Customer Authority Federation
MSPs can manage certificate lifecycles for customers that keep their CA and DNS credentials within their own infrastructure.
- Nexus-to-Nexus uses the customer’s existing Client Server; Customer Relay provides the same authority channel for customers without SSLNexus.
- Customer-specific pairing invitations are single-use and valid for 24 hours, with a copy control for sharing the full invitation.
- Issuance and renewal requests use the selected customer channel and profile. Returned certificates continue through deployment, verification and renewal scheduling.
- Pending requests retain their CSR across restarts, and failed deployment recovery reuses the issued certificate.
- External MSPs provides customer-side pairing and provider controls.
Customer Control
The customer approves local connector and policy settings before activating a channel. Each provider can be paused independently. Customer CA and DNS credentials remain local.
Upgrade
Use the native Linux package upgrade procedure and preserve a current backup. Review customer policy and listener connectivity before routing production targets through a new channel.

