Skip to main content

Integrations

Integrations connect Sectigo Edge to the systems that request, use or issue your certificates. Almost all of them run on a Mesh Node inside your environment; only Sectigo SCM runs in the cloud. Every guide in this section follows the same shape: what the integration does, how to prepare the host, what to add to the node's config.json, how to configure it in the console, what your policy must allow, how rotation and rollback behave, and how to troubleshoot.

Integrations page showing a card per integration with status, target count, revision, Configure and Test actions
Each integration card shows its status, targets, desired-state revision and any error code.

Choose an integration​

IntegrationConsole cardRuns onWhat it does
ACMEACMEAny nodeBuilt-in RFC 8555 service for ACME clients, with node-bound External Account Binding
SPIFFE / SPIRESPIFFE identitiesLinux / Kubernetes node beside SPIRE ServerTurns approved service claims into SPIRE registration entries
NGINXNGINXLinux nodeZero-downtime certificate rotation with exact-certificate health checks and automatic rollback
Apache HTTP ServerApache HTTP ServerLinux nodeGraceful-restart rotation with exact-certificate health checks and automatic rollback
Java (PKCS#12)Java PKCS#12 keystoreLinux or Windows nodePassword-protected PKCS#12 keystores, application reload, rollback
HashiCorp VaultHashiCorp Vault KV v2Any nodeWrites certificates and keys to Vault KV v2 with a check-and-set pointer
Kubernetes CSRKubernetes CSRKubernetes nodeCustom signer for approved CertificateSigningRequest objects
Microsoft ADCSMicrosoft ADCSWindows nodeIssues through your existing enterprise CA and template under Sectigo Edge policy
ESTESTAny nodeRFC 7030 enrollment for devices and appliances
Sectigo Certificate ManagerSectigo SCMCloudUses your SCM account as the issuing CA

How every node-hosted integration works​

Configuration is split deliberately between the console and the node:

Lives in the console (desired state)Lives on the node (config.json and local files)
Enabled or disabledPaths, executables and their SHA-256 pins
Target Mesh NodesPasswords, tokens and private keys in private local files
Certificate / identity profileReload commands and timeouts
A local adapter reference such as local/nginx-productionThe same adapter reference and profile, which the node matches
For Sectigo SCM: the active SCM connector; for ADCS: the public ADCS CA chain—

The adapter reference is a name, not a credential. Secrets are never accepted by the console's integration schema.

Configure an integration in the console​

  1. Prepare the node first: add the integration's keys to config.json, validate it and restart the node. Each guide shows the exact keys.
  2. Open ConsoleIntegrations and select Configure on the integration's card.
  3. Select Enable this integration.
  4. Under Target Mesh Nodes, select the node(s) that should run it (up to 32). NGINX and Apache only accept Linux or Linux-container nodes; incompatible nodes are disabled in the list.
  5. Enter the Certificate / identity profile (2–128 characters: letters, digits, ., -, _).
  6. Enter the Local adapter reference exactly as it appears in the node's config.json. ACME and SPIFFE use the fixed built-in references builtin/acme and builtin/spire.
  7. Select Save desired state. You need the right permission (can_manage_nodes, or can_manage_ca for Sectigo SCM) and a fresh MFA session.

Saving advances the integration's revision. The assigned node picks it up on its next poll, checks it against its local configuration and reports back.

Statuses​

Card statusAPI valueMeaning
DisableddisabledNot enabled; no authority or workload path is active.
Awaiting nodepending_nodeA new revision or test is waiting for every assigned node to acknowledge it.
HealthyhealthyEvery assigned node applied and checked the exact current revision.
DegradeddegradedA node rejected the revision or cannot operate the adapter. The card shows the error code.

Disabling an integration or removing a node from it sends that node an authority-withdrawal tombstone: the node immediately stops serving or activating that integration, even if it later loses its connection. Every save, test and acknowledgement is recorded in the tenant audit log.

Test​

For an enabled integration, Test asks the assigned nodes to re-check the adapter end to end and report again. The card shows Awaiting node until they do. For Sectigo SCM, see what a test records.

Error codes reported by any node-hosted integration​

CodeMeaningFix
adapter_not_installedThe node has no adapter for this kindUse a node that supports it
<kind>_not_configured (for example nginx_not_configured, est_not_configured, adcs_not_configured, spire_not_configured)The node's config.json does not enable this adapterAdd the keys, validate and restart the node
adapter_reference_invalidThe console's adapter reference differs from the node'sMake them identical
profile_not_mappedThe console's profile differs from the node's *_profile_idMake them identical
profile_not_configuredNo profile was selected in the consoleEnter a profile
integration_kind_unsupportedThe node version does not know this integrationUpgrade the node

Adapter-specific codes are listed on each integration page. To see them locally, run sectigo-edge … integrations or status on the node (CLI reference).

Policy requirements for activating adapters​

Adapters that change what a service is serving (NGINX, Apache, Java PKCS#12 and HashiCorp Vault) are activating deployment boundaries. Your signed policy must allow them explicitly:

  • the workload profile's allowed deployment modes must include the adapter's mode (nginx, apache, java_keystore or hashicorp_vault; microsoft_adcs for ADCS issuance);
  • the profile needs an explicit rotation block with mode: dual_slot, renewal lead time, overlap, health grace, a rollback window and a promotion mode of automatic_after_health or manual.

Every issuance for these adapters binds the profile, adapter reference and current integration revision. Disabling, reassigning or changing the integration invalidates an in-flight deployment before it is activated. See Policies and Zero-downtime rotation.

In this section​