Skip to content

Technical Architecture

SSL-CLM v2 is built on a modular, service-oriented architecture designed for scalability, extensibility, and secure enterprise deployment.


SSL-CLM consists of five primary layers:

  1. Web Interface (Angular) — Centralized management UI with role-based access
  2. Core API Services (Spring Boot) — Certificate lifecycle orchestration, policy enforcement, and workflow management
  3. Integration Layer (SPI Model) — Pluggable CA, store, discovery, and DNS connectors loaded dynamically via integration schemas
  4. ACME Server — Built-in RFC 8555 compliant ACME server for internal PKI automation
  5. Agent Layer — Secure distributed execution on managed hosts via mTLS

┌─────────────────────────────────────────────────────────────────┐
│ Web UI (Angular + PrimeNG) │
│ Dashboard │ Certificates │ Discovery │ Settings │
└────────────────────────────────┬────────────────────────────────┘
│ HTTPS / REST API
┌────────────────────────────────▼────────────────────────────────┐
│ API Gateway (Spring Boot 3.x) │
│ │
│ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ │
│ │ Certificate │ │ Discovery │ │ Enrollment/Renewal │ │
│ │ Service │ │ Engine │ │ Engine │ │
│ └──────────────┘ └──────────────┘ └──────────────────────┘ │
│ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ │
│ │ Policy │ │ ACME │ │ Deployment │ │
│ │ Engine │ │ Server │ │ Orchestrator │ │
│ └──────────────┘ └──────────────┘ └──────────────────────┘ │
│ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ │
│ │ Audit │ │ Scheduler │ │ Reporting │ │
│ │ Service │ │ Service │ │ Service │ │
│ └──────────────┘ └──────────────┘ └──────────────────────┘ │
│ ┌──────────────┐ ┌──────────────┐ ┌──────────────────────┐ │
│ │ Auth/RBAC │ │ Agent │ │ Notification │ │
│ │ Service │ │ Manager │ │ Service │ │
│ └──────────────┘ └──────────────┘ └──────────────────────┘ │
└────────────────────────────────┬────────────────────────────────┘
│
┌────────────────────────────────▼────────────────────────────────┐
│ SPI Integration Layer │
│ │
│ ┌────────────────┐ ┌────────────────┐ ┌─────────────────┐ │
│ │ CA Gateway │ │ Store Gateway │ │ DNS Provider │ │
│ │ SPI │ │ SPI │ │ SPI │ │
│ └────────────────┘ └────────────────┘ └─────────────────┘ │
│ │
│ Integration Schema Registry (dynamic config per type) │
└──┬──────────────────────┬──────────────────────┬────────────────┘
│ │ │
┌──▼────────────┐ ┌──────▼────────┐ ┌─────────▼──────────┐
│ CA Backends │ │ Store Targets │ │ DNS Providers │
│ │ │ │ │ │
│ • MS AD CS │ │ • NGINX │ │ • Cloudflare │
│ • Smallstep │ │ • Apache │ │ • AWS Route53 │
│ • ACME/LE │ │ • IIS │ │ • Azure DNS │
│ • EJBCA │ │ • F5 BIG-IP │ │ • Hostinger │
│ • AWS PCA │ │ • JKS │ │ │
│ • Google CAS │ │ • AWS ACM │ │ │
│ │ │ • Azure KV │ │ │
└──────────────┘ └───────────────┘ └────────────────────┘
│ │
┌──▼──────────────────────▼───────────────────────────────────────┐
│ Agent Framework │
│ │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ Agent (Java) — mTLS — Pull-based Job Execution │ │
│ │ Capabilities: CA_REFRESH, ISSUE_CERT, REVOKE_CERT, │ │
│ │ DEPLOY_CERT, DISCOVER_STORE, BIND_CERT │ │
│ └─────────────────────────────────────────────────────────┘ │
└──────────────────────────────────────────────────────────────────┘
│
┌────────────────────────────────▼────────────────────────────────┐
│ Database (MongoDB 7+) │
│ │
│ Collections: certificates, authorities, stores, agents, │
│ policies, acme_profiles, discovery_scans, jobs, audit_logs, │
│ users, roles, teams, tenants, alerts, dns_providers │
└──────────────────────────────────────────────────────────────────┘

ServiceResponsibility
Certificate ServiceInventory management, lifecycle state machine, tier management (Managed/Monitored)
Enrollment/Renewal EngineCSR generation, CA submission, certificate issuance, automated renewal orchestration
Discovery EngineNetwork scanning, store discovery, CA inventory sync, correlation & reconciliation
Deployment OrchestratorCertificate push to stores, binding, validation, rollback
Policy EngineIssuance & deployment policy evaluation, approval workflows, constraint enforcement
ACME ServerBuilt-in RFC 8555 server, challenge validation, EAB support, profile management
Scheduler ServiceRenewal scheduling, discovery cron jobs, CA refresh intervals, heartbeat monitoring
Auth/RBAC ServiceAuthentication (local + SSO/OIDC), role-based permission enforcement, team scoping
Audit ServiceImmutable event logging, actor tracking, entity correlation
Agent ManagerAgent registration, mTLS bootstrap, heartbeat monitoring, job dispatch
Notification ServiceEmail alerts, in-app notifications, webhook delivery
Reporting ServiceOn-demand and scheduled report generation

All services are stateless and horizontally scalable.


SSL-CLM v2 uses a Service Provider Interface (SPI) framework with dynamic integration schemas. Each integration type (CA, Store, DNS Provider) declares:

  • A type identifier (e.g., MSCA, store-filebased-nginx, CLOUDFLARE)
  • A config schema — JSON schema defining the fields needed to configure the integration
  • A runtime — Where execution happens: AGENT (on remote host), BACKEND (on platform), or BOTH
  • Capabilities — What operations the integration supports

The platform loads schemas from /api/integration-schemas/{category}/{type} and renders dynamic configuration forms in the UI.

