Cloud Store Integrations
Cloud Store Integrations
Section titled “Cloud Store Integrations”SSL-CLM supports agentless certificate deployment to cloud key management services. The platform connects directly via cloud provider APIs — no agent installation required on cloud infrastructure.
Supported Cloud Stores
Section titled “Supported Cloud Stores”| Store | Type ID | Cloud Provider | Authentication | Certificate Format |
|---|---|---|---|---|
| AWS Certificate Manager | store-cloud-aws-acm | AWS | IAM Access Keys | PEM (cert + chain + key) |
| Azure Key Vault | store-cloud-azure-keyvault-secret | Azure | Service Principal (Client Credentials) | PEM or PFX |
Architecture
Section titled “Architecture”SSL-CLM Platform (Backend)││ (Cloud SDK / HTTPS)▼Cloud API (AWS ACM / Azure Key Vault)│▼Load Balancer / CDN / App Service(references the imported certificate)No agent is needed. The SSL-CLM backend communicates directly with cloud APIs using configured credentials.
AWS Certificate Manager (ACM)
Section titled “AWS Certificate Manager (ACM)”What It Does
Section titled “What It Does”Imports certificates into AWS ACM so they can be used with:
- Elastic Load Balancers (ALB, NLB, Classic)
- CloudFront distributions
- API Gateway custom domains
- Elastic Beanstalk
Configuration Fields
Section titled “Configuration Fields”| Field | Description | Example |
|---|---|---|
| Name | Store display name | AWS ACM - Production US-East-1 |
| Region | AWS region | us-east-1 |
| Access Key ID | IAM access key | AKIAIOSFODNN7EXAMPLE |
| Secret Access Key | IAM secret key | (stored encrypted) |
| Certificate ARN | (Optional) Existing ACM cert ARN to update | arn:aws:acm:us-east-1:123:certificate/abc |
Required IAM Permissions
Section titled “Required IAM Permissions”{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "acm:ImportCertificate", "acm:DescribeCertificate", "acm:ListCertificates", "acm:DeleteCertificate", "acm:GetCertificate", "acm:ListTagsForCertificate" ], "Resource": "*" } ]}Deployment Flow
Section titled “Deployment Flow”- SSL-CLM issues or renews a certificate
- Platform calls
acm:ImportCertificatewith cert PEM, chain PEM, and key PEM - AWS ACM stores the certificate
- If an ARN was specified, the existing certificate is replaced (in-place update)
- Services referencing that ARN (ELB, CloudFront) automatically pick up the new cert
In-Place Renewal
Section titled “In-Place Renewal”When you specify a Certificate ARN, SSL-CLM will reimport the renewed certificate to the same ARN. This means:
- Load balancers referencing that ARN automatically get the new certificate
- No need to update listener configurations
- Zero-downtime certificate rotation
Without ARN (New Import)
Section titled “Without ARN (New Import)”If no ARN is specified, each deployment creates a new ACM certificate entry. You’ll need to update your load balancer/CDN configuration to reference the new ARN.
Azure Key Vault
Section titled “Azure Key Vault”What It Does
Section titled “What It Does”Imports certificates into Azure Key Vault for use with:
- Azure App Service / App Service Environment
- Azure Application Gateway
- Azure Front Door
- Azure Functions (custom domains)
- Any service that references Key Vault certificates
Configuration Fields
Section titled “Configuration Fields”| Field | Description | Example |
|---|---|---|
| Name | Store display name | Azure KV - Production |
| Vault URL | Key Vault URL | https://myvault.vault.azure.net |
| Tenant ID | Azure AD tenant ID | xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx |
| Client ID | Service principal client ID | xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx |
| Client Secret | Service principal secret | (stored encrypted) |
| Certificate Name | Name for the cert in Key Vault | my-ssl-cert |
Required Azure Permissions
Section titled “Required Azure Permissions”The service principal needs the following Key Vault access policies (or RBAC roles):
Access Policy model:
- Certificate permissions:
Import,Get,List,Delete - Secret permissions:
Get,List(if importing as secret)
RBAC model:
- Role:
Key Vault Certificates Officeron the vault
Deployment Flow
Section titled “Deployment Flow”- SSL-CLM issues or renews a certificate
- Platform calls Azure Key Vault’s certificate import API
- Certificate (with private key) is stored in Key Vault
- Services referencing the certificate name pick up the new version
Certificate Versioning
Section titled “Certificate Versioning”Azure Key Vault supports versioning — each import creates a new version of the certificate. Services that reference the certificate without a specific version ID automatically get the latest.
Format
Section titled “Format”Azure Key Vault accepts:
- PEM — Certificate + key + chain as PEM strings
- PFX — PKCS#12 bundle (SSL-CLM generates this automatically if needed)
Comparison
Section titled “Comparison”| Feature | AWS ACM | Azure Key Vault |
|---|---|---|
| In-place certificate update | ✓ (via ARN) | ✓ (via versioning) |
| Zero-downtime rotation | ✓ | ✓ |
| Private key accessible | No (ACM manages keys) | Yes (can export from KV) |
| Auto-reference by services | By ARN | By name + version |
| Cost | Free (for imported certs) | Key Vault pricing |
| Wildcard support | ✓ | ✓ |
Deployment Best Practices
Section titled “Deployment Best Practices”AWS ACM
Section titled “AWS ACM”- Always specify the Certificate ARN for renewal scenarios to enable in-place updates
- Use resource-scoped IAM policies (restrict to specific ARNs if possible)
- Tag imported certificates for governance tracking
- Note: ACM-imported certificates do NOT auto-renew via AWS — SSL-CLM handles renewal
Azure Key Vault
Section titled “Azure Key Vault”- Use a consistent Certificate Name across renewals for seamless versioning
- Prefer the RBAC permission model over access policies for better governance
- Enable soft-delete on Key Vault for recovery of accidentally deleted certificates
- Configure auto-rotation notifications in Azure (complementary to SSL-CLM alerts)
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Access denied (AWS) | IAM permissions insufficient | Check IAM policy allows acm:ImportCertificate |
| Access denied (Azure) | Service principal lacks permissions | Check Key Vault access policies or RBAC roles |
| Import fails — cert/key mismatch | Key doesn’t match certificate | Ensure the certificate and private key are from the same issuance |
| Region mismatch (AWS) | Wrong region configured | ACM certs are region-specific; use the correct region |
| Vault not found (Azure) | Wrong vault URL or network restriction | Check vault URL, VNet rules, and private endpoints |
Related Pages
Section titled “Related Pages”- Certificate Stores — Store configuration and management
- Certificates — Certificate lifecycle and deployment
- Jobs — Track deployment job execution
- AWS Private CA — Issue certs from AWS PCA, deploy to AWS ACM
- Google CAS — GCP certificate issuance