Internal TLS Certificates
All communication between CMP
Converged Monetisation Platform. The MDS Global product that supports customer care and billing for digital service providers. components is secured using Transport Layer Security (TLS).
During deployment, the CMP Ansible installer automatically provisions a complete internal Public Key Infrastructure (PKI) for the environment. This includes:
-
An internal Root Certificate Authority (CA)
-
Service certificates for all CMP components
-
Operating system trust stores
-
Component-specific keystores and truststores.
CMP Trust Relationship
The generated certificates are used exclusively for securing communication between CMP services and require no manual certificate management by the customer
In the context of the Cloud Monetisation Platform, an individual or organisation who has signed an agreement to take goods and services from a service provider. A customer receives a bill associated with one or more subscriptions, and can be a single end user or a large company with many subscriptions assigned to one agreement..
No customer supplied certificates are required for internal CMP communication.
Each service receives its own certificate containing the appropriate Subject Alternative Names (SANs) for the host on which it is deployed. All certificates are signed by the deployment-specific internal Root CA, allowing every CMP component to establish mutual trust automatically.
External Client Access
Customer-facing endpoints, such as web applications exposed through a load balancer or reverse proxy, are outside the scope of the CMP internal PKI.
Customers are responsible for provisioning
In telecommunications, the setup of equipment, wiring and transmission to deliver services to a customer. and managing certificates presented by external endpoints, for example:
-
HTTPS Load Balancers
-
Reverse Proxies
-
Web Application Firewalls
-
Enterprise Ingress Controllers
These certificates should be issued by a publicly trusted Certificate Authority, or by the customer's own enterprise PKI, according to their security policies.
Typical examples include:
-
Google Cloud Load Balancer certificates
-
AWS ACM certificates
-
Microsoft AD Certificate Services
-
DigiCert
-
Sectigo
-
Let's Encrypt
These certificates are used only for browser and external client connections and are independent of the certificates generated by the CMP installer.
Internal Trust Management
During deployment, the installer automatically configures trust between all CMP components.
This includes:
-
importing the CMP internal Root CA into component truststores
-
creating application-specific Java truststores
-
updating operating system trust stores where required
-
configuring each component to use its assigned keystore and truststore
This process is fully automated and normally requires no manual intervention.
Java Truststores
Many CMP components are Java-based applications.
The installer automatically creates and configures Java truststores containing:
-
the standard Java CA certificates (copied from the default JVM cacerts truststore)
-
the CMP internal Root CA certificate
Retaining the standard Java trusted certificates ensures applications continue to trust public Certificate Authorities when accessing external services, while also trusting certificates issued by the CMP internal PKI.
Operating System Trust Store
Where required, the installer also updates the operating system trust store.
This enables operating system utilities such as:
-
curl
-
OpenSSL
-
DNF/YUM
-
Apache HTTP Server
to trust certificates issued by the CMP internal Root CA.
On Enterprise Linux
A well-known widely used open source operating system. systems this is achieved using the system certificate trust infrastructure and the update-ca-trust utility.
Certificate Lifecycle
The CMP internal PKI is generated automatically during deployment.
The installer manages:
-
Root CA generation
-
Service certificate generation
-
Truststore creation
-
Keystore creation
-
Certificate distribution
-
Trust configuration
No manual certificate creation is normally required.
If certificates are regenerated, the installer updates the relevant keystores and truststores accordingly.