Technical Architecture
SSL-CLM Technical Architecture
Section titled “SSL-CLM Technical Architecture”SSL-CLM v2 is built on a modular, service-oriented architecture designed for scalability, extensibility, and secure enterprise deployment.
Architecture Overview
Section titled “Architecture Overview”SSL-CLM consists of five primary layers:
- Web Interface (Angular) — Centralized management UI with role-based access
- Core API Services (Spring Boot) — Certificate lifecycle orchestration, policy enforcement, and workflow management
- Integration Layer (SPI Model) — Pluggable CA, store, discovery, and DNS connectors loaded dynamically via integration schemas
- ACME Server — Built-in RFC 8555 compliant ACME server for internal PKI automation
- Agent Layer — Secure distributed execution on managed hosts via mTLS
System Architecture Diagram
Section titled “System Architecture Diagram”┌─────────────────────────────────────────────────────────────────┐│ Web UI (Angular + PrimeNG) ││ Dashboard │ Certificates │ Discovery │ Settings │└────────────────────────────────┬────────────────────────────────┘ │ HTTPS / REST API┌────────────────────────────────▼────────────────────────────────┐│ API Gateway (Spring Boot 3.x) ││ ││ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ ││ │ Certificate │ │ Discovery │ │ Enrollment/Renewal │ ││ │ Service │ │ Engine │ │ Engine │ ││ └──────────────┘ └──────────────┘ └──────────────────────┘ ││ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ ││ │ Policy │ │ ACME │ │ Deployment │ ││ │ Engine │ │ Server │ │ Orchestrator │ ││ └──────────────┘ └──────────────┘ └──────────────────────┘ ││ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ ││ │ Audit │ │ Scheduler │ │ Reporting │ ││ │ Service │ │ Service │ │ Service │ ││ └──────────────┘ └──────────────┘ └──────────────────────┘ ││ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ ││ │ Auth/RBAC │ │ Agent │ │ Notification │ ││ │ Service │ │ Manager │ │ Service │ ││ └──────────────┘ └──────────────┘ └──────────────────────┘ │└────────────────────────────────┬────────────────────────────────┘ │┌────────────────────────────────▼────────────────────────────────┐│ SPI Integration Layer ││ ││ ┌────────────────┐ ┌────────────────┐ ┌─────────────────┐ ││ │ CA Gateway │ │ Store Gateway │ │ DNS Provider │ ││ │ SPI │ │ SPI │ │ SPI │ ││ └────────────────┘ └────────────────┘ └─────────────────┘ ││ ││ Integration Schema Registry (dynamic config per type) │└──┬──────────────────────┬──────────────────────┬────────────────┘ │ │ │┌──▼────────────┐ ┌──────▼────────┐ ┌─────────▼──────────┐│ CA Backends │ │ Store Targets │ │ DNS Providers ││ │ │ │ │ ││ • MS AD CS │ │ • NGINX │ │ • Cloudflare ││ • Smallstep │ │ • Apache │ │ • AWS Route53 ││ • ACME/LE │ │ • IIS │ │ • Azure DNS ││ • EJBCA │ │ • F5 BIG-IP │ │ • Hostinger ││ • AWS PCA │ │ • JKS │ │ ││ • Google CAS │ │ • AWS ACM │ │ ││ │ │ • Azure KV │ │ │└──────────────┘ └───────────────┘ └────────────────────┘ │ │┌──▼──────────────────────▼───────────────────────────────────────┐│ Agent Framework ││ ││ ┌─────────────────────────────────────────────────────────┐ ││ │ Agent (Java) — mTLS — Pull-based Job Execution │ ││ │ Capabilities: CA_REFRESH, ISSUE_CERT, REVOKE_CERT, │ ││ │ DEPLOY_CERT, DISCOVER_STORE, BIND_CERT │ ││ └─────────────────────────────────────────────────────────┘ │└──────────────────────────────────────────────────────────────────┘ │┌────────────────────────────────▼────────────────────────────────┐│ Database (MongoDB 7+) ││ ││ Collections: certificates, authorities, stores, agents, ││ policies, acme_profiles, discovery_scans, jobs, audit_logs, ││ users, roles, teams, tenants, alerts, dns_providers │└──────────────────────────────────────────────────────────────────┘Core Platform Services
Section titled “Core Platform Services”| Service | Responsibility |
|---|---|
| Certificate Service | Inventory management, lifecycle state machine, tier management (Managed/Monitored) |
| Enrollment/Renewal Engine | CSR generation, CA submission, certificate issuance, automated renewal orchestration |
| Discovery Engine | Network scanning, store discovery, CA inventory sync, correlation & reconciliation |
| Deployment Orchestrator | Certificate push to stores, binding, validation, rollback |
| Policy Engine | Issuance & deployment policy evaluation, approval workflows, constraint enforcement |
| ACME Server | Built-in RFC 8555 server, challenge validation, EAB support, profile management |
| Scheduler Service | Renewal scheduling, discovery cron jobs, CA refresh intervals, heartbeat monitoring |
| Auth/RBAC Service | Authentication (local + SSO/OIDC), role-based permission enforcement, team scoping |
| Audit Service | Immutable event logging, actor tracking, entity correlation |
| Agent Manager | Agent registration, mTLS bootstrap, heartbeat monitoring, job dispatch |
| Notification Service | Email alerts, in-app notifications, webhook delivery |
| Reporting Service | On-demand and scheduled report generation |
All services are stateless and horizontally scalable.
