Vendor Portal

Delegate The Work. Keep The Control.

Give approved suppliers access to the certificates they are responsible for - not your certificate authority, not the wider certificate estate, and not the SSLNexus administration plane.

Controlled third-party certificate workflow
↗
External VendorWorks only with the certificate activity assigned to them.
→
◆
SSLNexus Vendor PortalProvides the hand-off point while keeping lifecycle visibility centralised.
→
✓
Internal TeamRetains oversight of the certificate estate and renewal position.
Less chasingReduce repeated renewal follow-ups.
Cleaner hand-offSeparate vendor activity from administration.
One estateExternally hosted services stay visible.
The Operational Gap

Delegated Certificate Management For Services You Do Not Operate Yourself.

01Renewal Ownership Gets BlurredIT owns the certificate, the vendor owns the application, and expiry dates end up being managed through email.
02Support Becomes The WorkflowTeams spend time raising tickets, chasing confirmation and resending certificate material instead of managing the lifecycle.
03Visibility Disappears After Hand-OffOnce a certificate leaves the internal team, its deployment status can become disconnected from the rest of the estate.
The Vendor Experience

A Focused Certificate Workspace, Not A Cut-Down Administrator Console.

Vendors see only the certificate names delegated to them. They generate their CSR and private key, request issuance, then copy or download the returned certificate without ever receiving your CA credentials or access to the wider estate.

Immediate Issuance After Policy ChecksApproved names go directly to the CA adapter once source-network, renewal-window and request-limit controls pass. There is no administrator approval queue.
Vendor Private Keys Are Not RetainedSSLNexus generates the vendor key material for one-time delivery, enforces a 4096-bit RSA minimum and does not retain the private key in its application state after it is shown.
Network Perimeter Can Be RestrictedVendor access can be limited to approved source IP addresses or CIDR ranges, adding a network boundary even if a vendor credential is exposed.
Certificate Scope Is Hard-LimitedVendors can request only delegated certificate names and SANs inside their assigned scope. Out-of-scope names are rejected before the request reaches the CA.
Handoff Remains Visible InternallyIssued, retrieved, installed and verified states remain part of the organisation's certificate lifecycle and audit trail.
One Active Certificate Per NameA replacement cannot be issued while a valid certificate is active. The vendor revokes the old certificate first; revoked and expired history stays available.
Built-In Support ChannelVendors can open a threaded support ticket from the portal. Organisation administrators are notified by email and handle the conversation from Vendor access.
vendors.example.org/vendor/
☀ Light mode☾ Dark mode[email protected] · 203.0.113.24
1 · Sign InUse your assigned credential and approved network.
2 · GenerateSave your one-time CSR and private key.
3 · Issue & copyCopy the certificate as soon as the CA returns it.
How To Request Your Certificate
  1. Select the assigned certificate name.
  2. Generate CSR and private key.
  3. Save both immediately.
  4. Request issuance.
  5. Copy/download the returned certificate.
  6. Revoke an active certificate before replacing it.

Approved Certificate

The organisation owns the certificate identity. You prepare the allowed certificate material.

test.example.com ▾
test.example.com
test.example.com, www.test.example.com, web-stage.test.example.com
Each SAN must end with the assigned certificate name.
4096 bits · default ▾
30 days before expiry
Generate CSR And Private Key
CSR and private key generated. Save both before continuing.

Private Key Handling

The private key is returned once and is not stored by SSLNexus.

-----BEGIN CERTIFICATE REQUEST-----
MIIC...vendor-request...
-----END CERTIFICATE REQUEST-----
Copy CSRDownload CSR
-----BEGIN PRIVATE KEY-----
MIIJ...shown-once...
-----END PRIVATE KEY-----
Copy Private KeyDownload Private Key
Issue certificate

SSLNexus validates the delegated name, network, renewal window and request limits, then sends the CSR directly to the assigned CA.

Issue Certificate
● Vendor portal connected
Public Vendor Edge

Expose The Vendor Experience Without Exposing The Admin Control Plane.

Run the Vendor Portal on its own restricted listener and public hostname while keeping the full SSLNexus administrator interface on an internal hostname or network. The vendor-only listener does not serve /admin/ or /api/admin/*.

01 · PUBLIC

Dedicated Vendor Hostname

Publish vendors.example.org through a separate reverse proxy/backend port while the administrator hostname stays private.

