Platform Installation
Platform Installation
Section titled “Platform Installation”The QCecuring SSL-CLM Platform v2 is delivered as a unified Spring Boot application containing:
- REST API
- Web UI (Angular, served from the same app)
- Certificate Lifecycle Engine
- Discovery Engine
- Policy Engine
- ACME Server
- Audit Layer
- Scheduler
- Notification Service
It runs as a single executable JAR.
Prerequisites
Section titled “Prerequisites”Required
Section titled “Required”| Component | Version | Purpose |
|---|---|---|
| Java | 21+ | Application runtime |
| MongoDB | 7.0+ | Primary data store |
Optional (Production)
Section titled “Optional (Production)”| Component | Purpose |
|---|---|
| TLS certificates | HTTPS for the platform |
| Reverse proxy (NGINX / LB) | SSL termination, load balancing |
| SMTP server | Email notifications (expiration alerts) |
| CA credentials | Certificate Authority integrations |
Step 1 — Verify Java
Section titled “Step 1 — Verify Java”java -versionExpected: Java 21 or higher
If not installed:
- Ubuntu/Debian:
apt install openjdk-21-jre - RHEL/CentOS:
dnf install java-21-openjdk - Windows: Download from Adoptium
Step 2 — Start MongoDB
Section titled “Step 2 — Start MongoDB”Docker (quickest)
Section titled “Docker (quickest)”docker run -d \ --name ssl-clm-mongo \ -p 27017:27017 \ -v ssl-clm-data:/data/db \ mongo:7Native install
Section titled “Native install”Follow MongoDB installation guide for your OS.
For production, configure a replica set for high availability.
Step 3 — Run the Platform
Section titled “Step 3 — Run the Platform”java -jar ssl-clm-<version>.jarThe application starts on:
http://localhost:8080Console output shows:
:: Spring Boot :: (v3.x.x)SSL-CLM Platform v2.0.x started on port 8080Configuration
Section titled “Configuration”Environment Profiles
Section titled “Environment Profiles”| Profile | Command | Use Case |
|---|---|---|
| dev (default) | java -jar ssl-clm.jar | Local development, relaxed security |
| prod | java -jar ssl-clm.jar --spring.profiles.active=prod | Production with strict security |
Environment Variables
Section titled “Environment Variables”Create a .env file or set environment variables:
# ─── Profile ───────────────────────────────────────SPRING_PROFILES_ACTIVE=prod
# ─── Server ────────────────────────────────────────SERVER_PORT=8080
# ─── MongoDB (REQUIRED) ───────────────────────────MONGODB_URI=mongodb://localhost:27017/ssl-clm-db
# ─── Security (REQUIRED in production) ────────────JWT_SECRET=your-long-random-secret-at-least-64-charsJWT_EXPIRATION=1800000
# ─── Email (Optional) ─────────────────────────────EMAIL_ENABLED=trueEMAIL_FROM=noreply@yourcompany.comEMAIL_HOST=smtp.yourcompany.comEMAIL_PORT=587EMAIL_USERNAME=smtp-userEMAIL_PASSWORD=smtp-password
# ─── HTTPS (Optional) ─────────────────────────────SERVER_SSL_ENABLED=falseSERVER_SSL_KEY_STORE=/path/to/keystore.p12SERVER_SSL_KEY_STORE_PASSWORD=changeitSERVER_SSL_KEY_STORE_TYPE=PKCS12
# ─── Scheduler ────────────────────────────────────SCHEDULING_ENABLED=trueREPORTING_ENABLED=true
# ─── Agent mTLS CA ────────────────────────────────AGENT_CA_CERT_PATH=/path/to/agent-ca.pemAGENT_CA_KEY_PATH=/path/to/agent-ca-key.pemKey Configuration Notes
Section titled “Key Configuration Notes”| Variable | Purpose | Default |
|---|---|---|
MONGODB_URI | MongoDB connection string | mongodb://localhost:27017/ssl-clm-db |
JWT_SECRET | Secret for signing JWT tokens — change in production | Random (dev only) |
JWT_EXPIRATION | JWT token lifetime in milliseconds | 1800000 (30 min) |
SERVER_PORT | HTTP port | 8080 |
SCHEDULING_ENABLED | Enable background scheduler (renewals, CA refresh) | true |
Step 4 — Verify Health
Section titled “Step 4 — Verify Health”curl http://localhost:8080/actuator/healthExpected:
{ "status": "UP"}Step 5 — Access the UI
Section titled “Step 5 — Access the UI”Open in your browser:
http://localhost:8080The UI is served from the same application. Log in with the default admin credentials (shown in console on first run) or configure SSO.
Production Deployment
Section titled “Production Deployment”Recommended Setup
Section titled “Recommended Setup”Internet / Internal Network│▼Reverse Proxy (NGINX / ALB)│ (HTTPS termination)▼SSL-CLM Platform (port 8080)│▼MongoDB (replica set)Running as a Service
Section titled “Running as a Service”Linux (systemd)
Section titled “Linux (systemd)”Create /etc/systemd/system/ssl-clm.service:
[Unit]Description=SSL-CLM PlatformAfter=network.target mongod.service
[Service]Type=simpleUser=ssl-clmWorkingDirectory=/opt/ssl-clmExecStart=/usr/bin/java -jar /opt/ssl-clm/ssl-clm.jar --spring.profiles.active=prodRestart=alwaysRestartSec=10EnvironmentFile=/opt/ssl-clm/.env
[Install]WantedBy=multi-user.targetsudo systemctl daemon-reloadsudo systemctl enable ssl-clmsudo systemctl start ssl-clmWindows (Service)
Section titled “Windows (Service)”Use NSSM or Windows Service wrapper:
nssm install SSLCLMPlatform "C:\Program Files\Java\jdk-21\bin\java.exe" "-jar C:\ssl-clm\ssl-clm.jar --spring.profiles.active=prod"nssm set SSLCLMPlatform AppEnvironmentExtra "MONGODB_URI=mongodb://localhost:27017/ssl-clm-db" "JWT_SECRET=your-secret"nssm start SSLCLMPlatformDocker
Section titled “Docker”docker run -d \ --name ssl-clm \ -p 8080:8080 \ -e MONGODB_URI=mongodb://mongo:27017/ssl-clm-db \ -e JWT_SECRET=your-secret \ -e SPRING_PROFILES_ACTIVE=prod \ qcecuring/ssl-clm:latestProduction Checklist
Section titled “Production Checklist”| Item | Status |
|---|---|
JWT_SECRET changed from default | ☐ |
| MongoDB secured with authentication | ☐ |
| HTTPS enabled (direct or via reverse proxy) | ☐ |
| Firewall restricts MongoDB port (27017) to platform only | ☐ |
| Agent CA certificate configured for mTLS | ☐ |
| SMTP configured for email alerts | ☐ |
| Backup strategy for MongoDB | ☐ |
| Log rotation configured | ☐ |
| Health check monitoring in place | ☐ |
Upgrading
Section titled “Upgrading”- Stop the platform:
systemctl stop ssl-clm - Back up MongoDB:
mongodump --db ssl-clm-db - Replace the JAR file with the new version
- Start the platform:
systemctl start ssl-clm - Verify health:
curl http://localhost:8080/actuator/health
SSL-CLM handles database migrations automatically on startup.
Next Steps
Section titled “Next Steps”After the platform is running: