Home / Solutions / Architecture
Architecture

Agentless Certificate Management for Server and Network Estates

Keep managed targets free from another resident certificate agent when existing administrative paths can perform the deployment safely.

The operational problem

Make the certificate workflow match the estate you actually run.

Installing and maintaining another agent across every server can become its own lifecycle problem. SSLNexus is designed to use established management paths for many targets, centralising orchestration while leaving the managed host clean.

SSH

Manage supported Linux targets through controlled SSH access.

WinRM

Manage supported Windows targets through WinRM.

Automation

Use the existing orchestration layer for repeatable deployment actions.

Workflow

From visibility to a repeatable operating process.

01Register the target and administrative access method
02Test connectivity and prerequisites
03Associate the target with managed certificates
04Run the deployment through the central workflow
05Reload/rebind the application as required
06Verify the application is serving the replacement certificate
Why SSLNexus

Customer-controlled certificate operations.

SSLNexus is installed into customer infrastructure and is designed to keep certificate operations, target access and private-key custody under customer control. The platform coordinates lifecycle work without requiring the estate to be rebuilt around a vendor-hosted key store.

  • Provider-neutral certificate lifecycle management.
  • Private keys remain inside customer-controlled infrastructure.
  • Delegated operational roles instead of one all-powerful administrator model.
  • Audit history, reports and verification stay attached to the certificate lifecycle.
Questions

Common questions

Does agentless mean no credentials are required?

No. The control plane still needs an authorised management path to the target. Agentless refers to avoiding a permanent SSLNexus process on every managed host.

Can this cross network segments?

It depends on the management paths permitted by your network design. SSLNexus is intended to operate within customer-controlled routing and segmentation rather than bypass it.

What if a target cannot be managed through the standard paths?

Custom deployment plugins can cover applications that need a different deployment procedure.

Related

Go deeper