAN-OS · F5 BIG-IP · VMware vCenter
Deployment Advantage

Adopt Certificate Automation Without Turning IT Into Another Transformation Project.

01

Useful From The First Connected Systems

SSLNexus is a central, self-hosted service rather than a new daemon for every endpoint. Connect supported CAs and representative targets first, prove the workflow, then expand coverage at your own pace.

02

Integrates Instead Of Replacing

Use the PKI, identity, cloud services, repositories and management protocols already approved in your environment. Vendor-neutral CA connectors and separate deployment integrations let governance become consistent while infrastructure choices remain yours.

Licensing

Tier-Aware Automation Without Tier-Aware Blind Spots.

Free and Starter automate Linux with Nginx/Apache. Business adds Windows automation platform and IIS. Enterprise adds application integrations, custom plugins and Vendor Portal. Discovery, policy, audit and reporting remain part of the operational core.

Compare Entitlements →
Enterprise Internal PKI

Govern Private Certificates With An Internal Pki.

Operate SSLNexus as a private ACME CA with EAB enrollment, delegated DNS and network scope, key policy, certificate inventory, revocation and CRL publication. Internal certificates still appear in the central SSLNexus estate.

01

Controlled Enrollment

EAB credentials, source CIDRs, DNS scope, key algorithms, validity and account limits are enforced by the ACME service.

02

Operational Management

Manage ACME accounts, private certificate inventory and revocation from a dedicated Internal PKI area, with Network Operator delegation for network-scoped objects.

MSP HUB · Enterprise Add-On

Run Your Own Certificate Estate And Every Managed Customer From One Control Plane.

MSP HUB extends Enterprise for service providers that need to operate many customer environments without deploying a separate SSLNexus appliance for every contract.

Isolated Customer Estates

Certificates, targets, policies, vendor activity and audit history remain separated by customer while the MSP keeps one operational view.

Engineer Assignment By Customer

Give engineers access only to the client estates they support, reducing unnecessary visibility and operational blast radius.

Fast Estate Switching

Move between the MSP's own estate and assigned customers from the same signed-in dashboard instead of maintaining dozens of separate sessions.

Portfolio Overview

See certificate volume, expiry risk, failed jobs and target health across the managed portfolio so teams can prioritise attention.

Customer Lifecycle Controls

Suspend an off-boarded customer without deleting its operational history, then reactivate the estate when service resumes.

MSP Infrastructure Stays First-Class

The Hub is still the MSP's own complete certificate estate, so internal infrastructure does not require a second installation.