SSL Certificate Management
SSL Certificate Management
Overview
This process is for any Ministry of Justice users (or suppliers) requiring an SSL Certificate, where certificate management isn't already included in the service offering.
There are 2 categories of certificate we use at Ministry of Justice:
- Automated certificate management for modern cloud native software and infrastructure e.g. AWS ACM or Let's Encrypt.
- Manual management i.e. which involves human tracking, hand-crafted requests, and physical installation.
Where at all practicable we should utilise automated certificate management in line with MOJ Security Standards.
Where that is not technically possible, or commercially feasable, and a manually created certficate is required, the preferred method for SSL/TLS certificate management is AWS Certificate Manager (ACM). Wherever possible, services requiring SSL certificates should use certificates issued and managed through ACM.
In some cases, vendors or third-party platforms cannot support ACM-issued certificates or the certificate export process. In these situations, Gandi.net remains available as a fallback option for certificate procurement and management.
Preferred Option: AWS Certificate Manager (ACM)
AWS ACM should be used as the default solution for all new SSL/TLS certificate requests where technically feasible.
For systems hosted outside AWS or managed by third-party suppliers, ACM certificates can be exported and provided to the vendor for installation. Before proceeding, the vendor must confirm that they can:
- support the use of exported AWS ACM certificates.
- Install the complete certificate chain supplied by the Ministry of Justice.
- securely install and manage the associated private key provided with the certificate.
- perform certificate replacement and renewal activities within the required timescales.
If a vendor cannot support exported ACM certificates, an alternative certificate management approach should be agreed with the Hosting Networks team.
If all of the pre-requisites for ACM can be met your request for a certficate must be submitted to certificates-gg@justice.gov.uk. Include details of where the service is hosted, Fully Qualified Domain Name (FQDM) to be covered, plus any additional Subject Alternative Names (SAN) to be includes in the certificate.
Fallback Option: Gandi.net
Where ACM cannot be used, please email your request to certificates-gg@justice.gov.uk. In addition to hosting location, FQDN, and SAN, also include justification of why ACM cannot be supported, and include the Certificate Signing Request (CSR).
The Hosting Networks team do not handle any pass-phrases or keys regarding the CSR or SSL certificates. Please do not send any private keys with your request.
Certificate Validity
All SSL/TLS certificates issued through the organisation's approved processes are limited to a maximum validity period of six months.
Service owners are responsible for ensuring renewals are planned and implemented before certificate expiry. Vendors managing externally hosted services must ensure they have appropriate processes in place to support the six-month renewal cycle.
Renewal Process
At least one month prior to renewal contact certificates-gg@justice.gov.uk to request a renewal.
Revoking Certificates
If an SSL certificate is no longer required e.g. a service has been decommissioned please contact certificates-gg@justice.gov.uk, so that the team can revoke the certificate.
Note that once a certificate has expired or been revoked it cannot be reinstated. If a certificate is required the process to request a new certificate should be followed.
Costs/Funding information
The costs for certificates are met centrally by Hosting. There is no cross charge for using this service.
Was this page useful?