Protocol Integrations
Protocol Integrations
Section titled “Protocol Integrations”SSL-CLM supports industry-standard certificate enrollment protocols.
Supported Protocols
Section titled “Supported Protocols”| Protocol | Direction | Use Case | Status |
|---|---|---|---|
| ACME (RFC 8555) | Client & Server | Automated certificate issuance with domain validation | Supported |
SSL-CLM includes both an ACME client and a built-in ACME server.
ACME Client
Section titled “ACME Client”SSL-CLM acts as an ACME client when requesting certificates from external ACME CAs:
- Let’s Encrypt
- ZeroSSL
- Google Trust Services
- Any RFC 8555-compliant CA
Supported challenge types:
- HTTP-01 — Platform or agent serves challenge token on port 80
- DNS-01 — Platform creates DNS TXT record via configured DNS provider (required for wildcards)
- TLS-ALPN-01 — Agent responds on port 443 with challenge certificate
External Account Binding (EAB) is supported for authenticated ACME access.
→ ACME / Let’s Encrypt CA Integration
ACME Server
Section titled “ACME Server”SSL-CLM exposes a built-in ACME server that allows standard clients (certbot, acme.sh, win-acme, Caddy, Traefik) to request certificates from your internal CAs using the ACME protocol.
Features:
- Multiple profiles (Production, Staging, Development)
- Trust models: Public PKI, Private PKI, Hybrid
- Validation modes: Policy-based, DNS-01, HTTP-01
- External Account Binding (EAB) for authenticated access
- Per-profile key type and validity restrictions
Future Protocols (Roadmap)
Section titled “Future Protocols (Roadmap)”The following protocols are planned for future releases but are not yet implemented:
| Protocol | Direction | Use Case |
|---|---|---|
| SCEP | Server | Certificate enrollment for network devices and MDM |
| EST (RFC 7030) | Server | Modern TLS-authenticated certificate enrollment |
| CMP (RFC 4210) | Server | Full-featured certificate lifecycle management |
These will be documented when available.