Skip to content

Certificate Authorities

The Certificate Authorities page manages all CA integrations used for certificate issuance, renewal, revocation, and inventory synchronization.

Navigation: Sidebar → Infrastructure → Certificate Authorities

Certificate Authorities


The main view displays all configured CAs with:

ColumnDescription
NameFriendly name assigned during creation
TypeIntegration type (e.g., MSCA, STEPCA, ACME)
StatusHealth status: HEALTHY, UNHEALTHY, UNREACHABLE, DISABLED
AgentAgent name (for agent-based CAs) or ”—” for direct API
CertificatesTotal certificates issued through this CA
Last CheckedTimestamp of the last health check or sync

SSL-CLM v2 supports 6 Certificate Authority integration types:

PropertyValue
Type IDMSCA
RuntimeAgent
Agent RequiredYes — must run on a domain-joined Windows server
ProtocolWinRM / certutil command execution
FeaturesEnrollment, renewal, revocation, template discovery

The agent executes native certutil and certreq commands against the Microsoft CA. Templates are automatically discovered and made available for certificate issuance.

→ Microsoft AD CS Integration Guide


PropertyValue
Type IDSTEPCA
RuntimeBackend (direct API)
Agent RequiredNo
ProtocolStep-CA REST API with JWK-signed tokens
FeaturesEnrollment, renewal, revocation, inventory sync

Authenticates using a JWK provisioner private key. Communicates directly with the Step-CA API over HTTPS.

Configuration Fields:

  • provisionerName — JWK provisioner name (e.g., clm@qcecuring.com)
  • baseUrl — Step-CA API URL (e.g., https://step-ca.internal:9000)
  • provisionerKeyId — KID from the JWK
  • provisionerJwk — Full JWK private key (EC P-256)

→ Smallstep CA Integration Guide


PropertyValue
Type IDACME
RuntimeBackend
Agent RequiredNo
ProtocolACME (RFC 8555)
FeaturesEnrollment, renewal, revocation via ACME

SSL-CLM acts as an ACME client, automating the full ACME flow (order creation, challenge completion, certificate download).

Configuration Fields:

  • directoryUrl — ACME directory URL (e.g., https://acme-v02.api.letsencrypt.org/directory)
  • accountEmail — Contact email for the ACME account
  • eabKid / eabHmacKey — External Account Binding credentials (if required)

Supported Challenge Types:

  • HTTP-01 (requires port 80 access)
  • DNS-01 (requires DNS provider integration)
  • TLS-ALPN-01 (requires port 443 access)

→ ACME / Let’s Encrypt Integration Guide


PropertyValue
Type IDEJBCA
RuntimeBackend
Agent RequiredNo
ProtocolEJBCA REST API
FeaturesEnrollment, renewal, revocation, template/profile discovery

Integrates with EJBCA (Enterprise Java Beans Certificate Authority) via its REST API for enterprise PKI environments.

Configuration Fields:

  • baseUrl — EJBCA API endpoint
  • clientCertPath — Client certificate for mutual TLS authentication
  • clientKeyPath — Client private key
  • caName — Target CA name within EJBCA
  • certificateProfileName — Certificate profile to use
  • endEntityProfileName — End entity profile to use

→ EJBCA Integration Guide


PropertyValue
Type IDACMPCA
RuntimeBackend
Agent RequiredNo
ProtocolAWS SDK (ACM PCA API)
FeaturesEnrollment, renewal, revocation

Integrates with AWS Certificate Manager Private Certificate Authority for cloud-native PKI.

Configuration Fields:

  • region — AWS region (e.g., us-east-1)
  • caArn — ARN of the Private CA
  • accessKeyId — AWS access key
  • secretAccessKey — AWS secret key
  • signingAlgorithm — e.g., SHA256WITHRSA
  • templateArn — (optional) ACM PCA template ARN

→ AWS Private CA Integration Guide


PropertyValue
Type IDGOOGLE_CAS
RuntimeBackend
Agent RequiredNo
ProtocolGoogle Cloud API (CAS v1)
FeaturesEnrollment, renewal, revocation

Integrates with Google Cloud Certificate Authority Service for GCP-native PKI.

Configuration Fields:

  • projectId — GCP project ID
  • location — Region (e.g., us-central1)
  • caPoolId — CA Pool identifier
  • caId — (optional) Specific CA within the pool
  • serviceAccountJson — GCP service account credentials (JSON)

→ Google CAS Integration Guide


  1. Click + Add CA
  2. Step 1 — Select Type: Choose from the 6 supported CA types displayed as cards
  3. Step 2 — Configure: Fill in the configuration fields (rendered dynamically based on the selected type’s schema)
    • Enter a friendly name
    • For agent-based CAs: select the agent from the dropdown
    • For API-based CAs: enter endpoint URL and credentials
    • Set discovery/refresh interval (hours) for automatic CA inventory sync
  4. Step 3 — Test Connection (optional): Verify connectivity before saving
  5. Click Save

The wizard uses dynamic config schemas loaded from /api/integration-schemas/ca/{type}, so configuration fields adapt to each CA type automatically.


Click any CA row to open its detail page:

  • CA name, type, status, integration ID
  • Agent assignment (if applicable)
  • Discovery interval configuration
  • Last sync timestamp
  • Certificate count
  • Current status with color indicator
  • Last check timestamp
  • Health check history
  • Error details (for UNHEALTHY/UNREACHABLE)

For CAs that support templates (Microsoft CA, EJBCA):

  • Auto-discovered template list
  • Template metadata: code, name, validity, key algorithms, min key size, SAN support, wildcard support, approval requirement, EKUs
  • Load Templates button to trigger fresh template discovery

List of all certificates issued by this CA, with links to certificate detail views.

  • Test Connection — Verify CA reachability
  • Refresh — Trigger immediate inventory sync (CA_REFRESH job)
  • Load Templates — Discover available certificate templates
  • Edit — Modify configuration
  • Disable — Deactivate the CA (prevents new issuance)
  • Delete — Remove the CA integration

StatusMeaningAction Required
HEALTHYCA reachable, credentials valid, API respondingNone
UNHEALTHYCA reachable but returning errorsCheck credentials, CA service health
UNREACHABLENetwork timeout or connection refusedCheck network, firewall, agent status
DISABLEDManually disabled by administratorRe-enable when ready

For template-based CAs, SSL-CLM automatically discovers available certificate templates:

Discovered via certutil -catemplates through the agent:

  • Template display name and OID
  • Key algorithm requirements
  • Validity period
  • Whether manual approval is required

Discovered via the EJBCA REST API:

  • Certificate profiles
  • End entity profiles
  • Key constraints

Templates appear in the enrollment workflow when a user selects the CA.


SSL-CLM periodically syncs with each CA based on the configured Refresh Interval:

  1. Platform dispatches a CA_REFRESH job
  2. Agent (or backend) queries the CA for all issued certificates
  3. Results are compared against platform inventory
  4. New certificates are flagged
  5. Revoked or expired certificates are updated

Default refresh interval: 24 hours. Can be set from 1 hour to 168 hours (7 days).