Hardware implementation of automatic certificate lifecycle management (ACLM)

ZoTrus ACLM Gateway

ACLM system + ACME gateway
One-stop CLM of dual-algorithm SSL certificates for all website system devices
Primary role: CLM, Backup role: SSL Gateway
Download Brochure: English 中文版
The SSL certificate validity will be shortened to 47 days

For network administrators who need to manage SSL certificates for many websites, devices, and cloud services, they are no longer satisfied with single site certificate automation management solutions. They need a centralized management system for all dual-algorithm SSL certificates required by their organization's websites, systems, devices, cloud services, etc. They need to discover which systems in the entire organization have deployed SSL certificates, when they expire, and how to achieve lifecycle management of all SSL certificates required by these websites, systems, devices, and cloud services, including application, validation, retrieval, distribution, deployment, renewal, revocation, archiving and audit.

ZoTrus Technology empowers other systems, devices, and cloud services that require SSL certificates but do not support certificate automation to have ability of dual-algorithm SSL certificate automation management capabilities by its HTTPS Automation Gateway. This enables centralized and unified automatic management of the entire lifecycle of SSL certificates required by all systems, as named ACLM. The primary role of the ZoTrus ACLM Gateway is automatic certificate lifecycle management, centrally managing public and intranet SSL certificates; its backup role is as an HTTPS Automation Gateway, serving as a backup device when other SSL gateway devices are unavailable.

1. Product Introduction

ZoTrus ACLM Gateway is a new hardware product that adds an ACLM system to ZoTrus HTTPS Automation Gateway (ACME gateway), it is also the on-premises edition of ZoTrus ACLM Cloud Service. It is a comprehensive certificate management system that integrates functions such as certificate discovery, centralized monitoring, automatic certificate application, automatic certificate deployment, compliance auditing and risk alerts, HTTPS encryption offloading and forwarding, post-quantum cryptography migration and WAF protection. It automates the transformation of scattered and isolated ACME certificates into a unified automatic management system covering the entire organization, ensuring that SSL certificates on physical servers, virtualization platforms, container environments, or cloud services can be automatically managed throughout their entire lifecycle on a single platform.

ZoTrus ACLM Gateway and ZoTrus ACME Gateway lie in their different dimensions. ACME Gateway provides the technical foundation at the "point," solving the technical challenge of "how to automatically obtain certificates", serving as a tool for automating certificate acquisition. ACLM Gateway, on the other hand, adds comprehensive management and implementation to the "point", addressing the governance challenge of "how to automatically manage all certificates within an organization", providing a secure foundation for digital transformation. ACME Gateway is one of the devices managed by ACLM Gateway, which is a unified management platform for various devices requiring SSL certificates.

SSL Certificate Lifecycle Management Automation Module

2. Main Functions

ZoTrus ACLM Gateway is designed for high security requirements and strict "zero-interference" needs for existing network services. It's not just a hardware gateway integrating an ACME client, but a comprehensive security device integrating Certificate Lifecycle Management (CLM), certificate automation, SM2 cryptography upgrades, post-quantum cryptography migration, and WAF protection. Its core innovation lies in the "hardware-based CLM" concept: integrating the CLM module, ACME service, SM2 cryptographic module, post-quantum cryptography module, and WAF engine into a single device deployed in front of the user's business servers. This not only provides automatic certificate management for the connected web servers but also empowers other systems and network devices in the organization's network architecture that do not support certificate automation, achieving unified and centralized management of dual-algorithm SSL certificates for all websites, systems, devices, and cloud services within the organization.

ZoTrus ACLM Gateway has the following four core functions:

3. Functional Modules and Management Interface

In addition to the 12 functional modules provided by ZoTrus HTTTPS Automation Gateway, the ZoTrus ACLM Gateway mainly offers the following 12 certificate management functional modules:

ZoTrus ACLM system provides a cockpit-style visual dashboard, displaying a global map of certificate assets, an expiration heatmap, compliance status, and algorithm distribution, along with alerts, reports, and audit logs. In particular, a PQC-ready 2D chart visually shows the percentage of all websites in the organization that have completed quantum cryptography migration. There is also a SM2-ready 2D chart visually shows the percentage of all websites in the organization that have completed SM2 cryptographic upgrades.

ZoTrus Automatic Certificate Lifecycle Management (ACLM) System

4. Performance and Deployment

ZoTrus ACLM Gateway comes in two different specifications: one provides only ACLM services, and the other provides both ACLM and ACME gateway services. The former has four built-in intermediate root keys for intranet SSL certificate issuance, enabling automatic intranet SSL certificate management. The latter, while also providing automatic intranet SSL certificate management, does not support customized intranet SSL intermediate roots; intranet SSL certificates are issued from ZoTrus public intranet SSL intermediate root keys. The latter's CPUs are available in Intel and Hygon, each supporting either 100 or 255 websites.

The performance parameters of various models are shown in the table below. For users with different requirements, products can be customized to meet their needs.

