Nexus Certificate Manager
Certificate issuance and revocation through Nexus Smart ID CM's REST issuance API.
Overview
Nexus Certificate Manager is registered as an issuer type in Cockpit's PKI module. The connector submits enrollment and revocation requests to a Nexus Smart ID CM deployment's REST issuance API, against a configured CA and certificate profile.
A bearer token is attached per request; a client certificate instead authenticates the TLS connection itself.
| Property | Value |
|---|---|
| Issuer type | nexus |
| Backend | Nexus Smart ID Certificate Manager REST issuance API |
| Authentication | Bearer API token (default), or mutual TLS with a client certificate |
| Issuance model | Synchronous — enrollment returns the certificate and chain directly |
| Key custody | Caller/CSR-based — Nexus never returns a private key |
The Nexus base URL commonly points at an appliance on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.
Configuration
Config fields
| Field | Purpose |
|---|---|
base_url | Base URL of the Nexus Certificate Manager REST endpoint (scheme, host, optional port and context path). |
ca_name | Name of the Nexus CA (as configured in Certificate Manager) that signs the certificate. |
profile_name | Nexus certificate profile used for enrollment. |
default_validity_days | Certificate validity applied when a request does not specify one (default 365). |
tls_skip_verify | Optional, non-production only. Accepts a Nexus server certificate that fails verification. |
Credentials
Nexus supports two authentication modes; choose one when registering the issuer.
| Mode | Fields | Purpose |
|---|---|---|
| Bearer token | api_token | A static API token presented as a bearer credential on every request. |
| Mutual TLS | client_cert_pem, client_key_pem | A client certificate and matching private key presented over mutual TLS. Both fields are required together. |
An optional tls_ca_pem trust bundle can be supplied under either mode to validate the Nexus server certificate. All credential fields are encrypted at rest and never echoed back by the platform.
Registering the issuer
Provide the base URL, CA and profile
Enter the Nexus Certificate Manager base URL, the CA name and the certificate profile to enroll against.
Choose the authentication mode
Provide either a bearer API token, or a client certificate and private key pair for mutual TLS. Add a trust bundle if the Nexus server certificate needs one.
Test the connection
Run test-connection to confirm the endpoint is reachable under the chosen authentication mode.
Issue through the issuer
Request certificates against the issuer; Cockpit submits the CSR, SANs and validity for enrollment.
Issuance flow
Enrollment is synchronous: the CSR is submitted and the signed certificate, with its chain, comes back in the same response.
No polling and no pending state — the response either carries the certificate or an error.
Supported operations
| Operation | Supported | Notes |
|---|---|---|
| test-connection | Yes | Probes the status endpoint under the configured authentication mode. |
| issue | Yes | Submits the CSR against the configured CA and profile; the response carries the certificate and chain. |
| renew | Yes | No native renewal flow — renew re-submits a fresh enrollment request. |
| revoke | Yes | Revokes by certificate serial, with a standard revocation reason and optional comment. |
The Nexus connector is built against the Nexus Certificate Manager published REST contract. It has not yet been validated against a live CM instance. Before relying on it for production issuance, verify the request and response shapes against a Nexus sandbox and validate a full issue/revoke cycle in a non-production issuer first.