Skip to content

Setup

Install and configure the SSL-CLM v2 platform to manage and monitor SSL/TLS certificates across your infrastructure.



  1. Install Platform — Deploy the SSL-CLM JAR with MongoDB
  2. Configure Environment — Set environment variables (database, JWT, profiles)
  3. Access UI — Open the web interface and log in
  4. Register Agent(s) — Deploy agents on remote servers that need local access (for on-prem CAs, file-based stores)
  5. Add Certificate Authorities — Integrate your CAs (Smallstep, ADCS, ACME, EJBCA, AWS PCA, Google CAS)
  6. Add Certificate Stores — Configure deployment targets (NGINX, Apache, IIS, F5, AWS ACM, Azure KV)
  7. Configure DNS Providers — (If using ACME with DNS-01 validation)
  8. Create Policies — Define issuance and deployment governance rules
  9. Run Discovery — Find existing certificates across your infrastructure
  10. Set Up Alerts — Configure expiration and failure notifications

ComponentMinimumRecommended
OSLinux (Ubuntu 20.04+, RHEL 8+) or Windows Server 2019+Ubuntu 22.04 LTS
Java21+21 (LTS)
MongoDB7.0+7.0+ (replica set)
RAM2 GB4+ GB
Disk10 GB50+ GB
CPU2 cores4+ cores
ComponentMinimum
OSLinux or Windows Server 2016+
Java21+
RAM512 MB
Disk1 GB
NetworkOutbound HTTPS to platform (no inbound required)
ConnectionDirectionPortPurpose
Platform → MongoDBOutbound27017Database
Browser → PlatformInbound8080 (or 443 via proxy)UI + API
Agent → PlatformOutbound8080 (or 443)Heartbeat + job polling
Platform → ACME CAOutbound443ACME certificate issuance
Platform → Cloud APIsOutbound443AWS/Azure/GCP integrations
Agent → On-prem CAVaries135, 443, 9000CA communication

For a quick local setup:

Terminal window
# Start MongoDB
docker run -d --name ssl-clm-mongo -p 27017:27017 mongo:7
# Run the platform
java -jar ssl-clm-<version>.jar

Open http://localhost:8080 in your browser. Default dev credentials will be displayed in the console output.


After installation:

  1. Configure your first Certificate Authority
  2. Register your first Agent (if using on-prem CAs or file-based stores)
  3. Issue your first certificate
  4. Run a discovery scan