sslTrus CaaSsslTrus CaaS

sslTrus CaaS

sslTrus CaaS automates the full lifecycle of individual SSL certificates—from request to renewal—within a subscription. It also offers monitoring, scanning, and alerts to keep your certificates secure and stable. Choose cloud push or install the lightweight clmBot for fully automated management, eliminating service interruptions caused by expired certificates.

Core Advantages

Lightweight, On Demand Subscription

Lightweight, On Demand Subscription

Ideal for low volume needs—no heavy platform required. Get professional full lifecycle certificate management at a low entry cost via subscription.

Fully Automated, Worry Free

Fully Automated, Worry Free

Auto completes certificate request, renewal, validation, and redeployment within the subscription. Zero manual intervention, zero risk of expiry‑related downtime.

Flexible Deployment, Broad Compatibility

Flexible Deployment, Broad Compatibility

Choose cloud push or a lightweight Agent to suit any network/security policy. Covers cloud hosts, on‑prem servers, and more.

Centralized Monitoring & Visibility

Centralized Monitoring & Visibility

Unified dashboard for status, expiration scans, and compliance checks—complete control at a glance.

Automated Deployment Components

Whether your servers are located on the public cloud, private cloud or isolated intranet, we provide two secure channels‑Agent and SDG‑to ensure private keys never leave your servers and deliver secure automated deployment for the last‑mile.

Agent (clmBot)

(Lightweight Client, Ready‑to‑Use)

Agent is a lightweight client deployed on your server. It receives cloud‑side instructions and automatically completes certificate download, storage, web‑server configuration updates and service reloads. It consumes minimal system resources, runs with least‑privilege permissions and keeps your server off public‑network exposure.Deploy CaaS certificates with clmBot.

Applicable

Single‑server or small‑scale deployments with outbound network access

SDG (Secure Deployment Gateway)

(Intranet Boundary Proxy, Zero Exposure)

SDG is an edge proxy node built for strictly isolated intranet environments. It acts as the sole secure bridge between the cloud and your internal server cluster. With only one outbound port, it centrally proxies certificate traffic for a group of intranet servers. No direct public‑internet access is required for individual servers, greatly reducing your attack surface.

Applicable

Multi‑server intranet clusters with high‑security and compliance requirements

sslTrus CaaS Product Architecture

sslTrus CaaS Architecture

Supported Environments

Nginx

Nginx

Apache

Apache

Tomcat

Tomcat

IIS

IIS

Baidu Cloud

Baidu Cloud

Volcano Engine

Volcano Engine

Alibaba Cloud

Alibaba Cloud

Tencent Cloud

Tencent Cloud

Azure

Azure

AWS

AWS

HashiCorp Vault

HashiCorp Vault

Linux

Linux

Windows Server

Windows Server

FreeBSD/Unix

FreeBSD/Unix

Caddy

Caddy

HAProxy

HAProxy

FAQs on CaaS

01/

What is CaaS?

A “certificate as a service” product for low volume users. It automatically handles SSL/TLS certificate lifecycle—request, renewal, deployment, monitoring—via subscription.

02/

Can I use it on intranet servers without public IPs?

Yes. Deploy our lightweight Agent on intranet servers. It connects securely to the cloud, receives commands, and deploys certificates automatically.

03/

How reliable are auto renewal and deployment?

The platform proactively monitors expiry, auto renews with the CA, and deploys new certificates per your preset policies—without human intervention.

04/

Which certificate types are supported?

Mainstream types including DV and OV. Check the product page for supported brands; we continuously update.

05/

Does the Agent affect server performance or security?

No. It’s extremely lightweight, runs with minimal privileges, and communicates via encrypted channels—no extra risk.

06/

Can I manage multiple servers/domains centrally?

Absolutely. Add servers and domains in one console, set unified policies for batch renewal/deployment—efficient one stop management.

07/

What monitoring features are included?

A dashboard shows validity, expiry countdown, issuer, etc. Alerts (email/SMS) notify you of imminent expiry or insecure configs.

08/

Is migration from manual management complex?

No. Add your servers/domains, import existing certs or request new ones—then automation takes over. Simple.

09/

Does auto deployment support custom server configs?

It supports standard Nginx/Apache/IIS configs. For custom setups, you can define post deployment commands/scripts in the console.

10/

How is pricing determined?

Flexible subscription based on number of certificates or servers. Choose a plan that fits your scale—no paying for unused features. See our pricing page for details.

11/

Where can customers in China learn about CaaS or get local service?

Customers in China can review the product capabilities on the sslTrus China CaaS page. For local purchasing, deployment guidance and technical support, visit Racent’s ssl CaaS service.