Setup
Install and configure the SSL-CLM v2 platform to manage and monitor SSL/TLS certificates across your infrastructure.
Setup Guides
Section titled “Setup Guides”- Platform Installation — Install the API + Web UI (single JAR deployment)
- Agent Installation — Deploy the operational agent on remote servers
Installation Flow
Section titled “Installation Flow”- Install Platform — Deploy the SSL-CLM JAR with MongoDB
- Configure Environment — Set environment variables (database, JWT, profiles)
- Access UI — Open the web interface and log in
- Register Agent(s) — Deploy agents on remote servers that need local access (for on-prem CAs, file-based stores)
- Add Certificate Authorities — Integrate your CAs (Smallstep, ADCS, ACME, EJBCA, AWS PCA, Google CAS)
- Add Certificate Stores — Configure deployment targets (NGINX, Apache, IIS, F5, AWS ACM, Azure KV)
- Configure DNS Providers — (If using ACME with DNS-01 validation)
- Create Policies — Define issuance and deployment governance rules
- Run Discovery — Find existing certificates across your infrastructure
- Set Up Alerts — Configure expiration and failure notifications
System Requirements
Section titled “System Requirements”Platform Server
Section titled “Platform Server”| Component | Minimum | Recommended |
|---|---|---|
| OS | Linux (Ubuntu 20.04+, RHEL 8+) or Windows Server 2019+ | Ubuntu 22.04 LTS |
| Java | 21+ | 21 (LTS) |
| MongoDB | 7.0+ | 7.0+ (replica set) |
| RAM | 2 GB | 4+ GB |
| Disk | 10 GB | 50+ GB |
| CPU | 2 cores | 4+ cores |
Agent Server
Section titled “Agent Server”| Component | Minimum |
|---|---|
| OS | Linux or Windows Server 2016+ |
| Java | 21+ |
| RAM | 512 MB |
| Disk | 1 GB |
| Network | Outbound HTTPS to platform (no inbound required) |
Network Requirements
Section titled “Network Requirements”| Connection | Direction | Port | Purpose |
|---|---|---|---|
| Platform → MongoDB | Outbound | 27017 | Database |
| Browser → Platform | Inbound | 8080 (or 443 via proxy) | UI + API |
| Agent → Platform | Outbound | 8080 (or 443) | Heartbeat + job polling |
| Platform → ACME CA | Outbound | 443 | ACME certificate issuance |
| Platform → Cloud APIs | Outbound | 443 | AWS/Azure/GCP integrations |
| Agent → On-prem CA | Varies | 135, 443, 9000 | CA communication |
Quick Start (Development)
Section titled “Quick Start (Development)”For a quick local setup:
# Start MongoDBdocker run -d --name ssl-clm-mongo -p 27017:27017 mongo:7
# Run the platformjava -jar ssl-clm-<version>.jarOpen http://localhost:8080 in your browser. Default dev credentials will be displayed in the console output.
Next Steps
Section titled “Next Steps”After installation:
- Configure your first Certificate Authority
- Register your first Agent (if using on-prem CAs or file-based stores)
- Issue your first certificate
- Run a discovery scan