Skip to content

Cloud Store Integrations

SSL-CLM supports agentless certificate deployment to cloud key management services. The platform connects directly via cloud provider APIs — no agent installation required on cloud infrastructure.


StoreType IDCloud ProviderAuthenticationCertificate Format
AWS Certificate Managerstore-cloud-aws-acmAWSIAM Access KeysPEM (cert + chain + key)
Azure Key Vaultstore-cloud-azure-keyvault-secretAzureService Principal (Client Credentials)PEM or PFX

SSL-CLM Platform (Backend)
│
│ (Cloud SDK / HTTPS)
▼
Cloud API (AWS ACM / Azure Key Vault)
│
▼
Load Balancer / CDN / App Service
(references the imported certificate)

No agent is needed. The SSL-CLM backend communicates directly with cloud APIs using configured credentials.


Imports certificates into AWS ACM so they can be used with:

  • Elastic Load Balancers (ALB, NLB, Classic)
  • CloudFront distributions
  • API Gateway custom domains
  • Elastic Beanstalk
FieldDescriptionExample
NameStore display nameAWS ACM - Production US-East-1
RegionAWS regionus-east-1
Access Key IDIAM access keyAKIAIOSFODNN7EXAMPLE
Secret Access KeyIAM secret key(stored encrypted)
Certificate ARN(Optional) Existing ACM cert ARN to updatearn:aws:acm:us-east-1:123:certificate/abc
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"acm:ImportCertificate",
"acm:DescribeCertificate",
"acm:ListCertificates",
"acm:DeleteCertificate",
"acm:GetCertificate",
"acm:ListTagsForCertificate"
],
"Resource": "*"
}
]
}
  1. SSL-CLM issues or renews a certificate
  2. Platform calls acm:ImportCertificate with cert PEM, chain PEM, and key PEM
  3. AWS ACM stores the certificate
  4. If an ARN was specified, the existing certificate is replaced (in-place update)
  5. Services referencing that ARN (ELB, CloudFront) automatically pick up the new cert

When you specify a Certificate ARN, SSL-CLM will reimport the renewed certificate to the same ARN. This means:

  • Load balancers referencing that ARN automatically get the new certificate
  • No need to update listener configurations
  • Zero-downtime certificate rotation

If no ARN is specified, each deployment creates a new ACM certificate entry. You’ll need to update your load balancer/CDN configuration to reference the new ARN.


Imports certificates into Azure Key Vault for use with:

  • Azure App Service / App Service Environment
  • Azure Application Gateway
  • Azure Front Door
  • Azure Functions (custom domains)
  • Any service that references Key Vault certificates
FieldDescriptionExample
NameStore display nameAzure KV - Production
Vault URLKey Vault URLhttps://myvault.vault.azure.net
Tenant IDAzure AD tenant IDxxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Client IDService principal client IDxxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Client SecretService principal secret(stored encrypted)
Certificate NameName for the cert in Key Vaultmy-ssl-cert

The service principal needs the following Key Vault access policies (or RBAC roles):

Access Policy model:

  • Certificate permissions: Import, Get, List, Delete
  • Secret permissions: Get, List (if importing as secret)

RBAC model:

  • Role: Key Vault Certificates Officer on the vault
  1. SSL-CLM issues or renews a certificate
  2. Platform calls Azure Key Vault’s certificate import API
  3. Certificate (with private key) is stored in Key Vault
  4. Services referencing the certificate name pick up the new version

Azure Key Vault supports versioning — each import creates a new version of the certificate. Services that reference the certificate without a specific version ID automatically get the latest.

Azure Key Vault accepts:

  • PEM — Certificate + key + chain as PEM strings
  • PFX — PKCS#12 bundle (SSL-CLM generates this automatically if needed)

FeatureAWS ACMAzure Key Vault
In-place certificate update✓ (via ARN)✓ (via versioning)
Zero-downtime rotation✓✓
Private key accessibleNo (ACM manages keys)Yes (can export from KV)
Auto-reference by servicesBy ARNBy name + version
CostFree (for imported certs)Key Vault pricing
Wildcard support✓✓

  • Always specify the Certificate ARN for renewal scenarios to enable in-place updates
  • Use resource-scoped IAM policies (restrict to specific ARNs if possible)
  • Tag imported certificates for governance tracking
  • Note: ACM-imported certificates do NOT auto-renew via AWS — SSL-CLM handles renewal
  • Use a consistent Certificate Name across renewals for seamless versioning
  • Prefer the RBAC permission model over access policies for better governance
  • Enable soft-delete on Key Vault for recovery of accidentally deleted certificates
  • Configure auto-rotation notifications in Azure (complementary to SSL-CLM alerts)

IssuePossible CauseResolution
Access denied (AWS)IAM permissions insufficientCheck IAM policy allows acm:ImportCertificate
Access denied (Azure)Service principal lacks permissionsCheck Key Vault access policies or RBAC roles
Import fails — cert/key mismatchKey doesn’t match certificateEnsure the certificate and private key are from the same issuance
Region mismatch (AWS)Wrong region configuredACM certs are region-specific; use the correct region
Vault not found (Azure)Wrong vault URL or network restrictionCheck vault URL, VNet rules, and private endpoints