Skip to content

Agent Installation

The QCecuring SSL-CLM Agent enables secure, distributed certificate lifecycle execution on remote infrastructure. Deploy agents on servers that need:

  • Local CA access (e.g., Microsoft AD CS on a domain-joined server)
  • File-based certificate deployment (NGINX, Apache, JKS stores)
  • IIS certificate management
  • Local network discovery
  • Store scanning

The agent does not expose inbound ports — all communication is outbound via HTTPS/mTLS.


OSVersionArchitecture
Windows Server2016, 2019, 2022x64
Ubuntu20.04, 22.04, 24.04x64, ARM64
RHEL / CentOS8, 9x64
Debian11, 12x64
SUSE15x64

RequirementDetails
Java21+
NetworkOutbound HTTPS to SSL-CLM platform (port 8080 or 443)
Bootstrap TokenGenerated from the platform UI
Disk~100 MB for agent + logs
RAM256 MB minimum, 512 MB recommended

  1. In the SSL-CLM UI, navigate to Infrastructure → Agents
  2. Click + Register Agent
  3. Enter the agent hostname
  4. Click Generate Token
  5. Copy the one-time bootstrap token

The token is:

  • Single-use — Consumed on first registration
  • Time-limited — Expires after 24 hours (configurable)
  • Non-recoverable — Cannot be viewed again after generation

Terminal window
sudo apt update && sudo apt install -y openjdk-21-jre-headless
java -version
Terminal window
sudo dnf install -y java-21-openjdk-headless
java -version

Download and install Java 21 from Adoptium. Verify:

Terminal window
java -version

Download the agent JAR from the platform:

  • Navigate to Infrastructure → Agents → Download Agent
  • Or obtain from your deployment package

Place on the target server:

Terminal window
mkdir -p /opt/ssl-clm-agent
cp ssl-clm-agent-<version>.jar /opt/ssl-clm-agent/

Terminal window
java -jar /opt/ssl-clm-agent/ssl-clm-agent.jar \
--backend.url=https://ssl-clm.example.com:8080 \
--bootstrap.token=YOUR_BOOTSTRAP_TOKEN
Terminal window
$env:BACKEND_URL = "https://ssl-clm.example.com:8080"
$env:AGENT_BOOTSTRAP_TOKEN = "YOUR_BOOTSTRAP_TOKEN"
java -jar C:\ssl-clm-agent\ssl-clm-agent.jar
  1. Agent sends the bootstrap token to the platform
  2. Platform validates the token (one-time use)
  3. Platform issues an mTLS client certificate to the agent
  4. Agent stores the certificate and key locally
  5. Agent begins heartbeat reporting
  6. Agent appears in the Agents list as BOOTSTRAPPING → ONLINE

After successful bootstrap, the token is consumed and not needed again.


After bootstrap, create a persistent configuration:

Linux: /opt/ssl-clm-agent/application.properties

Section titled “Linux: /opt/ssl-clm-agent/application.properties”
# Platform connection
backend.url=https://ssl-clm.example.com:8080
# Intervals (milliseconds)
agent.heartbeat.fixedDelayMs=30000
agent.jobs.fixedDelayMs=10000
# mTLS (auto-configured after bootstrap)
backend.mtls.enabled=true
backend.mtls.client-cert-path=/opt/ssl-clm-agent/certs/client.pem
backend.mtls.client-key-path=/opt/ssl-clm-agent/certs/client-key.pem
backend.mtls.ca-cert-path=/opt/ssl-clm-agent/certs/ca.pem
# Microsoft CA (enable if agent manages ADCS)
agent.msca.enabled=false
# agent.msca.ca-identifier=WIN-SERVER\\my-ca
# Logging
logging.level.root=INFO
logging.file.name=/var/log/ssl-clm-agent/agent.log