Integration Model (SPI-Based)
Section titled “Integration Model (SPI-Based)”SSL-CLM v2 uses a Service Provider Interface (SPI) framework with dynamic integration schemas. Each integration type (CA, Store, DNS Provider) declares:
- A type identifier (e.g.,
MSCA,store-filebased-nginx,CLOUDFLARE) - A config schema — JSON schema defining the fields needed to configure the integration
- A runtime — Where execution happens:
AGENT(on remote host),BACKEND(on platform), orBOTH - Capabilities — What operations the integration supports
The platform loads schemas from /api/integration-schemas/{category}/{type} and renders dynamic configuration forms in the UI.
Certificate Authorities
Section titled “Certificate Authorities”| Type ID | Display Name | Runtime | Agent Required |
|---|---|---|---|
MSCA | Microsoft CA (AD CS) | Agent | ✓ |
STEPCA | Smallstep CA | Backend | — |
ACME | Let’s Encrypt / ACME | Backend | — |
EJBCA | EJBCA | Backend | — |
ACMPCA | AWS Private CA | Backend | — |
GOOGLE_CAS | Google Cloud CAS | Backend | — |
Certificate Stores
Section titled “Certificate Stores”| Type ID | Display Name | Category | Runtime |
|---|---|---|---|
store-filebased-nginx | NGINX | File-Based | Agent |
store-filebased-jks | JKS | File-Based | Agent |
store-applicationserver-apache | Apache | Application Server | Agent |
store-applicationserver-iis | IIS | Application Server | Agent |
store-applicationserver-f5bigip | F5 BIG-IP | Application Server | Backend |
store-cloud-aws-acm | AWS ACM | Cloud | Backend |
store-cloud-azure-keyvault-secret | Azure Key Vault | Cloud | Backend |
DNS Providers
Section titled “DNS Providers”| Type | Display Name |
|---|---|
CLOUDFLARE | Cloudflare |
AWS_ROUTE53 | AWS Route 53 |
AZURE_DNS | Azure DNS |
HOSTINGER | Hostinger |
Agent Architecture
Section titled “Agent Architecture”SSL-CLM agents are lightweight Java processes deployed on remote hosts.
