Home / Solutions / Security architecture
Security architecture

Certificate Automation With Private Keys Kept Inside Your Infrastructure

Certificate automation should not require transferring private-key custody to the software vendor. SSLNexus is designed around customer-controlled key boundaries.

The operational problem

Make the certificate workflow match the estate you actually run.

Private keys are the identity material behind TLS. For many organisations, especially regulated, education and enterprise environments, moving those keys into a vendor-operated SaaS service creates an architectural and assurance burden that is avoidable.

Customer boundary

Private keys stay within customer-controlled infrastructure.

Local generation

Vendor Portal CSR generation happens locally in the browser.

Controlled destinations

Customer-owned vaults and secret stores can remain part of the lifecycle.

Workflow

From visibility to a repeatable operating process.

01Generate or retain key material inside the customer boundary
02Send certificate requests rather than exporting unnecessary key custody
03Issue through the configured CA
04Deploy to customer-controlled targets
05Publish to customer-controlled secret destinations when required
06Verify the deployed certificate without centralising key custody
Why SSLNexus

Customer-controlled certificate operations.

SSLNexus is installed into customer infrastructure and is designed to keep certificate operations, target access and private-key custody under customer control. The platform coordinates lifecycle work without requiring the estate to be rebuilt around a vendor-hosted key store.

  • Provider-neutral certificate lifecycle management.
  • Private keys remain inside customer-controlled infrastructure.
  • Delegated operational roles instead of one all-powerful administrator model.
  • Audit history, reports and verification stay attached to the certificate lifecycle.
Questions

Common questions

Does SSLNexus store customer private keys in a hosted SaaS service?

No. The product policy explicitly prohibits SSLNexus-operated SaaS custody of customer private keys.

Can a customer-owned cloud vault be used?

Yes. A customer-controlled vault or secret destination can be part of the customer infrastructure boundary.

How does the Vendor Portal create CSRs?

The browser generates the key pair locally and submits the CSR. The private key is not returned from the Client Server.

Related

Go deeper