Type IDDisplay NameRuntimeAgent Required
MSCAMicrosoft CA (AD CS)Agent✓
STEPCASmallstep CABackend—
ACMELet’s Encrypt / ACMEBackend—
EJBCAEJBCABackend—
ACMPCAAWS Private CABackend—
GOOGLE_CASGoogle Cloud CASBackend—
Type IDDisplay NameCategoryRuntime
store-filebased-nginxNGINXFile-BasedAgent
store-filebased-jksJKSFile-BasedAgent
store-applicationserver-apacheApacheApplication ServerAgent
store-applicationserver-iisIISApplication ServerAgent
store-applicationserver-f5bigipF5 BIG-IPApplication ServerBackend
store-cloud-aws-acmAWS ACMCloudBackend
store-cloud-azure-keyvault-secretAzure Key VaultCloudBackend
TypeDisplay Name
CLOUDFLARECloudflare
AWS_ROUTE53AWS Route 53
AZURE_DNSAzure DNS
HOSTINGERHostinger

SSL-CLM agents are lightweight Java processes deployed on remote hosts.

  • Pull-based — Agents poll the platform for jobs; no inbound ports required
  • mTLS — Mutual TLS with platform-issued client certificates
  • Bootstrap — One-time token for initial registration, then certificate-based auth
  • Heartbeat — Periodic health reporting (default: 30s)
BOOTSTRAPPING → ONLINE → (OFFLINE) → (DISABLED) → (EXPIRED) → (SAFE_MODE)
StatusMeaning
BOOTSTRAPPINGRegistration in progress
ONLINEConnected and healthy
OFFLINENo recent heartbeat
DISABLEDManually disabled by admin
EXPIREDAgent mTLS certificate expired
SAFE_MODERestricted operation (auth failure)
Job TypeDescription
CA_REFRESHSync certificate inventory from CA
ISSUE_CERTSubmit CSR to CA and retrieve issued certificate
REVOKE_CERTRevoke certificate on CA
DEPLOY_CERTDeploy certificate to store
DISCOVER_STOREScan local store for certificates
BIND_CERTBind certificate to service endpoint

The Policy Engine evaluates rules at key lifecycle points:

Evaluated during certificate creation:

  • Minimum key size enforcement
  • Allowed key algorithms (RSA, ECDSA, Ed25519)
  • Maximum validity period
  • SAN pattern matching (required/forbidden)
  • Maximum SAN count
  • CA scope restrictions
  • Approval workflow triggers

Evaluated during certificate deployment:

  • Maintenance window enforcement
  • Maximum concurrent deployments
  • Auto-backup before deployment
  • Auto-validation after deployment
  • Store and CA scope restrictions
  • Approval workflow triggers

SSL-CLM v2 includes a built-in ACME server (RFC 8555) that allows standard ACME clients to request certificates from your internal CAs.

Features:

  • Multiple ACME profiles (Production, Staging, Development)
  • Trust models: PUBLIC_PKI, PRIVATE_PKI, HYBRID
  • Validation modes: POLICY, DNS-01, HTTP-01
  • External Account Binding (EAB) support
  • Per-profile key type and size restrictions
  • Auto-renewal control

  • Local username/password with JWT tokens
  • SSO via OIDC (Microsoft Entra ID, Google Workspace, Okta, Generic OIDC)
  • JIT (Just-In-Time) user provisioning on first SSO login

15 resource types with 48+ granular permissions:

ResourcePermissions
Certificatesread, issue, revoke, deploy, renew, approve, export-key
Certificate Authoritiesread, create, delete, discover
Certificate Storesread, create, delete, deploy
Agentsread, register, disable
Discoveryread, run, configure
Policiesread, create, delete
Reportsread, create, run
Usersread, create, delete, assign-role
Teamsread, create, edit, delete
Alertsread, acknowledge
Auditread
Settingsread, edit
ACMEread, configure
DNSread, configure
Jobsread, manage

SSL-CLM v2 supports multi-tenant operation:

  • Platform-level admin for tenant management
  • Tenant isolation for certificates, CAs, stores, and agents
  • Per-tenant license quotas
  • Tenant-scoped roles and teams

Full internal deployment within enterprise infrastructure. Single JAR deployment with MongoDB.

Deployed in AWS, Azure, or GCP with managed scaling and container orchestration.

Cloud control plane with on-premise agents for local CA and store access.

Fully managed service operated by QCecuring.


  • Stateless API nodes behind load balancers
  • Horizontal scaling support
  • MongoDB replica-set architecture
  • Asynchronous job processing with retry logic
  • Configurable scheduler intervals
  • Agent failover and re-bootstrap

Designed for environments managing thousands to millions of certificates.


  • End-to-end TLS encryption
  • mTLS for agent communication
  • Role-based access control with granular permissions
  • Immutable audit logging
  • Policy-driven cryptographic governance
  • Secure secret handling (vault-backed credential storage)
  • One-time bootstrap tokens for agent registration
  • JWT with configurable expiration
  • SSO/OIDC integration

LayerTechnology
FrontendAngular 18+, PrimeNG, TypeScript
BackendSpring Boot 3.x, Java 21
DatabaseMongoDB 7+
AgentSpring Boot (lightweight), Java 21
SecuritySpring Security, JWT, mTLS, OIDC
ProtocolsACME (RFC 8555)
DeploymentDocker, systemd, Windows Service