Model
MG-1-5
MG-8-5
MG-9-5
Functions
ACLM system
ACLM system + ACME gateway
ACLM system + ACME gateway
CPU Brand
Intel Atom
Intel Xeon (dual)
Hygon 5380
Number of manageable websites
1-99999
1-99999
1-99999
Number of ACME websites
0
100 / 255
100 / 255
Built-in intranet intermediate root CA
4
0
0
ACEM for public certificate
Yes
Yes
Yes
ACEM for Intranet certificates
Yes
Yes
Yes
Built-in ACME service
Yes
Yes
Yes
Built-in API service
Yes
Yes
Yes
Automatic certificate discovery
Yes
Yes
Yes
Supports multiple devices and CDN
Yes
Yes
Yes
SM2 Readiness Management
Yes
Yes
Yes
PQC Readiness Management
Yes
Yes
Yes
Equipment Management
Yes
Yes
Yes
Statistical Reports
Yes
Yes
Yes
Incl. No. of ECC SSL certificates
Purchase as needed
100 / 255
100 / 255
Incl. No. of SM2 SSL certificates
Purchase as needed
100 / 255
100 / 255
ACME service duration
Purchase as needed
5 years
5 years
ECC SSL Certificate Type
DV/OV/EV SSL Certificate
DV SSL Certificate
DV SSL Certificate
SM2 SSL Certificate Type
DV/OV/EV SSL Certificate
OV SSL Certificate
OV SSL Certificate
Each website has its own key/certificate
Yes
Yes
Yes
SSL certificate validity period
90 days
90 days
90 days
SSL certificate renewal cycle
Every 80 days
Every 80 days
Every 80 days
Website Trusted Identity Types
EV certification
EV certification
EV certification
X25519MLKEM768 algorithm
Yes
Yes
SM2DHMLKEM768 algorithm
Yes
Yes
ECC/RSA algorithm
Yes
Yes
SM2 algorithm
Yes
Yes
SM2 HTTPS Throughput
9 Gbps
9 Gbps
ECC HTTPS throughput
9 Gbps
9 Gbps
SM2 SSL Request
120 K/s
60 K/s
ECC SSL Requests
130 K/s
90 K/s
Max concurrent
1.5M
1M
WAF function
Built-in
Built-in
Network interface
6 gigabit Ethernet ports
6 gigabit Ethernet ports
+ 4 10 Gigabit optical ports
6 gigabit Ethernet ports
+ 4 10 Gigabit optical ports
Chassis size
155*240*40 (mm)
2U
2U
Power supply
60W single power supply
Dual power supply 550W
Dual power supply 550W
Suitable Scope
For ACLM services only
For ACLM and ACME gateway services
For ACLM and ACME gateway services

For ACLM Gateway that only provides ACLM functions (model MG-1-5), a public IP address is not required; it only needs internet access and a connection to the intranet. For ACLM Gateway that also provides ACME functions (models MG-8-5 and MG-9-5), it deploys in front of the Web servers same as other types of ZoTrus HTTPS Automation Gateway.

If it is inconvenient to deploy ZoTrus ACLM gateway hardware device, customers can choose to deploy the ZoTrus ACLM system on their own data center servers or containers, achieving the same ACLM functionality as the ZoTrus ACLM Gateway (MG-1-5).

5. ZoTrus ACLM Gateway – The Inevitable Path to Comprehensive Security Protection

Driven by the triple demands of shortened certificate validity periods, in-depth reforms of SM2 cryptographic transformation, and the looming threat of quantum computing, ZoTrus ACLM Gateway has emerged, possessing the following five characteristics:

  • Automation and intelligence: Full-process automation with intelligent early warning and strategy self-healing capabilities.
  • Cryptographic algorithm agility: It natively supports both traditional RSA/ECC/SM2 algorithms and post-quantum cryptographic algorithms. It prioritizes the use of the SM2 hybrid PQC algorithm to achieve smooth PQC migration.
  • Architecture integration: It can be seamlessly integrated with commonly used CDN/WAF services to form a collaborative defense.
  • Enterprise-level reliability: Meets the stringent requirements of critical business operations for high availability, high performance, and auditability.
  • Hybrid environment adaptability: It can seamlessly manage multi-form certificate application assets across cloud, ground, edge, and endpoint.

ZoTrus ACLM Gateway integrates CLM with cryptographic acceleration, security protection, and unified management capabilities into a dedicated security hardware platform. This not only completely solves the operational challenges of automatic certificate management but also provides a one-stop solution for three critical protection tasks urgently needed by critical information infrastructure operators: SM2 cryptographic transformation, post-quantum cryptography migration, and HTTPS traffic security protection. Upgrading the security protection system is no longer about single-point reinforcement but a complete architectural reshaping of overall security capabilities. ZoTrus ACLM Gateway creates a robust yet intelligent security foundation for the digital businesses of large and medium-sized organizations, capable of addressing current needs while remaining future-proof.

For large and medium-sized organizations with multiple websites, systems, devices, and cloud services, the need is not just for ACME, but for unified management and scheduling of ACME – namely, ACLM. ACME solves the "how to do it" problem, while ACLM solves the "how to manage it well" problem. An excellent ACLM solution can integrate all ACME services into a unified view, orchestrate manually applied certificates with automatically applied certificates, seamlessly integrate support for RSA/ECC and SM2 algorithms, support the mixed application and seamless migration of traditional and post-quantum cryptographic algorithms, and present the certificate lifecycle status to administrators in real time in the form of reports and alerts. ACLM is the ultimate solution for automatic certificate management. ZoTrus ACLM Gateway makes the passive management of SSL certificates into proactively and automatically build a cryptographically agile digital trust infrastructure.