Skip to content

Protocol Integrations

SSL-CLM supports industry-standard certificate enrollment protocols.


ProtocolDirectionUse CaseStatus
ACME (RFC 8555)Client & ServerAutomated certificate issuance with domain validationSupported

SSL-CLM includes both an ACME client and a built-in ACME server.

SSL-CLM acts as an ACME client when requesting certificates from external ACME CAs:

  • Let’s Encrypt
  • ZeroSSL
  • Google Trust Services
  • Any RFC 8555-compliant CA

Supported challenge types:

  • HTTP-01 — Platform or agent serves challenge token on port 80
  • DNS-01 — Platform creates DNS TXT record via configured DNS provider (required for wildcards)
  • TLS-ALPN-01 — Agent responds on port 443 with challenge certificate

External Account Binding (EAB) is supported for authenticated ACME access.

→ ACME / Let’s Encrypt CA Integration

SSL-CLM exposes a built-in ACME server that allows standard clients (certbot, acme.sh, win-acme, Caddy, Traefik) to request certificates from your internal CAs using the ACME protocol.

Features:

  • Multiple profiles (Production, Staging, Development)
  • Trust models: Public PKI, Private PKI, Hybrid
  • Validation modes: Policy-based, DNS-01, HTTP-01
  • External Account Binding (EAB) for authenticated access
  • Per-profile key type and validity restrictions

→ ACME Server Configuration


The following protocols are planned for future releases but are not yet implemented:

ProtocolDirectionUse Case
SCEPServerCertificate enrollment for network devices and MDM
EST (RFC 7030)ServerModern TLS-authenticated certificate enrollment
CMP (RFC 4210)ServerFull-featured certificate lifecycle management

These will be documented when available.