Delegation Creates A New Security Boundary

Giving an external vendor a self-service certificate workflow can remove a large volume of routine tickets, but it also creates a boundary between your certificate authority, your organisation and a third party. The portal should therefore minimise what it knows and what it retains.

Private keys are the most obvious place to start. If the vendor’s deployment does not require the central platform to retain the key, storing it creates risk without adding operational value.

One-Time Delivery Changes The Breach Equation

When a vendor key pair is generated ephemerally and the private key is shown only once, the platform can complete the certificate request without building a long-term repository of vendor keys. A later database compromise may expose audit or request metadata, but it should not reveal a historical collection of those private keys.

This is a different security property from simply encrypting keys at rest. Encryption reduces exposure; non-retention removes the stored asset.

Combine Key Non-Retention With Scope

Key handling alone is not enough. A vendor identity should be hard-scoped to the organisational domain or certificate names it is allowed to request. SANs outside that delegated boundary should be rejected by policy, not left to human review.

Source IP/CIDR restrictions add another layer. Even if credentials are leaked, the portal can refuse access from outside the vendor’s approved corporate networks.

Keep The Portal Separate From Administration

The external portal should have its own hostname and narrowly exposed routes rather than publishing the internal administration interface to vendors. The backend can remain private while the public edge exposes only the vendor workflows, assets and authentication paths that are actually required.

This reduces the number of assumptions an organisation has to make about every external user.

Delegation Without Surrendering Control

The objective is not to make vendors trusted administrators. It is to let them complete the small set of certificate actions they legitimately need while the organisation retains domain authority, audit visibility and lifecycle governance.

A well-designed Vendor Portal therefore gives away convenience, not control.

Operational Principle: Certificate automation should reduce repetitive work without weakening the security, ownership or change controls around the systems being managed.

See SSLNexus In Your Environment

SSLNexus brings discovery, multi-CA lifecycle management, agentless deployment, vendor delegation and policy into one self-hosted control plane.

Request A Demo Read The Documentation