Delegation Creates A New Security Boundary
Giving an external vendor a self-service certificate workflow can remove a large volume of routine tickets, but it also creates a boundary between your certificate authority, your organisation and a third party. The portal should therefore minimise what it knows and what it retains.
Private keys are the most obvious place to start. If the vendor’s deployment does not require the central platform to retain the key, storing it creates risk without adding operational value.
One-Time Delivery Changes The Breach Equation
When a vendor key pair is generated ephemerally and the private key is shown only once, the platform can complete the certificate request without building a long-term repository of vendor keys. A later database compromise may expose audit or request metadata, but it should not reveal a historical collection of those private keys.
This is a different security property from simply encrypting keys at rest. Encryption reduces exposure; non-retention removes the stored asset.
Combine Key Non-Retention With Scope
Key handling alone is not enough. A vendor identity should be hard-scoped to the organisational domain or certificate names it is allowed to request. SANs outside that delegated boundary should be rejected by policy, not left to human review.
Source IP/CIDR restrictions add another layer. Even if credentials are leaked, the portal can refuse access from outside the vendor’s approved corporate networks.
Keep The Portal Separate From Administration
The external portal should have its own hostname and narrowly exposed routes rather than publishing the internal administration interface to vendors. The backend can remain private while the public edge exposes only the vendor workflows, assets and authentication paths that are actually required.
This reduces the number of assumptions an organisation has to make about every external user.
Delegation Without Surrendering Control
The objective is not to make vendors trusted administrators. It is to let them complete the small set of certificate actions they legitimately need while the organisation retains domain authority, audit visibility and lifecycle governance.
A well-designed Vendor Portal therefore gives away convenience, not control.
See SSLNexus In Your Environment
SSLNexus brings discovery, multi-CA lifecycle management, agentless deployment, vendor delegation and policy into one self-hosted control plane.
Request A Demo Read The Documentation
