Skip to content

Platform Installation

The QCecuring SSL-CLM Platform v2 is delivered as a unified Spring Boot application containing:

  • REST API
  • Web UI (Angular, served from the same app)
  • Certificate Lifecycle Engine
  • Discovery Engine
  • Policy Engine
  • ACME Server
  • Audit Layer
  • Scheduler
  • Notification Service

It runs as a single executable JAR.


ComponentVersionPurpose
Java21+Application runtime
MongoDB7.0+Primary data store
ComponentPurpose
TLS certificatesHTTPS for the platform
Reverse proxy (NGINX / LB)SSL termination, load balancing
SMTP serverEmail notifications (expiration alerts)
CA credentialsCertificate Authority integrations

Terminal window
java -version

Expected: Java 21 or higher

If not installed:

  • Ubuntu/Debian: apt install openjdk-21-jre
  • RHEL/CentOS: dnf install java-21-openjdk
  • Windows: Download from Adoptium

Terminal window
docker run -d \
--name ssl-clm-mongo \
-p 27017:27017 \
-v ssl-clm-data:/data/db \
mongo:7

Follow MongoDB installation guide for your OS.

For production, configure a replica set for high availability.


Terminal window
java -jar ssl-clm-<version>.jar

The application starts on:

http://localhost:8080

Console output shows:

:: Spring Boot :: (v3.x.x)
SSL-CLM Platform v2.0.x started on port 8080

ProfileCommandUse Case
dev (default)java -jar ssl-clm.jarLocal development, relaxed security
prodjava -jar ssl-clm.jar --spring.profiles.active=prodProduction with strict security

Create a .env file or set environment variables:

Terminal window
# ─── Profile ───────────────────────────────────────
SPRING_PROFILES_ACTIVE=prod
# ─── Server ────────────────────────────────────────
SERVER_PORT=8080
# ─── MongoDB (REQUIRED) ───────────────────────────
MONGODB_URI=mongodb://localhost:27017/ssl-clm-db
# ─── Security (REQUIRED in production) ────────────
JWT_SECRET=your-long-random-secret-at-least-64-chars
JWT_EXPIRATION=1800000
# ─── Email (Optional) ─────────────────────────────
EMAIL_ENABLED=true
EMAIL_FROM=noreply@yourcompany.com
EMAIL_HOST=smtp.yourcompany.com
EMAIL_PORT=587
EMAIL_USERNAME=smtp-user
EMAIL_PASSWORD=smtp-password
# ─── HTTPS (Optional) ─────────────────────────────
SERVER_SSL_ENABLED=false
SERVER_SSL_KEY_STORE=/path/to/keystore.p12
SERVER_SSL_KEY_STORE_PASSWORD=changeit
SERVER_SSL_KEY_STORE_TYPE=PKCS12
# ─── Scheduler ────────────────────────────────────
SCHEDULING_ENABLED=true
REPORTING_ENABLED=true
# ─── Agent mTLS CA ────────────────────────────────
AGENT_CA_CERT_PATH=/path/to/agent-ca.pem
AGENT_CA_KEY_PATH=/path/to/agent-ca-key.pem
VariablePurposeDefault
MONGODB_URIMongoDB connection stringmongodb://localhost:27017/ssl-clm-db
JWT_SECRETSecret for signing JWT tokens — change in productionRandom (dev only)
JWT_EXPIRATIONJWT token lifetime in milliseconds1800000 (30 min)
SERVER_PORTHTTP port8080
SCHEDULING_ENABLEDEnable background scheduler (renewals, CA refresh)true

Terminal window
curl http://localhost:8080/actuator/health

Expected:

{
"status": "UP"
}

Open in your browser:

http://localhost:8080

The UI is served from the same application. Log in with the default admin credentials (shown in console on first run) or configure SSO.


Internet / Internal Network
│
▼
Reverse Proxy (NGINX / ALB)
│ (HTTPS termination)
▼
SSL-CLM Platform (port 8080)
│
▼
MongoDB (replica set)

Create /etc/systemd/system/ssl-clm.service:

[Unit]
Description=SSL-CLM Platform
After=network.target mongod.service
[Service]
Type=simple
User=ssl-clm
WorkingDirectory=/opt/ssl-clm
ExecStart=/usr/bin/java -jar /opt/ssl-clm/ssl-clm.jar --spring.profiles.active=prod
Restart=always
RestartSec=10
EnvironmentFile=/opt/ssl-clm/.env
[Install]
WantedBy=multi-user.target
Terminal window
sudo systemctl daemon-reload
sudo systemctl enable ssl-clm
sudo systemctl start ssl-clm

Use NSSM or Windows Service wrapper:

Terminal window
nssm install SSLCLMPlatform "C:\Program Files\Java\jdk-21\bin\java.exe" "-jar C:\ssl-clm\ssl-clm.jar --spring.profiles.active=prod"
nssm set SSLCLMPlatform AppEnvironmentExtra "MONGODB_URI=mongodb://localhost:27017/ssl-clm-db" "JWT_SECRET=your-secret"
nssm start SSLCLMPlatform
Terminal window
docker run -d \
--name ssl-clm \
-p 8080:8080 \
-e MONGODB_URI=mongodb://mongo:27017/ssl-clm-db \
-e JWT_SECRET=your-secret \
-e SPRING_PROFILES_ACTIVE=prod \
qcecuring/ssl-clm:latest

ItemStatus
JWT_SECRET changed from default☐
MongoDB secured with authentication☐
HTTPS enabled (direct or via reverse proxy)☐
Firewall restricts MongoDB port (27017) to platform only☐
Agent CA certificate configured for mTLS☐
SMTP configured for email alerts☐
Backup strategy for MongoDB☐
Log rotation configured☐
Health check monitoring in place☐

  1. Stop the platform: systemctl stop ssl-clm
  2. Back up MongoDB: mongodump --db ssl-clm-db
  3. Replace the JAR file with the new version
  4. Start the platform: systemctl start ssl-clm
  5. Verify health: curl http://localhost:8080/actuator/health

SSL-CLM handles database migrations automatically on startup.


After the platform is running:

  1. Register agents on remote servers
  2. Add Certificate Authorities
  3. Configure Certificate Stores
  4. Run your first discovery scan