Give approved suppliers access to the certificates they are responsible for - not your certificate authority, not the wider certificate estate, and not the SSLNexus administration plane.
Vendors see only the certificate names delegated to them. They generate their CSR and private key, request issuance, then copy or download the returned certificate without ever receiving your CA credentials or access to the wider estate.


The organisation owns the certificate identity. You prepare the allowed certificate material.
The private key is returned once and is not stored by SSLNexus.
SSLNexus validates the delegated name, network, renewal window and request limits, then sends the CSR directly to the assigned CA.
Issue CertificateRun the Vendor Portal on its own restricted listener and public hostname while keeping the full SSLNexus administrator interface on an internal hostname or network. The vendor-only listener does not serve /admin/ or /api/admin/*.
Publish vendors.example.org through a separate reverse proxy/backend port while the administrator hostname stays private.
Use a Vendor redirect URL so Entra, Okta, Google Workspace or generic OIDC sign-in completes on the vendor hostname.
Vendor key material is delivered once and is not retained by SSLNexus. RSA generation starts at 4096 bits, reducing the sensitive key material held by the control plane.
Restrict a vendor to approved IP addresses or CIDR ranges so possession of an account alone is not enough to reach the portal from an untrusted network.
Certificate names and SANs stay inside the scope assigned by your organisation. Vendors cannot use the portal to request unrelated names.
Each vendor sees only its own support threads. Staff replies stay attached to the selected vendor ticket rather than broadcasting across the vendor estate.
The Vendor Portal is designed for organisations that own certificates for services operated by agencies, SaaS partners, hosting companies, application vendors or other third parties. The organisation keeps certificate authority control and lifecycle visibility while the supplier receives only the work assigned to them.
Keep third-party certificate activity on a dedicated surface rather than creating platform administrator accounts or exposing the broader SSLNexus control plane. Suppliers see the certificates and actions assigned to them, not unrelated certificate inventory.
Externally hosted websites and applications remain part of the same certificate estate, with renewal position visible alongside internally deployed services.
Give suppliers a predictable route for the certificate work assigned to them instead of repeatedly moving certificate material through support tickets and email chains or relying on individual staff to chase completion.
Internal teams can see which certificate belongs to an external service and maintain oversight without having to perform the vendor's application work themselves.
As the number of externally managed services grows, the manual pattern grows with it: issue, export, raise a ticket, find the right contact, send the certificate, chase installation, confirm completion, repeat next year. The Vendor Portal gives that recurring work its own route.
The value is not another login page. It is a controlled boundary between third-party operational work and your certificate infrastructure: no CA credentials, no platform administration and no visibility of unrelated certificates.
Vendor Portal is included with the Enterprise tier, alongside unlimited active certificate capacity, application integrations and the wider SSLNexus orchestration platform.
SSLNexus tracks the handoff independently from certificate issuance: Issued → Retrieved → Installed → Verified → Complete. The portal records retrieval when the vendor opens the issued certificate, installation is confirmed by the vendor, and staff verify and close the handoff. A vendor-notified marker is still available for teams that use a manual notification step.
Stalled handoffs are highlighted for attention, reminders can be sent from SSLNexus, and every transition is retained in Activity & audit.