SSLNexus connects the certificate authority you choose to the systems you actually run, keeping certificate acquisition, deployment and verification inside one lifecycle.
Changing CA should not mean rebuilding deployment. Adding a new application should not mean inventing a second renewal process. SSLNexus keeps those concerns separate while operating them from one control plane.
SSLNexus uses ownership-verified parent domains as the primary discovery boundary, then connects public certificate observation to the registered target that actually owns the deployment.
Use the certificate authority that fits your organisation without making that provider the architecture for your whole estate. Change your automation without forcing a certificate-provider migration.
Built-in integrations understand the supported target platform and keep certificate deployment and renewal visible from the same lifecycle.
Automated SSL certificate renewal and deployment for Windows estates and IIS-hosted services.
Automated certificate renewal and deployment across Linux, Nginx and Apache web servers.
Purpose-built certificate management for PaperCut NG/MF, SAP BusinessObjects BI Launch Pad, Palo Alto Networks PAN-OS, F5 BIG-IP, VMware vCenter and IWMC. SSL Nexus preserves application and appliance security boundaries while managing renewal and activation.
Built-in workflows cover common platforms. For internal systems, bespoke applications and less common products, teams can add controlled custom deployment workflows with target testing, bounded execution, verification, rollback and isolated credentials.
SSLNexus combines enterprise SSL certificate management with application-aware deployment. That includes PaperCut NG/MF, SAP BusinessObjects BI Launch Pad, Palo Alto Networks PAN-OS, F5 BIG-IP, VMware vCenter, IIS, Nginx, Apache and IWMC.
Manage trusted PaperCut SSL certificates as part of the same renewal, deployment, verification and audit workflow used across the wider infrastructure estate.
Manage the Launch Pad certificate used by BusinessObjects Tomcat while keeping the private key on the application server and retaining safe rollback behaviour.
Manage externally signed PAN-OS certificates on firewalls and Panorama through the supported management API while keeping private keys on the appliance.
Use iControl REST to test appliance access, import managed certificate material and bind it to an explicitly selected Client SSL profile. The R13 implementation is intended for lab validation before production rollout.
Generate the Machine SSL CSR inside vCenter, issue it through the target-bound CA and install the signed certificate without exporting the vCenter private key. The R13 implementation is intended for lab validation before production rollout.
Centralise certificate lifecycle management across mixed estates where web platforms, print systems, learning environments, Windows services and externally managed applications all have different deployment requirements.
Keep certificate authority choice separate from deployment, so multi-CA certificate management does not force a rewrite of application automation.
Automate Nginx, Apache, IIS, PaperCut and other supported targets without installing a persistent SSLNexus agent on every managed server or appliance.
Keep application deployment and secret distribution as separate outputs of the same certificate lifecycle. A successful renewal can update the web server and republish the same managed material to the secret stores used by cloud-native workloads.
| Integration | Use |
|---|---|
| HashiCorp Vault KV v2 | Versioned certificate/key/metadata publication. |
| AWS Secrets Manager | Structured secret publication with create/update handling. |
| Azure Key Vault | Native certificate import into the selected vault. |
| Multi-destination binding | Publish one managed certificate to multiple destinations after issue and renewal. |
When a website or application is operated by a third party, SSLNexus keeps issuance and renewal visible internally while giving the vendor a controlled route to the certificate work they need.
SSLNexus keeps authentication integration separate from certificate operations. One identity-provider connection can support staff, vendors or both while preserving independent authorisation rules for the administration plane and Vendor Portal.
Use provider discovery metadata and signed ID-token validation with issuer, audience, expiry, nonce and signing-key checks. Staff access can use domain/group restrictions, role mapping, JIT provisioning and identity-provider MFA evidence.
Retain directory-backed administrator authentication where LDAP or Active Directory remains the organisation standard.
Vendor SSO requires an existing enabled vendor identity and does not self-provision supplier assignments or administrator access.
Connect GitHub, Bitbucket Cloud or GitLab directly to Deployment Plugins. The organisation chooses the approved account, workspace or group while each SSLNexus administrator connects their own identity, preserving individual repository attribution without sharing a personal token.
Pull a plugin into the normal editor, test it against a registered target, then publish the validated plugin.json and YAML playbooks back to the repository. Secret names remain portable; secret values stay inside SSLNexus.
Use built-in integrations where they fit. When your estate includes something specialised, internal or simply less common, add a controlled deployment workflow instead of waiting for a new product-specific connector.
Use the Let’s Encrypt preset, DigiCert ACME with External Account Binding, or another compatible ACME directory without introducing a second certificate lifecycle. For managed HTTP-01 targets, SSLNexus can originate the key, CSR and ACME order on the remote server that actually receives the validation request, then bring the issued material back under central lifecycle management.
Use the production or staging directory with native HTTP-01 validation, including remote-origin issuance for managed targets where validation must occur on the application server.
Use the Directory URL, KID and HMAC secret issued by CertCentral while keeping the existing DigiCert API adapter available.
Connect another compatible HTTPS ACME directory, with optional EAB credentials where the CA requires them.
The default profiles make Nginx and Apache available from Free/Starter, Business adds Windows and IIS, and Enterprise includes the full integration set. Licence Authority 0.16 can apply explicit capability overrides to an organisation.
See The Full Tier Matrix →The default Enterprise profile includes a private ACME directory governed by EAB enrollment policies, DNS and source-network scope, account controls, certificate inventory, revocation and CRL. Read the Internal PKI documentation.