Integrations

One Certificate Workflow. Different Environments.

SSLNexus connects the certificate authority you choose to the systems you actually run, keeping certificate acquisition, deployment and verification inside one lifecycle.

One Integration Layer

Keep Certificate Issuance Separate From The Last Mile.

Changing CA should not mean rebuilding deployment. Adding a new application should not mean inventing a second renewal process. SSLNexus keeps those concerns separate while operating them from one control plane.

CA
Certificate AuthoritiesPublic, private or internal providers
SN
SSLNexusIssue · renew · deploy · track
Your EstateWindows · Linux · apps · vendors
Discovery Inputs

Begin With Verified Domains, Not An Unrestricted Network Sweep.

SSLNexus uses ownership-verified parent domains as the primary discovery boundary, then connects public certificate observation to the registered target that actually owns the deployment.

1 · VerifyAdd the SSLNexus TXT challenge to prove ownership of the parent domain.
2 · DiscoverUse Subfinder when available, with Certificate Transparency fallback, then probe HTTPS certificates.
3 · AdoptBind the observed fingerprint to the real server and choose the CA only when management begins.
Certificate Authorities

Keep The CA You Already Have.

Use the certificate authority that fits your organisation without making that provider the architecture for your whole estate. Change your automation without forcing a certificate-provider migration.

Connect supported public certificate authorities directly.
Use private or internal CA workflows where required.
Extend the connector layer for additional providers.
S
SectigoAPI-driven certificate workflows.
LE
Let's EncryptAutomated public certificate workflows.
D
DigiCertEnterprise certificate authority integration path.
+
Internal / Custom CAExtend beyond a fixed provider list.
Deployment Targets

Deploy To The System That Actually Needs The Certificate.

Built-in integrations understand the supported target platform and keep certificate deployment and renewal visible from the same lifecycle.

Windows targets use the Windows remote-management profile.
Linux targets use the Linux SSH path.
Application-aware deployment keeps target logic consistent.
W

Windows &Amp; IIS SSL Automation

Automated SSL certificate renewal and deployment for Windows estates and IIS-hosted services.

WINDOWSIISWINRM
L

Nginx &Amp; Apache SSL Automation

Automated certificate renewal and deployment across Linux, Nginx and Apache web servers.

LINUXNGINXAPACHE
A

Application-Aware Certificate Automation

Purpose-built certificate management for PaperCut NG/MF, SAP BusinessObjects BI Launch Pad, Palo Alto Networks PAN-OS, F5 BIG-IP, VMware vCenter and IWMC. SSL Nexus preserves application and appliance security boundaries while managing renewal and activation.

PAPERCUTSAP BI LAUNCH PADPAN-OSF5 BIG-IPVMWARE VCENTERIWMC
+

Extensible Deployment Workflows

Built-in workflows cover common platforms. For internal systems, bespoke applications and less common products, teams can add controlled custom deployment workflows with target testing, bounded execution, verification, rollback and isolated credentials.

CUSTOM FLOWWINDOWS OR LINUXEXTENSIBLE
Application Certificate Automation

Automate SSL Certificates Where Generic Web-Server Renewal Is Not Enough.

SSLNexus combines enterprise SSL certificate management with application-aware deployment. That includes PaperCut NG/MF, SAP BusinessObjects BI Launch Pad, Palo Alto Networks PAN-OS, F5 BIG-IP, VMware vCenter, IIS, Nginx, Apache and IWMC.

01

PaperCut Certificate Automation

Manage trusted PaperCut SSL certificates as part of the same renewal, deployment, verification and audit workflow used across the wider infrastructure estate.

02

SAP Bi Launch Pad Certificate Automation

Manage the Launch Pad certificate used by BusinessObjects Tomcat while keeping the private key on the application server and retaining safe rollback behaviour.

03

Palo Alto Networks Certificate Automation

Manage externally signed PAN-OS certificates on firewalls and Panorama through the supported management API while keeping private keys on the appliance.

04

F5 BIG-IP Certificate Automation

Use iControl REST to test appliance access, import managed certificate material and bind it to an explicitly selected Client SSL profile. The R13 implementation is intended for lab validation before production rollout.

05

VMware vCenter Certificate Automation

Generate the Machine SSL CSR inside vCenter, issue it through the target-bound CA and install the signed certificate without exporting the vCenter private key. The R13 implementation is intended for lab validation before production rollout.

04

University And Education Certificate Management

Centralise certificate lifecycle management across mixed estates where web platforms, print systems, learning environments, Windows services and externally managed applications all have different deployment requirements.

05

Vendor-Neutral PKI Automation

Keep certificate authority choice separate from deployment, so multi-CA certificate management does not force a rewrite of application automation.

06

Agentless SSL Deployment

Automate Nginx, Apache, IIS, PaperCut and other supported targets without installing a persistent SSLNexus agent on every managed server or appliance.

Certificate Destinations

Publish Certificates Beyond The Server Filesystem.

Keep application deployment and secret distribution as separate outputs of the same certificate lifecycle. A successful renewal can update the web server and republish the same managed material to the secret stores used by cloud-native workloads.

IntegrationUse
HashiCorp Vault KV v2Versioned certificate/key/metadata publication.
AWS Secrets ManagerStructured secret publication with create/update handling.
Azure Key VaultNative certificate import into the selected vault.
Multi-destination bindingPublish one managed certificate to multiple destinations after issue and renewal.
External Services

Keep Externally Hosted Certificates Inside The Same Lifecycle.

When a website or application is operated by a third party, SSLNexus keeps issuance and renewal visible internally while giving the vendor a controlled route to the certificate work they need.

Internal Certificate EstateRenewal policy and ownership stay with your organisation.
SSLNexus Vendor PortalControlled external workflow without administrator access.
External ProviderReceives the permitted certificate material and completes deployment.
Identity Providers

Use The Identity Platform Your Administrators And Vendors Already Have.

SSLNexus keeps authentication integration separate from certificate operations. One identity-provider connection can support staff, vendors or both while preserving independent authorisation rules for the administration plane and Vendor Portal.

OIDC

Microsoft Entra ID · Okta · Google Workspace · Generic OIDC

Use provider discovery metadata and signed ID-token validation with issuer, audience, expiry, nonce and signing-key checks. Staff access can use domain/group restrictions, role mapping, JIT provisioning and identity-provider MFA evidence.

LDAP

LDAP / Active Directory

Retain directory-backed administrator authentication where LDAP or Active Directory remains the organisation standard.

VENDOR

Separate Vendor Portal Authorisation

Vendor SSO requires an existing enabled vendor identity and does not self-provision supplier assignments or administrator access.

Source Control For Custom Automation

Keep Deployment Plugins With The Code Your Team Already Reviews.

Connect GitHub, Bitbucket Cloud or GitLab directly to Deployment Plugins. The organisation chooses the approved account, workspace or group while each SSLNexus administrator connects their own identity, preserving individual repository attribution without sharing a personal token.

Pull a plugin into the normal editor, test it against a registered target, then publish the validated plugin.json and YAML playbooks back to the repository. Secret names remain portable; secret values stay inside SSLNexus.

GitHub AppsBitbucket OAuthGitLab OAuthPer-admin identitySecrets stay local

Source-Control Setup →

Team plugin workflow
1Repositoryplugin.json + YAML playbooks
2Pull & testSSLNexus validation + target test
3PublishCommit with the connected admin identity
Extensible By Design

Extend Certificate Deployment To Your Own Applications.

Use built-in integrations where they fit. When your estate includes something specialised, internal or simply less common, add a controlled deployment workflow instead of waiting for a new product-specific connector.

Explore Extensibility →
ACME

One ACME Engine, Multiple Certificate Authorities

Use the Let’s Encrypt preset, DigiCert ACME with External Account Binding, or another compatible ACME directory without introducing a second certificate lifecycle. For managed HTTP-01 targets, SSLNexus can originate the key, CSR and ACME order on the remote server that actually receives the validation request, then bring the issued material back under central lifecycle management.

PRESET

Let’s Encrypt

Use the production or staging directory with native HTTP-01 validation, including remote-origin issuance for managed targets where validation must occur on the application server.

EAB

DigiCert ACME

Use the Directory URL, KID and HMAC secret issued by CertCentral while keeping the existing DigiCert API adapter available.

COMPATIBLE DIRECTORY

Custom ACME

Connect another compatible HTTPS ACME directory, with optional EAB credentials where the CA requires them.

Licence Entitlements

Integrations Unlock With The Estate You Need To Manage.

The default profiles make Nginx and Apache available from Free/Starter, Business adds Windows and IIS, and Enterprise includes the full integration set. Licence Authority 0.16 can apply explicit capability overrides to an organisation.

See The Full Tier Matrix →
Private PKI

SSLNexus Internal PKI / ACME

The default Enterprise profile includes a private ACME directory governed by EAB enrollment policies, DNS and source-network scope, account controls, certificate inventory, revocation and CRL. Read the Internal PKI documentation.