Home / Solutions / Delegation
Delegation

Vendor Certificate Portal for Controlled Third-Party Requests

Let approved third parties request and manage the certificates they are responsible for without giving them access to the main SSLNexus administration plane.

The operational problem

Make the certificate workflow match the estate you actually run.

Vendors often need certificates for systems they operate on behalf of an organisation. Emailing CSRs, private keys or renewal reminders between teams creates unnecessary risk and delay. A dedicated workflow keeps vendor access separate and auditable.

Separate portal

Vendor identities use a dedicated portal rather than the administrator UI.

Scoped access

Restrict vendors by domain and approved source ranges.

Local keys

CSR key generation occurs in the vendor browser so the private key does not enter SSLNexus infrastructure.

Workflow

From visibility to a repeatable operating process.

01Register the vendor organisation/contact
02Define approved domains and source ranges
03Vendor signs in with its own account and MFA controls
04Generate a key and CSR locally in the browser or submit a CSR
05Request the certificate within approved scope
06Track lifecycle and audit activity separately from administrators
Why SSLNexus

Customer-controlled certificate operations.

SSLNexus is installed into customer infrastructure and is designed to keep certificate operations, target access and private-key custody under customer control. The platform coordinates lifecycle work without requiring the estate to be rebuilt around a vendor-hosted key store.

  • Provider-neutral certificate lifecycle management.
  • Private keys remain inside customer-controlled infrastructure.
  • Delegated operational roles instead of one all-powerful administrator model.
  • Audit history, reports and verification stay attached to the certificate lifecycle.
Questions

Common questions

Can a vendor see the Client Server admin dashboard?

No. Vendor Portal authentication and capabilities are separated from Client Server administration.

Does SSLNexus generate the vendor private key on the server?

No. Browser-local generation keeps the private key out of the Client Server API.

Can vendor access be offboarded?

Vendor registry and organisation mapping are designed to support controlled onboarding and offboarding.

Related

Go deeper