Windows: C:\ssl-clm-agent\application.properties

Section titled “Windows: C:\ssl-clm-agent\application.properties”
backend.url=https://ssl-clm.example.com:8080
agent.heartbeat.fixedDelayMs=30000
agent.jobs.fixedDelayMs=10000
backend.mtls.enabled=true
agent.msca.enabled=true
agent.msca.ca-identifier=WIN-SERVER\\my-ca
logging.level.root=INFO

Create /etc/systemd/system/ssl-clm-agent.service:

[Unit]
Description=SSL-CLM Agent
After=network.target
[Service]
Type=simple
User=ssl-clm-agent
WorkingDirectory=/opt/ssl-clm-agent
ExecStart=/usr/bin/java -jar /opt/ssl-clm-agent/ssl-clm-agent.jar
Restart=always
RestartSec=10
[Install]
WantedBy=multi-user.target
Terminal window
sudo useradd -r -s /bin/false ssl-clm-agent
sudo chown -R ssl-clm-agent: /opt/ssl-clm-agent
sudo systemctl daemon-reload
sudo systemctl enable ssl-clm-agent
sudo systemctl start ssl-clm-agent
sudo systemctl status ssl-clm-agent
Terminal window
nssm install SSLCLMAgent "C:\Program Files\Java\jdk-21\bin\java.exe" "-jar C:\ssl-clm-agent\ssl-clm-agent.jar"
nssm set SSLCLMAgent AppDirectory "C:\ssl-clm-agent"
nssm start SSLCLMAgent

  1. Check the platform UI: Infrastructure → Agents — agent should show ONLINE
  2. Check agent logs:
    Terminal window
    # Linux
    journalctl -u ssl-clm-agent -f
    # Or
    tail -f /var/log/ssl-clm-agent/agent.log
  3. Test with a job: trigger a discovery scan or CA refresh from the UI

For agents managing Microsoft AD CS:

agent.msca.enabled=true
agent.msca.ca-identifier=WIN-SERVER\\my-ca-name

Additional Windows requirements:

  • Server must be domain-joined
  • Agent process must run as a domain user with enrollment permissions
  • certutil must be available in PATH

Optional environment variables for AD CS authentication:

ADCS_SERVER=WIN-SERVER
ADCS_USERNAME=DOMAIN\ServiceAccount
ADCS_PASSWORD=StrongPassword

For agents deploying to web servers, ensure the agent user has write access:

Terminal window
# For NGINX cert paths
sudo chown ssl-clm-agent: /etc/nginx/ssl/
sudo chmod 750 /etc/nginx/ssl/
# For Apache cert paths
sudo chown ssl-clm-agent: /etc/ssl/certs/ /etc/ssl/private/
# For reload commands (sudoers)
echo "ssl-clm-agent ALL=(root) NOPASSWD: /bin/systemctl reload nginx, /bin/systemctl reload apache2" | sudo tee /etc/sudoers.d/ssl-clm-agent

PracticeImplementation
Run as dedicated userssl-clm-agent user with minimal permissions
mTLS onlyDisable plain HTTP after bootstrap
Restrict outboundFirewall allows only HTTPS to platform
Rotate credentialsAgent cert auto-renewed by platform
Log monitoringForward agent logs to SIEM
Least privilegeOnly grant file/service permissions needed

IssuePossible CauseResolution
Bootstrap failsToken expired or already usedGenerate a new token
Connection refusedWrong backend URL or portVerify URL and firewall rules
mTLS handshake errorCA cert mismatchEnsure agent CA cert matches platform
Agent OFFLINE after rebootService not enabledsystemctl enable ssl-clm-agent
Deploy job failsFile permission deniedCheck agent user has write access to cert paths
MSCA operations failNot domain-joined or wrong CA identifierVerify domain membership and certutil -ping

After the agent is running:

  1. Configure Certificate Stores assigned to this agent
  2. Add a Certificate Authority (if agent-based CA)
  3. Run a discovery scan using this agent
  4. Deploy a certificate to verify end-to-end flow