Web Server Integrations
Web Server Integrations
Section titled “Web Server Integrations”SSL-CLM automates certificate deployment to web servers through agents and direct API management. Certificates are pushed to configured paths, services are reloaded, and deployments are validated automatically.
Supported Web Servers
Section titled “Supported Web Servers”| Web Server | Store Type ID | Mode | Certificate Format | Post-Deploy |
|---|---|---|---|---|
| NGINX | store-filebased-nginx | Agent | PEM (cert + key + chain) | nginx -t && systemctl reload nginx |
| Apache HTTP Server | store-applicationserver-apache | Agent | PEM (cert + key + chain) | apachectl configtest && systemctl reload apache2 |
| Microsoft IIS | store-applicationserver-iis | Agent | PFX / PKCS#12 | Windows Certificate Store import + site binding |
| F5 BIG-IP | store-applicationserver-f5bigip | Agentless (API) | PEM / PKCS#12 | iControl REST API upload + SSL profile binding |
Architecture
Section titled “Architecture”Agent-Based (NGINX, Apache, IIS)
Section titled “Agent-Based (NGINX, Apache, IIS)”SSL-CLM Platform││ (mTLS, Pull-Based Jobs)▼SSL-CLM Agent (on web server or jump host)││ (Local file operations + service reload)▼Web Server (NGINX / Apache / IIS)Agentless (F5 BIG-IP)
Section titled “Agentless (F5 BIG-IP)”SSL-CLM Platform││ (HTTPS, iControl REST API)▼F5 BIG-IP (Management Interface)Common Deployment Flow
Section titled “Common Deployment Flow”For all web server integrations:
- Certificate is issued or renewed in SSL-CLM
- Platform dispatches a
DEPLOY_CERTjob - Agent (or backend for F5) receives the job
- Certificate and key are written to the target (files or Windows store or API)
- Post-deployment command is executed (reload/restart)
- Validation confirms the server is responding with the new certificate
- Job status updated to SUCCESS or FAILED
Common Prerequisites
Section titled “Common Prerequisites”All agent-based web server integrations require:
- SSL-CLM Agent installed on the web server (or a jump host with file access)
- Agent registered and in ONLINE status
- Certificate Store configured in SSL-CLM pointing to the correct certificate/key paths
- File permissions — Agent process has write access to certificate paths
- Reload permissions — Agent process can execute the reload command (may require sudo)
Integration Guides
Section titled “Integration Guides”- NGINX — PEM file deployment with reload
- Apache HTTP Server — PEM file deployment with config test
- Microsoft IIS — Windows Certificate Store import with site binding
- F5 BIG-IP — Agentless API deployment
Automated Renewal for Web Servers
Section titled “Automated Renewal for Web Servers”SSL-CLM monitors certificate expiry and handles renewal end-to-end:
- Policy triggers renewal (e.g., 30 days before expiry)
- New certificate is issued from the configured CA
- Agent deploys new cert to the same store paths
- Post-deploy hook reloads the web server
- Old certificate is archived
- Zero downtime — reload picks up new cert without restarting
Troubleshooting
Section titled “Troubleshooting”| Issue | Solution |
|---|---|
| Certificate not updating on server | Check agent status. Verify file permissions on cert paths. |
| Web server fails to reload | Run the reload command manually. Check cert/key match. |
| Agent not executing deploy job | Verify agent is ONLINE. Check store assignment to agent. |
| Wrong certificate served after deploy | Clear server cache. Check for duplicate server blocks/sites. |
| Permission denied writing files | Ensure agent runs with appropriate user/group permissions. |
Related Pages
Section titled “Related Pages”- Certificate Stores — Store configuration
- Agents — Agent deployment and monitoring
- Jobs — Track deployment job execution