02 · SSO

Independent OIDC Callback

Use a Vendor redirect URL so Entra, Okta, Google Workspace or generic OIDC sign-in completes on the vendor hostname.

03 · KEY SAFETY

Private-Key Non-Retention

Vendor key material is delivered once and is not retained by SSLNexus. RSA generation starts at 4096 bits, reducing the sensitive key material held by the control plane.

04 · PERIMETER

Source-Network Allowlisting

Restrict a vendor to approved IP addresses or CIDR ranges so possession of an account alone is not enough to reach the portal from an untrusted network.

05 · SCOPE

Delegated Names Stay Locked

Certificate names and SANs stay inside the scope assigned by your organisation. Vendors cannot use the portal to request unrelated names.

06 · ISOLATED SUPPORT

Private Ticket Threads

Each vendor sees only its own support threads. Staff replies stay attached to the selected vendor ticket rather than broadcasting across the vendor estate.

Built For The Hand-Off

Keep Ownership Internal While The Supplier Performs The Application Work.

The Vendor Portal is designed for organisations that own certificates for services operated by agencies, SaaS partners, hosting companies, application vendors or other third parties. The organisation keeps certificate authority control and lifecycle visibility while the supplier receives only the work assigned to them.

01 · SEPARATION

Supplier-Specific Access

Keep third-party certificate activity on a dedicated surface rather than creating platform administrator accounts or exposing the broader SSLNexus control plane. Suppliers see the certificates and actions assigned to them, not unrelated certificate inventory.

02 · CONTINUITY

Keep External Certificates Inside The Same Lifecycle

Externally hosted websites and applications remain part of the same certificate estate, with renewal position visible alongside internally deployed services.

03 · HAND-OFF

Replace Ticket-And-Email Handoffs With A Defined Workflow

Give suppliers a predictable route for the certificate work assigned to them instead of repeatedly moving certificate material through support tickets and email chains or relying on individual staff to chase completion.

04 · ACCOUNTABILITY

Make Ownership Clearer Across Teams

Internal teams can see which certificate belongs to an external service and maintain oversight without having to perform the vendor's application work themselves.

Reduce Support Load

Stop Making The Service Desk The Certificate Courier.

As the number of externally managed services grows, the manual pattern grows with it: issue, export, raise a ticket, find the right contact, send the certificate, chase installation, confirm completion, repeat next year. The Vendor Portal gives that recurring work its own route.

  • Fewer certificate hand-off tickets
  • Less time spent finding the right external contact
  • Less repeated explanation of what needs to be installed
  • Less dependence on individual staff remembering renewal dates
  • Clearer separation between internal administration and vendor work
Without Vendor Portal
With Vendor Portal
Expiry alert reaches internal IT
Support ticket raised with vendor
Certificate material exchanged manually
IT chases installation confirmation
Status lives across inboxes and tickets
Certificate remains visible in SSLNexus
Vendor works through the dedicated portal
Third-party activity stays separated
Internal team retains lifecycle oversight
Externally hosted services remain in one estate
Control Without Friction

Give Suppliers Only The Surface They Need.

The value is not another login page. It is a controlled boundary between third-party operational work and your certificate infrastructure: no CA credentials, no platform administration and no visibility of unrelated certificates.

Separated Vendor ExperienceExternal users do not need the same interface or privileges as SSLNexus administrators.
Central Lifecycle VisibilityVendor-managed certificate work remains visible to the internal team rather than disappearing into a separate process.
Scales With External ServicesThe workflow becomes more valuable as the organisation accumulates agencies, hosted applications and third-party platforms.
Supports Operational HandoverA defined portal reduces dependence on named individuals and undocumented email-based processes.
Enterprise

Built For Certificate Estates That Cross Organisational Boundaries.

Vendor Portal is included with the Enterprise tier, alongside unlimited active certificate capacity, application integrations and the wider SSLNexus orchestration platform.

See Pricing →
Lifecycle Visibility

See Exactly Where Every Vendor Handoff Stands

SSLNexus tracks the handoff independently from certificate issuance: Issued → Retrieved → Installed → Verified → Complete. The portal records retrieval when the vendor opens the issued certificate, installation is confirmed by the vendor, and staff verify and close the handoff. A vendor-notified marker is still available for teams that use a manual notification step.

Stalled handoffs are highlighted for attention, reminders can be sent from SSLNexus, and every transition is retained in Activity & audit.