Skip to content

Web Server Integrations

SSL-CLM automates certificate deployment to web servers through agents and direct API management. Certificates are pushed to configured paths, services are reloaded, and deployments are validated automatically.


Web ServerStore Type IDModeCertificate FormatPost-Deploy
NGINXstore-filebased-nginxAgentPEM (cert + key + chain)nginx -t && systemctl reload nginx
Apache HTTP Serverstore-applicationserver-apacheAgentPEM (cert + key + chain)apachectl configtest && systemctl reload apache2
Microsoft IISstore-applicationserver-iisAgentPFX / PKCS#12Windows Certificate Store import + site binding
F5 BIG-IPstore-applicationserver-f5bigipAgentless (API)PEM / PKCS#12iControl REST API upload + SSL profile binding

SSL-CLM Platform
│
│ (mTLS, Pull-Based Jobs)
▼
SSL-CLM Agent (on web server or jump host)
│
│ (Local file operations + service reload)
▼
Web Server (NGINX / Apache / IIS)
SSL-CLM Platform
│
│ (HTTPS, iControl REST API)
▼
F5 BIG-IP (Management Interface)

For all web server integrations:

  1. Certificate is issued or renewed in SSL-CLM
  2. Platform dispatches a DEPLOY_CERT job
  3. Agent (or backend for F5) receives the job
  4. Certificate and key are written to the target (files or Windows store or API)
  5. Post-deployment command is executed (reload/restart)
  6. Validation confirms the server is responding with the new certificate
  7. Job status updated to SUCCESS or FAILED

All agent-based web server integrations require:

  1. SSL-CLM Agent installed on the web server (or a jump host with file access)
  2. Agent registered and in ONLINE status
  3. Certificate Store configured in SSL-CLM pointing to the correct certificate/key paths
  4. File permissions — Agent process has write access to certificate paths
  5. Reload permissions — Agent process can execute the reload command (may require sudo)


SSL-CLM monitors certificate expiry and handles renewal end-to-end:

  1. Policy triggers renewal (e.g., 30 days before expiry)
  2. New certificate is issued from the configured CA
  3. Agent deploys new cert to the same store paths
  4. Post-deploy hook reloads the web server
  5. Old certificate is archived
  6. Zero downtime — reload picks up new cert without restarting

IssueSolution
Certificate not updating on serverCheck agent status. Verify file permissions on cert paths.
Web server fails to reloadRun the reload command manually. Check cert/key match.
Agent not executing deploy jobVerify agent is ONLINE. Check store assignment to agent.
Wrong certificate served after deployClear server cache. Check for duplicate server blocks/sites.
Permission denied writing filesEnsure agent runs with appropriate user/group permissions.