Internal TLS Certificates

All communication between CMPClosed Converged Monetisation Platform. The MDS Global product that supports customer care and billing for digital service providers. components is secured using Transport Layer Security (TLS).

During deployment, the CMP Ansible installer automatically provisions a complete internal Public Key Infrastructure (PKI) for the environment. This includes:

CMP Trust Relationship

The generated certificates are used exclusively for securing communication between CMP services and require no manual certificate management by the customerClosed In the context of the Cloud Monetisation Platform, an individual or organisation who has signed an agreement to take goods and services from a service provider. A customer receives a bill associated with one or more subscriptions, and can be a single end user or a large company with many subscriptions assigned to one agreement..

No customer supplied certificates are required for internal CMP communication.

Each service receives its own certificate containing the appropriate Subject Alternative Names (SANs) for the host on which it is deployed. All certificates are signed by the deployment-specific internal Root CA, allowing every CMP component to establish mutual trust automatically.

External Client Access

Customer-facing endpoints, such as web applications exposed through a load balancer or reverse proxy, are outside the scope of the CMP internal PKI.

Customers are responsible for provisioningClosed In telecommunications, the setup of equipment, wiring and transmission to deliver services to a customer. and managing certificates presented by external endpoints, for example:

  • HTTPS Load Balancers

  • Reverse Proxies

  • Web Application Firewalls

  • Enterprise Ingress Controllers

These certificates should be issued by a publicly trusted Certificate Authority, or by the customer's own enterprise PKI, according to their security policies.

Typical examples include:

  • Google Cloud Load Balancer certificates

  • AWS ACM certificates

  • Microsoft AD Certificate Services

  • DigiCert

  • Sectigo

  • Let's Encrypt

These certificates are used only for browser and external client connections and are independent of the certificates generated by the CMP installer.

Internal Trust Management

During deployment, the installer automatically configures trust between all CMP components.

This includes:

  • importing the CMP internal Root CA into component truststores

  • creating application-specific Java truststores

  • updating operating system trust stores where required

  • configuring each component to use its assigned keystore and truststore

This process is fully automated and normally requires no manual intervention.

Java Truststores

Many CMP components are Java-based applications.

The installer automatically creates and configures Java truststores containing:

  • the standard Java CA certificates (copied from the default JVM cacerts truststore)

  • the CMP internal Root CA certificate

Retaining the standard Java trusted certificates ensures applications continue to trust public Certificate Authorities when accessing external services, while also trusting certificates issued by the CMP internal PKI.

Operating System Trust Store

Where required, the installer also updates the operating system trust store.

This enables operating system utilities such as:

  • curl

  • OpenSSL

  • DNF/YUM

  • Apache HTTP Server

to trust certificates issued by the CMP internal Root CA.

On Enterprise LinuxClosed A well-known widely used open source operating system. systems this is achieved using the system certificate trust infrastructure and the update-ca-trust utility.

Certificate Lifecycle

The CMP internal PKI is generated automatically during deployment.

The installer manages:

  • Root CA generation

  • Service certificate generation

  • Truststore creation

  • Keystore creation

  • Certificate distribution

  • Trust configuration

No manual certificate creation is normally required.

If certificates are regenerated, the installer updates the relevant keystores and truststores accordingly.

Related Topics Link IconRelated Topics