Communication Model
Section titled “Communication Model”- Pull-based — Agents poll the platform for jobs; no inbound ports required
- mTLS — Mutual TLS with platform-issued client certificates
- Bootstrap — One-time token for initial registration, then certificate-based auth
- Heartbeat — Periodic health reporting (default: 30s)
Agent Lifecycle
Section titled “Agent Lifecycle”BOOTSTRAPPING → ONLINE → (OFFLINE) → (DISABLED) → (EXPIRED) → (SAFE_MODE)| Status | Meaning |
|---|---|
| BOOTSTRAPPING | Registration in progress |
| ONLINE | Connected and healthy |
| OFFLINE | No recent heartbeat |
| DISABLED | Manually disabled by admin |
| EXPIRED | Agent mTLS certificate expired |
| SAFE_MODE | Restricted operation (auth failure) |
Supported Job Types
Section titled “Supported Job Types”| Job Type | Description |
|---|---|
CA_REFRESH | Sync certificate inventory from CA |
ISSUE_CERT | Submit CSR to CA and retrieve issued certificate |
REVOKE_CERT | Revoke certificate on CA |
DEPLOY_CERT | Deploy certificate to store |
DISCOVER_STORE | Scan local store for certificates |
BIND_CERT | Bind certificate to service endpoint |
Policy Engine
Section titled “Policy Engine”The Policy Engine evaluates rules at key lifecycle points:
Issuance Policies
Section titled “Issuance Policies”Evaluated during certificate creation:
- Minimum key size enforcement
- Allowed key algorithms (RSA, ECDSA, Ed25519)
- Maximum validity period
- SAN pattern matching (required/forbidden)
- Maximum SAN count
- CA scope restrictions
- Approval workflow triggers
Deployment Policies
Section titled “Deployment Policies”Evaluated during certificate deployment:
- Maintenance window enforcement
- Maximum concurrent deployments
- Auto-backup before deployment
- Auto-validation after deployment
- Store and CA scope restrictions
- Approval workflow triggers
ACME Server
Section titled “ACME Server”SSL-CLM v2 includes a built-in ACME server (RFC 8555) that allows standard ACME clients to request certificates from your internal CAs.
Features:
- Multiple ACME profiles (Production, Staging, Development)
- Trust models: PUBLIC_PKI, PRIVATE_PKI, HYBRID
- Validation modes: POLICY, DNS-01, HTTP-01
- External Account Binding (EAB) support
- Per-profile key type and size restrictions
- Auto-renewal control
Authentication & Authorization
Section titled “Authentication & Authorization”Authentication Methods
Section titled “Authentication Methods”- Local username/password with JWT tokens
- SSO via OIDC (Microsoft Entra ID, Google Workspace, Okta, Generic OIDC)
- JIT (Just-In-Time) user provisioning on first SSO login
RBAC Model
Section titled “RBAC Model”15 resource types with 48+ granular permissions:
| Resource | Permissions |
|---|---|
| Certificates | read, issue, revoke, deploy, renew, approve, export-key |
| Certificate Authorities | read, create, delete, discover |
| Certificate Stores | read, create, delete, deploy |
| Agents | read, register, disable |
| Discovery | read, run, configure |
| Policies | read, create, delete |
| Reports | read, create, run |
| Users | read, create, delete, assign-role |
| Teams | read, create, edit, delete |
| Alerts | read, acknowledge |
| Audit | read |
| Settings | read, edit |
| ACME | read, configure |
| DNS | read, configure |
| Jobs | read, manage |
Multi-Tenancy
Section titled “Multi-Tenancy”SSL-CLM v2 supports multi-tenant operation:
- Platform-level admin for tenant management
- Tenant isolation for certificates, CAs, stores, and agents
- Per-tenant license quotas
- Tenant-scoped roles and teams
Deployment Models
Section titled “Deployment Models”On-Premise
Section titled “On-Premise”Full internal deployment within enterprise infrastructure. Single JAR deployment with MongoDB.
Cloud-Hosted
Section titled “Cloud-Hosted”Deployed in AWS, Azure, or GCP with managed scaling and container orchestration.
Hybrid
Section titled “Hybrid”Cloud control plane with on-premise agents for local CA and store access.
Fully managed service operated by QCecuring.
Scalability & Resilience
Section titled “Scalability & Resilience”- Stateless API nodes behind load balancers
- Horizontal scaling support
- MongoDB replica-set architecture
- Asynchronous job processing with retry logic
- Configurable scheduler intervals
- Agent failover and re-bootstrap
Designed for environments managing thousands to millions of certificates.
Security Principles
Section titled “Security Principles”- End-to-end TLS encryption
- mTLS for agent communication
- Role-based access control with granular permissions
- Immutable audit logging
- Policy-driven cryptographic governance
- Secure secret handling (vault-backed credential storage)
- One-time bootstrap tokens for agent registration
- JWT with configurable expiration
- SSO/OIDC integration
Technology Stack
Section titled “Technology Stack”| Layer | Technology |
|---|---|
| Frontend | Angular 18+, PrimeNG, TypeScript |
| Backend | Spring Boot 3.x, Java 21 |
| Database | MongoDB 7+ |
| Agent | Spring Boot (lightweight), Java 21 |
| Security | Spring Security, JWT, mTLS, OIDC |
| Protocols | ACME (RFC 8555) |
| Deployment | Docker, systemd, Windows Service |